Live data from Hacker News

Bridgefy, the messenger promoted for mass protests, is a privacy disaster

arstechnica.com

11–20 of 49 posts

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#11
post #8

From the article these attacks allow for: * deanonymizing users * building social graphs of users’ interactions, both in real time and after the fact * decrypting and reading direct messages * impersonating users to anyone else on the network * completely shutting down the network * performing active man-in-the-middle attacks, which allow an adversary not only to read messages, but to tamper with them as well This ap…

You can always ask for a refund of the zero dollar purchase price. :/

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#12
post #11
post #8

From the article these attacks allow for: * deanonymizing users * building social graphs of users’ interactions, both in real time and after the fact * decrypting and reading direct messages * impersonating users to anyone else on the network * completely shutting down the network * performing active man-in-the-middle attacks, which allow an adversary not only to read messages, but to tamper with them as well This ap…

You can always ask for a refund of the zero dollar purchase price. :/

Do you think a company has zero obligations to its users if those users are not paying for the service?

Most of us have never directly paid Google for anything. I think we would still have justification in being upset if there was a central Google flaw that allowed users to view our search or Gmail histories.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#13
post #12
post #11

Earlier quoted context omitted.

You can always ask for a refund of the zero dollar purchase price. :/

Do you think a company has zero obligations to its users if those users are not paying for the service? Most of us have never directly paid Google for anything. I think we would still have justification in being upset if there was a central Google flaw that allowed users to view our search or Gmail histories.

You assume the company is not doing this on purpose, or without intent.

-- There were general flaws w/ Google & gMail to allow governments to snoop in on unencrypted communication. There probably still is.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#15
Does anyone have a design that works for this kind of adhoc meshing network with good privacy guarantees? It seems like a really hard problem to solve, especially the social graph problem because inherently messages will take time to propagate through the network based on proximity. Maybe adding random wait and hop count increments? Efficient routing kind of depends on being able to discover the network graph.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#16
post #10

Learn to use radios (in mass balls-to-the-walls protests).

Isn't that even easier to eavesdrop and/or disrupt?

Jamming is a big step I don't think we've seen in the US so far and I'm not sure the police have that tech readily at hand. Inherently though you're going to want to be able to include people into the network easily which already opens you up to eavesdropping of the public channels. For purely public broadcasts radio is nice because anyone can listen and it doesn't reveal location in the network.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#17
post #10

Learn to use radios (in mass balls-to-the-walls protests).

People do. More than a few hams have been involved in the recent US protests.

Radio has different characteristics that make it an imperfect substitute in protests. The biggest one is that people already have cell phones, but pre-event coordination also becomes much more important, and people have to practice. (Not much, but radio discipline is a thing, and in an emergency you need it.)

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#18
>A key shortcoming that makes many of these attacks possible is that Bridgefy offers no means of cryptographic authentication, which one person uses to prove she’s who she claims to be.

Identity is critical in encrypted messaging. Identity is a hard problem in practice. Very few things do an adequate job. The things that do are awkward and require concepts that few people understand.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#19
post #4

I have noticed that since the protests began there has been a huge influx of my contacts onto Signal and I've gotten a few questions about how to use PGP. I'm glad folks are starting to take privacy in their messengers more seriously, but a lot of the privacy-focused messengers are pretty bad (with Bridgefy being a particularly egregious case). Unfortunately there seems to be a trade off continuum between user friend…

My money is on p2p matrix. It doesn't solve the immediate case Bridgefy does yet (I think it expects to have an internet connection), but it does solve the 'we have to trust central services like signal and or have incredibly difficult ux' scenario somewhat. Metadata resistant to a point etc. Cwtch.im (pronounced couch) is an app I'm looking closely at but doesn't seem to have much movement in terms of shipping new r…

> Cwtch.im (pronounced couch)

You can forget about this one. With a name like that, it isn't going anywhere.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#20

>A key shortcoming that makes many of these attacks possible is that Bridgefy offers no means of cryptographic authentication, which one person uses to prove she’s who she claims to be. Identity is critical in encrypted messaging. Identity is a hard problem in practice. Very few things do an adequate job. The things that do are awkward and require concepts that few people understand.

Somebody needs to expend a bunch of effort to provide identity. It doesn't have to be you (in a PKI the effort is expended by the Certificate Authorities and those overseeing them, not by Relying Parties) but it does have to be somebody you trust.

For personal identity the most plausible outside authority is government, and it's unlikely that people protesting a government would trust it to identify them - after all government counter-protest forces would presumably be able to make use of that against them.

So you're probably screwed in the larger sense. Is this tip that "There is a team with food and water on the North side of the bridge" from "Kirsty" real? Well you haven't the faintest idea who "Kirsty" is so even if you could magically be entirely confident the message is really from "Kirsty" that doesn't help you decide.

Signal does the absolute most it's practical to attempt here, you can choose to check that your friend Kirsty is actually your friend Kirsty by some trustworthy means (e.g. meeting up physically) and then Signal promises you'll know that future messages are really from Kirsty. But trust isn't transitive so PGP's apparently more powerful offering doesn't actually do anything except maybe give you a false sense of security.

Bridgefy doesn't offer even that very limited capability from Signal, but I'm dubious about the practical import for a live protest. I can buy that BLM or Extinction Rebellion which are long-term organisations with sustained buy-in from local organisers benefit from something like that (and indeed ER uses Signal) but individual protests or protesters I don't think so.

Post reply on HN