Live data from Hacker News

Messenger systems compared by security, privacy, compatibility, and features

docs.google.com

101–110 of 242 posts

Re: Messenger systems compared by security, privacy, compatibility, and features

#102
post #80
post #45

This is neat but it has plenty of flaws. I wish the definitions were spelled out. It says Signal isn't "anonymous", which I assume means "uses a phone number to find peers". And it has the usual feature matrix problem: sure XMPP "does E2E". But what does that mean? It supports S/MIME. Do you want S/MIME? (You don't.) It supports OTR, TS and SCIMP too: but you need to be an expert in messaging schemes to understand ho…

> It supports S/MIME. Do you want S/MIME? (You don't.) Could you provide your source? I've never seen S/MIME used in XMPP. Client certificates for authentication sure but not for E2E security. > It supports OTR, TS and SCIMP too: but you need to be an expert in messaging schemes to understand how those are different. OTR is being rolled back from clients in favor of OMEMO for good reasons: https://conversations.im/om…

S/MIME for XMPP E2E: https://xmpp.org/rfcs/rfc3923.html

I am aware that OTR is being rolled back. My point is that extensibility is at odds with practical security and privacy for the vast majority of users. The people who need it the most do not understand the difference between OMEMO and OTR, but I can tell them to go install WhatsApp or Signal, give them a rough idea of why you want one or the other, and everything will be copacetic.

Re: Messenger systems compared by security, privacy, compatibility, and features

#103
post #100
post #73

Earlier quoted context omitted.

Fair enough, but this is kind of inherent for anything based on open standards. Was your email encrypted? It depends on whether the sending and receiving mailserver support TLS. Is your website visit perfect-forward-secret? Depends on whether your browser and the webserver support modern cipher suites. Is your DNS request encrypted? Only if your OS and your DNS server support DNSSEC or DoH. These are valid challenges…

How do I know my XMPP client is actually doing what it says? Are you saying the provenance for my XMPP client is fundamentally better than that of the WhatsApp app?

OMEMO and its implementation in Conversations has been security audited by an independent entity.

Other than that, sure, you have no guarantees, yet it's still desirable for such critical security components to be free, or at least "open source".

Re: Messenger systems compared by security, privacy, compatibility, and features

#104
post #28

What is the data source for all of these? I'm particularly curious about a number of the "claimed" entries.

+1 It seems like someone just created a spreadsheet with no description of what methodology was used to test the assertions.

If you click the cells you will see the rationale for columns or what "claimed" means etc.

Re: Messenger systems compared by security, privacy, compatibility, and features

#105
post #100

Earlier quoted context omitted.

How do I know my XMPP client is actually doing what it says? Are you saying the provenance for my XMPP client is fundamentally better than that of the WhatsApp app?

OMEMO and its implementation in Conversations has been security audited by an independent entity. Other than that, sure, you have no guarantees, yet it's still desirable for such critical security components to be free, or at least "open source".

> it's still desirable for such critical security components to be free, or at least "open source".

Why the scare quotes?

What about software's source code being available makes it more desirable for your non-technical users who will never modify their software?

Re: Messenger systems compared by security, privacy, compatibility, and features

#106
post #45

This is neat but it has plenty of flaws. I wish the definitions were spelled out. It says Signal isn't "anonymous", which I assume means "uses a phone number to find peers". And it has the usual feature matrix problem: sure XMPP "does E2E". But what does that mean? It supports S/MIME. Do you want S/MIME? (You don't.) It supports OTR, TS and SCIMP too: but you need to be an expert in messaging schemes to understand ho…

Typo correction, but I can no longer edit: WhatsApp uses the Signal protocol, just with fewer of the privacy tweaks in the implementation. The criteria don't seem to consider those. They're important, but the two should be equivalent.

Re: Messenger systems compared by security, privacy, compatibility, and features

#107
post #100

Earlier quoted context omitted.

How do I know my XMPP client is actually doing what it says? Are you saying the provenance for my XMPP client is fundamentally better than that of the WhatsApp app?

OMEMO and its implementation in Conversations has been security audited by an independent entity. Other than that, sure, you have no guarantees, yet it's still desirable for such critical security components to be free, or at least "open source".

That's all fine but not responsive to my point. GP post said "but what if whatsapp silently hamstrings e2e overnight" -- my point is: what if my XMPP client/server does?

EDIT: I previously said "turns off E2E", which I didn't say in my original referred-to post, and that's more misleading than "hamstrings", which is how the actual attack works.

Re: Messenger systems compared by security, privacy, compatibility, and features

#108
post #107

Earlier quoted context omitted.

OMEMO and its implementation in Conversations has been security audited by an independent entity. Other than that, sure, you have no guarantees, yet it's still desirable for such critical security components to be free, or at least "open source".

That's all fine but not responsive to my point. GP post said "but what if whatsapp silently hamstrings e2e overnight" -- my point is: what if my XMPP client/server does? EDIT: I previously said "turns off E2E", which I didn't say in my original referred-to post, and that's more misleading than "hamstrings", which is how the actual attack works.

If your server does, your client will notice. If your client does, the other party's client will notice.

Re: Messenger systems compared by security, privacy, compatibility, and features

#109
post #85
post #45

This is neat but it has plenty of flaws. I wish the definitions were spelled out. It says Signal isn't "anonymous", which I assume means "uses a phone number to find peers". And it has the usual feature matrix problem: sure XMPP "does E2E". But what does that mean? It supports S/MIME. Do you want S/MIME? (You don't.) It supports OTR, TS and SCIMP too: but you need to be an expert in messaging schemes to understand ho…

> Use WhatsApp to talk to normal people. Use Signal for nerds. This has been my go-to advice for a while now too! The key driving point is that amazing crypto is 100% useless if the person you're talking to doesn't use it, or uses it incorrectly. The only sticking point with the above advice is the nerds who think they understand crypto but don't and insist on you using some crazy app :/

Consider that security you can't possibly verify is just marketing.

Maybe try listening to those nerds and try out some open alternatives with security that is possible to verify.

You might be surprised to find both tools are pretty low on the list in respect to security and privacy compared to tools with smaller marketing budgets.

Re: Messenger systems compared by security, privacy, compatibility, and features

#110

I can't see Jitsi there

also, what about 'blockchain messaging' apps like Dust, Echo etc. ?

Dust is woefully underspecified and uses an ancient design with no forward secrecy and no (specified) message or sender authentication of any kind.

Blockchain, as usual, purports to solve a problem nobody had. Dust doesn't try to address the simplest, best-understood problems we have for reputation systems on chained blocks.

Post reply on HN