Live data from Hacker News

TextSecure's Private Group Messaging

whispersystems.org

41–50 of 109 posts

Re: TextSecure's Private Group Messaging

#41
post #40
post #2

The fact that transcript consistency is waved aside, despite being an essential property of a messaging protocol especially in a group context, is problematic, from my perspective. Consider a group chat between Alice, Bob, and Carol. With this protocol, Alice can selectively send different messages to Bob and Carol with both of them thinking they got the same message. For example, Alice can tell Bob "The funds were t…

> For example, Alice can tell Bob "The funds were transferred, thanks!" and tell Carol "Bob is stealing money." — and the protocol will ascribe integrity to the messages for both participants and label them as the same message. Isn't this trivially possible in Cryptocat for anyone who controls the server?

I don't think it would be trivial (it's likely possible to some degree, but authentication and integrity checks might make it slightly more difficult), but the issue with this protocol is that you don't even need server control — any client with TextSecure installed can do this.

Note: I don't mean to disparage TextSecure by saying this. By all means, TextSecure is a kickass app and you should use it. I'm just trying to point out something that could be fixed in a future update.

Re: TextSecure's Private Group Messaging

#42
post #40

Earlier quoted context omitted.

> For example, Alice can tell Bob "The funds were transferred, thanks!" and tell Carol "Bob is stealing money." — and the protocol will ascribe integrity to the messages for both participants and label them as the same message. Isn't this trivially possible in Cryptocat for anyone who controls the server?

I don't think it would be trivial (it's likely possible to some degree, but authentication and integrity checks might make it slightly more difficult), but the issue with this protocol is that you don't even need server control — any client with TextSecure installed can do this. Note: I don't mean to disparage TextSecure by saying this. By all means, TextSecure is a kickass app and you should use it. I'm just trying…

It seems pretty trivial to me. Can't you just send different messages to different people?

Re: TextSecure's Private Group Messaging

#43
post #21

Earlier quoted context omitted.

Despite the fact that you've fleshed your responses out from single sentences to whole paragraphs, there is still no technical content in this comment that addresses my comment. It appears that your response is "no, we don't properly do transcript consistency either, but we're working on it". But I had to read between the lines of your name-dropping comment to come to that conclusion. An uninformed reader of your roo…

jesus christ fuck already

No thank you.

Re: TextSecure's Private Group Messaging

#44
post #18

I'm a big fan of TextSecure and recommended it to all my friends, both those in IT and 'normal' people. Usually, I managed to convince them that the open source nature of TextSecure and the crypto experts behind it (e.g. Moxie) make it more secure than Threema/... . However, the more sceptical ones among my friends always asked two questions, which I didn't have a good answer for: 1. What is TextSecure's business mod…

Afaik TextSecures server infrastructure consists mainly of Google Play Services which comes at no financial costs for them but with the downside of depending on Google to temporary store encrypted text.

I would rather pay a nominal fee to support their infrastructure than have to rely on Google Play Services for a supposedly "secure" messaging service.

Re: TextSecure's Private Group Messaging

#45
I wished moxie would have discussed more the group management aspects.

> Anyone can create a group, name it, give it an avatar icon, add members, and then everyone can chat together with a normal asynchronous experience.

Does this mean that any group member can add more members? Are there any IRC-like moderation features (even planned?), eg. privileged members who can remove users from group? Is there support for persistent groups (ie IRC channel equivalents)?

Re: TextSecure's Private Group Messaging

#46

I'm a big fan of TextSecure and recommended it to all my friends, both those in IT and 'normal' people. Usually, I managed to convince them that the open source nature of TextSecure and the crypto experts behind it (e.g. Moxie) make it more secure than Threema/... . However, the more sceptical ones among my friends always asked two questions, which I didn't have a good answer for: 1. What is TextSecure's business mod…

> 1. What is TextSecure's business model? Who pays for the server infrastructure?

It's a good question. TextSecure is not a business, so we don't really have a business model in the traditional sense. Open Whisper Systems is a collective project made up of volunteers and a growing number of contributors, who are sometimes paid by donations (https://whispersystems.org/blog/bithub/) and grants.

Thus far, we've been able to smoothly fund the server infrastructure through grants and donations as well. I think we'll probably be able to continue that way indefinitely, but if that ever changed for any reason, we would consider charging small amounts for premium or high cost features like extremely large attachments. But in general, Open Whisper Systems is a project rather than a company, and the project's objective is not financial profit. I know that's a difficult thing to explain.

> 2. Doesn't WhisperSystems belong to Twitter? Twitter is a US-company (and also part of the NSA stuff), so why should I use that kind of software?

This is also confusing, but Open Whisper Systems is not Whisper Systems. Open Whisper Systems has no relationship with Twitter at all, and is a different organization that came together to facilitate development of the Whisper Systems software which was released under GPLv3. Twitter has never contributed money or resources to Open Whisper Systems, and is not in control of any of the infrastructure.

Re: TextSecure's Private Group Messaging

#47
post #30
post #28

Earlier quoted context omitted.

gj implying on twitter that your followers should upvote your comments lol https://i.imgur.com/FI6IdaO.png

That is incredibly annoying, because it will probably have the effect of setting off the ring detector and burying the story, which is too bad, because the TextSecure post we're talking about here is excellent. I'll let the mods know. Thanks for catching this.

Looks like he has two accounts too...

Re: TextSecure's Private Group Messaging

#48
post #46

I'm a big fan of TextSecure and recommended it to all my friends, both those in IT and 'normal' people. Usually, I managed to convince them that the open source nature of TextSecure and the crypto experts behind it (e.g. Moxie) make it more secure than Threema/... . However, the more sceptical ones among my friends always asked two questions, which I didn't have a good answer for: 1. What is TextSecure's business mod…

> 1. What is TextSecure's business model? Who pays for the server infrastructure? It's a good question. TextSecure is not a business, so we don't really have a business model in the traditional sense. Open Whisper Systems is a collective project made up of volunteers and a growing number of contributors, who are sometimes paid by donations ( https://whispersystems.org/blog/bithub/ ) and grants. Thus far, we've been a…

That is indeed confusing. Because the names are so similar, there is an implied close relationship between these two entities. Have you considered renaming the project?

Re: TextSecure's Private Group Messaging

#49
post #7
post #6

Earlier quoted context omitted.

This post says that TextSecure implements transcript consistency in the protocol, and in a fashion objectively superior to that of mpOTR: the TextSecure protocol can provide continuous consistency checks, while mpOTR can do so only when the session is torn down. What the TextSecure client does not yet do is provide a UI for that feature of the protocol. Further, it's hard to understand how transcript consistency coul…

I'm quite certain that the current TextSecure chat allows my proposed scenario with Alice, Bob and Carol to go through without issue. This is the main problem here. So while transcript consistency is discussed in the blog post, it remains the case that Alice can send a different message to Bob and Carol without being detected.

I'm quite certain that the current TextSecure chat allows my proposed scenario with Alice, Bob and Carol to go through without issue. This is the main problem here. So while transcript consistency is discussed in the blog post, it remains the case that Alice can send a different message to Bob and Carol without being detected.

Are you sure this is correct? From the blog post, it seems like this is impossible:

https://whispersystems.org/blog/images/groups-pairwise-optim...

However, there’s an optimization we can make for longer messages and media. The sending client generates an ephemeral symmetric key K, encrypts the message with K (C = EK(P)), and then transmits a single copy of the ciphertext (C) along with the pairwise encryptions of the plaintext hash and the small key K:

So, when a client wants to send a message to the group (like "How are you?") under this scheme, the client encrypts the message using a random encryption key K, yielding message ciphertext C. The client transmits to the server, then the server sends C to every other member of the group.

Since C can only be decrypted by someone who knows K, our client must of course send K to every other member of the group. This is easily accomplished: the client encrypts K once per other member. So, if there are N members in the group, this yields N-1 small ciphertexts. Let's call them "key ciphertexts". These "key ciphertexts" are sent to the server and routed to the appropriate recipient, who decrypts it, thus receiving K. Then the recipient decrypts C using K, yielding the client's original message ("How are you?").

So even though the client is indeed generating a ciphertext per recipient, that ciphertext contains nothing but the decryption key K. It doesn't contain the client's actual message. The actual message is contained in ciphertext C, which is generated by the client and sent to the server only once, and C is relayed verbatim to every other member. That's why I say your attack seems impossible: every member has the same message ciphertext, C, so there's no opportunity for a malicious client to send different message ciphertexts to different clients.)

As long as TextSecure uses this implementation of group messaging, then your attack shouldn't be possible, right?

Re: TextSecure's Private Group Messaging

#50
post #46

I'm a big fan of TextSecure and recommended it to all my friends, both those in IT and 'normal' people. Usually, I managed to convince them that the open source nature of TextSecure and the crypto experts behind it (e.g. Moxie) make it more secure than Threema/... . However, the more sceptical ones among my friends always asked two questions, which I didn't have a good answer for: 1. What is TextSecure's business mod…

> 1. What is TextSecure's business model? Who pays for the server infrastructure? It's a good question. TextSecure is not a business, so we don't really have a business model in the traditional sense. Open Whisper Systems is a collective project made up of volunteers and a growing number of contributors, who are sometimes paid by donations ( https://whispersystems.org/blog/bithub/ ) and grants. Thus far, we've been a…

Hey moxie, I recently myself switched to using TextSecure (mostly was just looking from an SMS app from reputable people, but the crypto parts are a nice bonus). The above question about the business model was also my first question after my initial evaluation. It would be awesome if you could put this info somewhere on the website (maybe I missed it?).
Post reply on HN