Live data from Hacker News

Registration without a phone number on Signal will use zero-knowledge proofs

community.signalusers.org

81–90 of 201 posts

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#81
post #14

For those who missed it, unrelated to this specific ZKP thing the release cycle also now permits Android tablets without a SIM to be first-class adjunct devices without using wierd tricks or alternate clients. It may permit them to be the initiation/sign-on device, which would invoke the ZKP, but the point for me as an existing phone number denominated user, the point is I can be on my tablet with true signal now. No…

Thanks for pointing this out. I've been waiting for this for years and was not aware!

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#82

any link to presentations/papers on this? I'm interested on learning ZKPs -- they seem so much like "fairy-tale come true" because I don't know much

It's standard cryptography, not some new-fangled tech! Wikipedia even has some easy examples:

https://en.wikipedia.org/wiki/Zero-knowledge_proof

Main caveat is that ZKPs are probabilistic. The protocol (number of rounds etc) determines how sure, e.g. 99.9%. But never 100%.

Second caveat: tech- and crypto-bros play fast and loose with the term "ZKP", either because they don't know any better (marketing) or they straight up lie. Whether any application you run actually uses ZKP (or any other cryptography scheme) is unknown unless you have the source code.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#83

Earlier quoted context omitted.

"open" is literally in the name, so yes

Apple should make their products edible as well.

'Apple' was a metaphor to Newton. 'Open'AI was meant as a promise; one that they've since broke both to some of their founders as well to the general populace. Reminding people of that broken promise doesn't seem that wild.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#85
post #54

Earlier quoted context omitted.

They avoid Monero because Signal and the EFF are actually the feds and this is all theater.

Claims without evidence can be dismissed without evidence. Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX. If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?…

If I was the NSA, I would be using the fact that signal uses AWS for their backend combined with the cudgel that .us.gov has with the AWS govcloud contract to mandate that all traffic to and from signal's backend also gets routed to NSA traffic analysis servers, which could then be correlated with other sources like ISP data to get a pretty complete record of all Signal message metadata.

To be clear, I use signal pretty heavily, but that's because my threat model doesn't really include competent .us.gov actors. I don't think that they'd either prove they're doing this or go through the trouble of parallel construction over anything in my messages or who I'm talking to.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#86
post #22

Earlier quoted context omitted.

> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not? While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data. I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connect…

It's true someone snooping at either end of a conversation could over time correlate timing and sizes to show that two users are communicating, but that's the most they can do. Signal is not peer to peer so you're not connecting to your recipient, and signal itself has enough raw volume that simply correlating sizes and timing of a small number of messages wouldn't really be sufficient to know who is communicating wi…

> Ex-NSA Chief: 'We Kill People Based on Metadata'

> Hayden made the remark after saying he agreed with the idea that metadata - the information collected by the NSA about phone calls and other communications that does not include content - can tell the government "everything" about anyone it's targeting for surveillance, often making the actual content of the communication unnecessary.

https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-...

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#87

any link to presentations/papers on this? I'm interested on learning ZKPs -- they seem so much like "fairy-tale come true" because I don't know much

I liked this: "I can prove I’ve solved this Sudoku without revealing it" https://youtu.be/Otvcbw6k4eo

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#88

Earlier quoted context omitted.

The big deal is, having talked to security people, they are "fine" with WhatsApp because the theory is, they get data from whatsapp so they have some sort of backdoor access. They are pretty chill with WhatsApp which id unexplainable

Maybe WhatsApp gives them a ton of metadata like all their contacts, when they chat and with who, IPs, etc. Signal only gives out either time registered or last used last time I checked.

WhatsApp uploads decrypted chats to the cloud once a week.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#90
post #54

Earlier quoted context omitted.

They avoid Monero because Signal and the EFF are actually the feds and this is all theater.

Claims without evidence can be dismissed without evidence. Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX. If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?…

Nobody is arguing the e2ee isn't valid, its useful as a metadata collection platform, which is all they care about. Former NSA and CIA Director Michael Hayden famously stated: “We kill people based on metadata." and then he tried to hold back a smile and said "but not with this metadata". It's usefulness as a metadata collection platform becomes much less useful if people don't trust it, so of course it's secure.

If you can convince as many of your enemies (the american people who politically organize against them) to use the same platform, your job becomes easier than having to ETL from 20 different privacy platforms..

To be honest, I use signal, I have nothing to hide but it is useful in that nobody can spoof me (easily). I even talk to my 60 year old mother on signal. It has it's uses. But the EFF is definitely a federal psyop to get people using tools and techniques they control.

Just look at the people who created TOR, they're all feds. All these projects are funded by feds. These tools are advertised in CIA recruitment campaigns, they are literal weapons to circumvent nation state firewalls and deliver psychological weapons, overthrow governments or allow covert recruitment of foreign traitors.

Post reply on HN