Live data from Hacker News

Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

ndss-symposium.org

161–170 of 206 posts

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#162
post #106

Earlier quoted context omitted.

The clients are not actually native, at least on desktop it's just Electron and the mobile clients (Android, iOS) don't feel fast either, but frankly rough edges like these are my only real complaint. Features are available and work everywhere (unlike Signal which has a dumbed-down desktop client and no web client at all), it does everything you generally need and the search is actually superb (better than Telegram e…

The Wire iOS native Arm client is fast and can be made officially available for M1 Arm-based Macs. Looking forward to that, as the Slack iOS Arm client is way faster on my M1 Macbook than the desktop memory-hogging Slack.

Did you use unofficial means to install Slack iOS on M1 (which is now patched if I remember right) or is there still a way?

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#163

Earlier quoted context omitted.

The Wire iOS native Arm client is fast and can be made officially available for M1 Arm-based Macs. Looking forward to that, as the Slack iOS Arm client is way faster on my M1 Macbook than the desktop memory-hogging Slack.

Did you use unofficial means to install Slack iOS on M1 (which is now patched if I remember right) or is there still a way?

I did it before the patch, but the enforcement is now being done by Fairplay DRM. There are reports that you can extract the iOS app from a jailbroken iPhone, with DRM removed. Then the resulting .ipk will work on M1.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#164

An even bigger problem: if you set up an Android phone without a Google account and need to access the Play Store (which is impossible to do without nowadays), Google will force you to sign into a Google account at the OS level and will suck in all your devices contacts -- with no opt out. You can disable this sync "feature" but *only after*, once Google has collected all your contacts (phone number, addresses, email…

I use Aurora for the Playstore. It's buggy but does the trick for the few apps not in FDroid. No account needed as they provide a service for shared credentials.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#165
post #109
post #77

Earlier quoted context omitted.

If you can acquire BTC anonymously, then you can pay anonymously.

If you can acquire BTC anonymously, then you can acquire prepaid virtual credit cards anonymously. Most localbitcoins exchangers will happily do bank transfers for you without asking any questions either. There's not many kinds of payments which aren't fairly easy to do anonymously.

Any recommendation on prepaid virtual credit cards which are accepted in EU?

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#166
post #106
post #78

Earlier quoted context omitted.

Wire is massively underrated in general. It’s got a slick UI that’s easy for non techies, it’s got native clients on all major platforms, and it has everything you really need from an e2e IM without the fluff. I’m surprised it doesn’t come up more in these discussions and people just “settle” for Signal or another service that needs your phone number etc.

The clients are not actually native, at least on desktop it's just Electron and the mobile clients (Android, iOS) don't feel fast either, but frankly rough edges like these are my only real complaint. Features are available and work everywhere (unlike Signal which has a dumbed-down desktop client and no web client at all), it does everything you generally need and the search is actually superb (better than Telegram e…

Element can search encrypted chats, just not yet in the browser

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#167
post #127

Earlier quoted context omitted.

Matrix tools like Element is decentralised which is preferred, wire is not. The company keeps a list of all the users you contact until you delete your account. Source: https://archive.fo/ARZe4#im

It is federated, not decentralized. You need to use a server, which will have access to your contacts and the rest of the metadata such as how often you talk to them etc (and all message content that is not E2EE). You are only safe from third party if both you and people you talk to run their own servers.

mind explaining how Matrix is not decentralized?

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#168
post #73

Earlier quoted context omitted.

This is one of those replies that should be put in some kind of HN canon. It perfectly shows why there are so few privacy or security respecting options. They did the correct thing for security and you switched. As I've observed for a long time: UX is more powerful than anything else except maybe cost, and even then one driver for user preference for "free" apps is not having to dig out a card... so cost is also UX.

That’s a bit unfair. I value privacy for some things but for other things I value more not losing my message history. Telegram is not as secure as other options by default, but for me it strikes a good balance between convenience/usability and privacy, as I can optionally open a self-destroying secret chat when I need it.

With Matrix you get privacy with message history.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#169

Earlier quoted context omitted.

there is always Matrix app. Some may argue that Matrix still a centralized server by the virtue of seeding your group info somewhere. But this seeding can be done via paper-only thereby it is still a true decentralized messaging server.

No, there is always xmpp. Matrix is just an app, and we need a federated protocol. I think that Matrix will never have an alternative server implementation made by a competing party, which makes it's main selling point void.

Matrix is no app. Matrix an open protocol for decentralized communication that works through federation.

Further, there is a alternative server implementation: Conduit.

What main selling point are you talking about?

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#170
post #158
post #130

Earlier quoted context omitted.

For metadata you just have to trust them. Sealed sender doesn't solve that[1], even if it's better than nothing. It's also better than nothing to require no phone number in the first place (Wire), or not to require a payment (like Threema does) which is roughly as hard to make anonymous as getting an anonymous phone number. But either way, they can track everything you send, it's a matter of wanting to. The only way…

> The only way to avoid that is by not sending personal data to semi-/untrusted parties at all (Matrix). With Matrix you still end up trusting the server sysadmin (both in terms of ethics and technical abilities), it's not like it solves the problem for mass communication where at least one user has to agree on a 3rd-party instance. > those contacts connect to Signal with an IP address and are doing other things like…

> SGX. This in itself is its own can of worms, but assuming it's secure

It likely doesn't really add much security. Anyone capable of running processes on the chip hosting the SGX enclave can probably run a side-channel attack to recover the necessary keys. I was very disappointed that Signal took that approach.

Post reply on HN