Live data from Hacker News

Global Encryption Day: Demand End-to-End Encryption in DMs

blog.torproject.org

41–50 of 78 posts

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#41
post #32

As I understand it, if we had true end-to-end encryption, I would have to make sure I kept a set of keys, copied them between every computer and phone I used for chatting, and if I lost those keys I'd lose all my messages? Honestly, for most people I don't think that's functionality they would want, at least without us getting much better at interfaces and usability. Standard ways of storing keys, for example in a pa…

IMHO, for most people the best interface would be a physical key (with software keys on it). That is something like a smartcard or ubikey, and even a way of obtaining multiple copies, like with physical keys. My employer rolled out a smartcard based PKI about 15 years ago, where you may own more than one card (optionally in sim card size for usb tokens) so, for example, you can have one in the office and have another…

The difference is: If you lose your smartcard, it's pretty straight forward for your employer to verify your identity and issue a new one.

How do I do that with WhatsApp? We all know how well these tech giants react if you got permanently locked you out of accounts, no matter whose fault it was.

And even if I could get a new key, I would have to explain to all my contacts why my key changed and they would have to re-verify it over a secure channel. It doesn't scale.

Now you might say: just keep multiple copies, but there will be cases where people lose all copies, and depending on how much of our digital lives will be tied to these keys, we will need a secure recovery plan for that.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#42

Earlier quoted context omitted.

How do you know that the AES instruction set on your device's processor doesn't include a backdoor? Sure, the algorithm is public, but how do you know how it was implemented?

AES starts with 16 bytes and then encrypts it to 16 bytes. So there is no good place to hide extra data. Even a single bit that did not meet the AES spec for the key in use would produce complete garbage at decryption. So attempts to leak the key would at least leave a mark.

Unless it’s a timing based leak..

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#43
What I find intriguing is that E2EE was significantly more common long ago than it is today. Multi-protocol chat clients would utilize the OTR libraries meaning 'off the record' and even auto-negotiate with folks over AIM, MSN, ICQ, IRC and others to assist in showing fingerprints and sharing public keys which could be done over the platform or out of band if one so wished.

I would have expected that by today that not only would this be more common but that the technology would have significantly advanced by now. Instead the opposite appears to be true. People are instead using apps that pinky promise to E2EE things and depend on the chat service to handle the trust mechanism for them which in my view entirely defeats the intent and purpose of E2EE. I assume the motivation is the desire to capture and monetize every conversation, especially the private conversations and/or to comply with national security letters. I've heard people try to rationalize this with because non technical people but non technical people were utilizing OTR just fine.

What could realistically be done to reverse this in a way that puts the control back into the individuals hands? i.e. Even if all the kings horses and all the kings men wanted your messages they could only pound sand again and again.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#44
post #5

It's mind blowing e2e is not a standard. I guess the equivalent is looking back and realising cars and homes did not have locks at one stage

Given how everyone uses TLS nowadays, a better analogy would be for the dealership to retain a copy of the key to your car after you buy it. Which would probably upset people but isn't as bad as having no lock at all.

The analogy breaks down a little here.

We don’t want the dealership to keep the key, but we do want them to give us a new one if we lose it.

So afaik we trust the manufacturer to keep the info, and to keep sufficient logs that anyone that abuses it to steal cars can be caught.

I don’t think the way this is works can be extended to communications apps though.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#45
post #11

Earlier quoted context omitted.

This is called "Reproducible Builds". https://signal.org/blog/reproducible-android/

Reproducible builds are for developers. As a user I didn't build the app on my phone. I have a phone with Signal on it. Tell me what I should do to verify it's running the open source Signal code.

Not perfect chain of custody but could report to virustotal (virustotal.com) and compare in a sandbox:

https://play.google.com/store/apps/details?id=com.funnycat.v...

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#46
post #3

Earlier quoted context omitted.

So run free software?

Every free software will have dozens or even hundreds of transitive dependencies. It literally isn't possible for an ordinary person to audit all code. At some point you have to blindly trust.

There us a huge difference between you alone trusting a piece of software and the whole community verifying it at random.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#47

What I find intriguing is that E2EE was significantly more common long ago than it is today. Multi-protocol chat clients would utilize the OTR libraries meaning 'off the record' and even auto-negotiate with folks over AIM, MSN, ICQ, IRC and others to assist in showing fingerprints and sharing public keys which could be done over the platform or out of band if one so wished. I would have expected that by today that no…

This may be due to policy activism on the side of governments.

I think asking service providers to use more E2EE is not the right approach. Governments' intelligence agencies do not shy away from infiltrating commercial vendors (from Yahoo! to the infamous Crypto AG - https://en.wikipedia.org/wiki/Crypto_AG).

1. People should diversify across many, in particular smaller platform, so that surveillance cannot be done as it becomes a scale & long tail problem.

2. People should use P2P E2EE protocols and GPG-encrypted emails. The single biggest step forward would be easier ways to set up public key encrypted email part of e.g. Mozilla Thunderbird and other clients. But in parallel an attitude change is needed, for the receiving end needs to know how to open an encrypted email.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#48

What I find intriguing is that E2EE was significantly more common long ago than it is today. Multi-protocol chat clients would utilize the OTR libraries meaning 'off the record' and even auto-negotiate with folks over AIM, MSN, ICQ, IRC and others to assist in showing fingerprints and sharing public keys which could be done over the platform or out of band if one so wished. I would have expected that by today that no…

I used OTR, but I would not say that it was _more_ common, as that was just a layer over a non E2EE platform like the ones you listed.

Using OTR meant using a non-standard client, installing the plugins for it, and configuring it. Worse, all parties you wanted to chat with had to do it as well. Which means it was almost always a novelty feature among nerdy friends and no one else.

Because most people did not have it installed, having it auto negotiate always was a non-starter. It meant people who didn't have it would recieve cryptic messages from you at the start of each session and then complain to you.

So most of the time it was completely manual process of enabling it for _some_ chats, and this leaks a massive amount of data. It basically declares that for this particular chat sometime might have been interesting. Often the chat log would include a plain text message like "Let's switch to OTR".

Unlike you I could not get any non-technical friends to care about OTR enough to install it. I have difficulty even today getting people interested in Signal. I still hear arguments like "I'm not that interesting, they can look" and "I've got nothing to hide"

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#49
post #6
post #3

Earlier quoted context omitted.

So run free software?

Are you confident enough to audit the free software yourself - or pushing the trust back to someone else?

Our modern society couldn't exist without some trust, but there are huge differences in types of trust and the trustee's underlying motivations.

Trusting the community to audit is like trusting the scientific method. Anyone can find and point out a flaw, which can then be verified by everyone. That's an idyllic description, and the process is quite imperfect, but it's the best we've got.

Meanwhile, trusting a surveillance company to self police is like trusting a quack medicine healer.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#50
post #11

Earlier quoted context omitted.

This is called "Reproducible Builds". https://signal.org/blog/reproducible-android/

Reproducible builds are for developers. As a user I didn't build the app on my phone. I have a phone with Signal on it. Tell me what I should do to verify it's running the open source Signal code.

Reproducible builds benefit the user by allowing independent checks of the software.
Post reply on HN