Live data from Hacker News

We can do better than Signal

icyphox.sh

51–60 of 290 posts

Re: We can do better than Signal

#51
post #32
post #8

I'm confused about this piece. If there's true E2E encryption (verified by open source client code and review of released binaries) then why does it matter if the server code is backdoored or not? The whole point of E2E is that you don't need to care about the server being able to ever see the text of your messages because it never can.

Copy pasting my comment: Consider this paragraph from the Signal protocol > ...For example, they may compare public key fingerprints manually, or by scanning a QR code. Methods for doing this are outside the scope of this document. > If authentication is not performed, the parties receive no cryptographic guarantee as to who they are communicating with . Nobody I know in practice does this authentication. If an activ…

Wouldn't it just take 1 person doing the verification on a new message to catch this though?

Re: We can do better than Signal

#52

As I wrote in https://news.ycombinator.com/item?id=25795575 - WhatsApp: Oh wait, SMS etc. is completely insecure - Signal: Oh wait, WhatsApp is structurally unable to be a force for privacy - Matrix: Oh wait, even benevolent centralization is an unnecessary risk It's not that worse is better, but the general public's imagination can only grow so fast. We need to coax people along. As such, I do think all 3 serve a pu…

In fairness, I think WhatsApp's value proposition is and was as little more than 'just' oh wait, sms etc. is completely insecure. I don't think the majority really cared about that (especially since end-to-end encryption was a later addition). I think most people primarily started using WhatsApp because a) it was (is) free b) cross-platform c) worked very reliably

Re: We can do better than Signal

#53
post #32

Earlier quoted context omitted.

Copy pasting my comment: Consider this paragraph from the Signal protocol > ...For example, they may compare public key fingerprints manually, or by scanning a QR code. Methods for doing this are outside the scope of this document. > If authentication is not performed, the parties receive no cryptographic guarantee as to who they are communicating with . Nobody I know in practice does this authentication. If an activ…

>If an active attack is carried out, I'm reasonably sure people would not notice. If the attack happened after you have started communicating wouldn't you get a notification that the key of those you're communicating with has changed? An attack would only be invisible if it happened from the first communication. But unless it's very targeted someone somewhere would compare the keys and notice.

> An attack would only be invisible if it happened from the first communication.

This is the scenario I'm talking about.

Re: We can do better than Signal

#54
post #20

The article calls out that the Signal server could be compromised. I always thought one design philosophy of Signal was to ensure the server doesn’t matter from the perspective of privacy. Would having multiple servers help here, anyway? Once your data leaves your own server, you would then be in untrusted territory assuming the server needed to be trusted.

It's my understanding that the main concern about a compromised Signal server is that metadata of which phone numbers are registered as user IDs could be compromised. Basically the same threat model the Signal people themselves address when talking about court orders and subpoeanas received by their corporation for "customer" data.

That's not true afaik. Signal days that they don't store phone numbers beyond the initial setup/verification. See here:

> Does Signal send my number to my contacts? Signal does not send your phone number to anyone unless you send them a message or make a call to them. The Signal service does not have any knowledge of your contacts. Data is all owned by your phone. Registration notifications are never transmitted by anyone in any direction at all; these notifications are created by your phone.

> How does Signal know my contact is using Signal? Signal periodically sends truncated cryptographically hashed phone numbers for contact discovery. Names are never transmitted, and the information is not stored on the servers. The server responds with the contacts that are Signal users and then immediately discards this information. Your phone now knows which of your contacts is a Signal user and notifies you if your contact just started using Signal.

https://support.signal.org/hc/en-us/articles/360007061452-Do...

(Btw, I think that first sentence is a bit confusing and should be classified/reworded.)

Re: We can do better than Signal

#55

Earlier quoted context omitted.

It turns out that decentralization closes the door on top-down censorship, but at the same time, invites spam and abuse of the system for personal gain. It's very easy to do this in a decentralized model, and every single decentralized service suffers from this. IRC, Email, Mastodon, you name it. It's all bad.

The solution is simple. Make the decentralized systems social, with reputation.

Will the arbiter of reputations be central or decentralized?

Re: We can do better than Signal

#56
post #32

Earlier quoted context omitted.

Copy pasting my comment: Consider this paragraph from the Signal protocol > ...For example, they may compare public key fingerprints manually, or by scanning a QR code. Methods for doing this are outside the scope of this document. > If authentication is not performed, the parties receive no cryptographic guarantee as to who they are communicating with . Nobody I know in practice does this authentication. If an activ…

Wouldn't it just take 1 person doing the verification on a new message to catch this though?

Not if it's targeted towards a particular pair of people.

Re: We can do better than Signal

#57
post #10

I'm a bit annoyed at "we can do better than X" when, you know what? Maybe we can't. Yes, it's nice that you and I can install Element and deal with the finicky crypto handshake that for some reason always shows red for me because a friend opened the web UI and closed it before he completed the handshake and now we can never actually make that check go green, and it's nice that Mastodon is distributed but mastodon.hos…

I had a similar experience with Matrix/Element. I was using the desktop app to chat with a friend, and while we were able to get some end-to-end encryption working, it was a huge pain the butt, and if two software engineers struggled this much to get the damn thing working, there's no way in hell that I'm convincing my parents to use it.

To me, we have to accept the incremental wins where we can get them; getting my parents on Signal means that they're not on WhatsApp.

I am a believer in federation, honestly, but the fact of the matter is that there's a reason that XMPP hasn't taken the world by storm, and people have gravitated towards centralized stuff: it's just easier, and not everyone is a software engineer.

That said, I would love to be wrong about this....if we can make Matrix/Element approachable by anyone, I would support that.

Re: We can do better than Signal

#59
post #46

As I wrote in https://news.ycombinator.com/item?id=25795575 - WhatsApp: Oh wait, SMS etc. is completely insecure - Signal: Oh wait, WhatsApp is structurally unable to be a force for privacy - Matrix: Oh wait, even benevolent centralization is an unnecessary risk It's not that worse is better, but the general public's imagination can only grow so fast. We need to coax people along. As such, I do think all 3 serve a pu…

I'm not positive, but I think the signal protocol and signal messenger came before Moxie worked with Whatsapp to provide e2e encryption. Not refuting your point at all, just providing additional context.

Yeah I'm charting the public's realizations, not security experts' realizations.

Re: We can do better than Signal

#60

Earlier quoted context omitted.

The solution is simple. Make the decentralized systems social, with reputation.

And that then is extremely easy to abuse as soon as you have enough people with high rank enough deciding to start to misbehave.

Sounds like IRL
Post reply on HN