Live data from Hacker News

Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

ndss-symposium.org

101–110 of 206 posts

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#101

Wire (from the creators of Skype) does not mandate a mobile phone number (SIM cards are tied to government identity in many countries). Only an email address is required to open a free account. Nor does Wire mandate upload of your phone's address book with personal social graph of contacts. Free for consumers with paid teams offering for enterprises, optional on-prem server. Open-source clients and server. Cross-devi…

I can't seem to find any information about their free version on that page.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#102
post #78

Wire (from the creators of Skype) does not mandate a mobile phone number (SIM cards are tied to government identity in many countries). Only an email address is required to open a free account. Nor does Wire mandate upload of your phone's address book with personal social graph of contacts. Free for consumers with paid teams offering for enterprises, optional on-prem server. Open-source clients and server. Cross-devi…

Wire is massively underrated in general. It’s got a slick UI that’s easy for non techies, it’s got native clients on all major platforms, and it has everything you really need from an e2e IM without the fluff. I’m surprised it doesn’t come up more in these discussions and people just “settle” for Signal or another service that needs your phone number etc.

> I’m surprised it doesn’t come up more in these discussions and people just “settle” for Signal

Not needing a phone number is nice, but last I checked Wire does little when it comes to metadata, while Signal is more or less the state of the art in that regard.

The phone number requirement itself is supposed to be eventually dropped in Signal (although I'll admit it's taking quite some time, and with the spam issues it might take some more).

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#103

The reason this abuse of privacy is so widespread is because there are no bad consequences for the perpetrators. Governments don't enforce privacy acts in this circumstance. Users just roll their eyes, knowing there is no way for them to complain except though boycotts, which are difficult to organise and might not work unless coordinated on a massive scale which has never been tried. And so it goes.

And yet people are still bitching about the GDPR. The only problem with the GDPR is the lack of enforcement. However, it isn't really surprising considering a large chunk of this very community makes their money off large-scale stalking and the same unethical things they complain about.

The only people really bitching about GDPR are software engineers and lawyers at companies whose privacy practices are still questionable after all the time given to clean up their act. That's why, if you look at HN comments, everyone seems to hate it. Sample bias. None of the remaining 7 billion people on the planet really know much about it. I bet if you summarize the regulation and describe it to a random person on the street, they'll nod and think "sure it's kind of a good idea" and forget about it in the next 10 seconds.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#104

Earlier quoted context omitted.

there is always Matrix app. Some may argue that Matrix still a centralized server by the virtue of seeding your group info somewhere. But this seeding can be done via paper-only thereby it is still a true decentralized messaging server.

No, there is always xmpp. Matrix is just an app, and we need a federated protocol. I think that Matrix will never have an alternative server implementation made by a competing party, which makes it's main selling point void.

Matrix is not an app. It is a protocol. You can find the specification here: https://matrix.org/docs/spec/

There are also multiple client and server implementations already. You can find them here: https://matrix.org/docs/projects/try-matrix-now/

There are also at least two companies offering homeserver hosting: https://matrix.org/hosting/

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#105

The paper claims that stricter rate limits are a possible solution to this issue, and that with stricter limits in place "crawling entire countries would only be feasible for very powerful attackers". I don't think I agree. Take Signal: the authors managed to crawl all US phone numbers in 25 days, using 100 accounts. Their proposed stricter rate limits force an approx 50x slowdown on an attacker (Table V), which seem…

From the paper:

> Signal acknowledged the issue of enumeration attacks as not fully preventable,

So rate-limiting is fine as long as you don't hurt user experience, e.g. you can still message your contacts within 1min if you have around 500 contacts. It's also nice to lower the load on the servers. But there's no real fix as long as phone numbers are used.

And it's fine, given that Signal basically leaks one bit of information: whether a phone number has a Signal account or not.

...of course, assuming that the account owner doesn't accept unsolicited messages (and thus shares their profile, with their picture and "About" field).

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#106
post #78

Wire (from the creators of Skype) does not mandate a mobile phone number (SIM cards are tied to government identity in many countries). Only an email address is required to open a free account. Nor does Wire mandate upload of your phone's address book with personal social graph of contacts. Free for consumers with paid teams offering for enterprises, optional on-prem server. Open-source clients and server. Cross-devi…

Wire is massively underrated in general. It’s got a slick UI that’s easy for non techies, it’s got native clients on all major platforms, and it has everything you really need from an e2e IM without the fluff. I’m surprised it doesn’t come up more in these discussions and people just “settle” for Signal or another service that needs your phone number etc.

The clients are not actually native, at least on desktop it's just Electron and the mobile clients (Android, iOS) don't feel fast either, but frankly rough edges like these are my only real complaint.

Features are available and work everywhere (unlike Signal which has a dumbed-down desktop client and no web client at all), it does everything you generally need and the search is actually superb (better than Telegram even, since tg only does word matching and Wire can do symbol and arbitrary string matching and is also very fast) although limited to one chat so you need to know which chat contains what you're looking for. Meanwhile Element (Matrix) goes "can't search encrypted chats"... useless if you want to communicate something non-ephemeral, you'd need to switch to pgp-encrypted email and all its problems or another chat service.

Compared to all the alternatives, Wire with all its faults is the best encrypted messenger. I would recommend it to everyone aside from the network effect: Signal clearly has more users (while being worse on features and privacy). Because it's useless to be alone on a messenger and because it's still a step forwards from the status quo, most of the time I end up recommending subpar solutions.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#107

I think the information who is a contact of whom should not reside with the provider, but be distributed among the peers. I had a proof of concept of something similar working a couple years ago. I was writing a file-sharing app, and the goal was to piggy-pack on the existing social graph that you had from Facebook, Skype and so on. I could not register as a proper Facebook app, since that required having a domain, a…

> I think the information who is a contact of whom should not reside with the provider, but be distributed among the peers.

Signal partially solves this with SGX. Partially because SGX will probably never be fully secure.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#108
post #90

Earlier quoted context omitted.

Monero is.

So you think if a notorious terrorist or whatever moved millions of dollars through Monero to fund a terror attack, American or other intelligence agencies wouldn't be able to identify the transaction? It could be done truly anonymously when up against the full weight and might of US, Western, Israeli etc intelligence budgets and methods?

Well the sender, receiver and the amounts are all hidden, so yes.

I should still note that it isn't a magic bullet, and that things you do in connection to the monero blockchain can obviously still give the authorities an idea of what you are doing.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#109
post #77
post #70

Earlier quoted context omitted.

Who said Bitcoin is anonymous?

If you can acquire BTC anonymously, then you can pay anonymously.

If you can acquire BTC anonymously, then you can acquire prepaid virtual credit cards anonymously. Most localbitcoins exchangers will happily do bank transfers for you without asking any questions either.

There's not many kinds of payments which aren't fairly easy to do anonymously.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#110

Wire (from the creators of Skype) does not mandate a mobile phone number (SIM cards are tied to government identity in many countries). Only an email address is required to open a free account. Nor does Wire mandate upload of your phone's address book with personal social graph of contacts. Free for consumers with paid teams offering for enterprises, optional on-prem server. Open-source clients and server. Cross-devi…

I can't seem to find any information about their free version on that page.

https://app.wire.com/auth/?hl=en#register

It's a bit hard to find, looks like they've given up trying to compete for non-business users, but the client has a registration form open to everyone.

I think they'll keep supporting this because inviting those 'guest' accounts into rooms of business users is a big feature. We regularly collaborate with people via Wire (customers or freelancers, who can just use their personal Wire accounts) because it's the easiest way to collaborate without forfeiting encryption or features.

Post reply on HN