Earlier quoted context omitted.
Another feature of Keybase's exploding messages is that when they expire, the text is replaced by the md5sum of the message. So a faked screenshot can (potentially; I haven't verified this) be proven to be faked by appealing to the md5sum in its place, crucially, without needing to reveal the contents of the original message.
That would only work if everything else about the photo was identical - device, resolution, carrier, time, battery level. Seems very unlikely one could substitute even identical text in a screenshot with enough accuracy to get the same hash from an image file.
Keybase Exploding Messages
131–140 of 155 posts
Re: Keybase Exploding Messages
#132anyone care to expand on the practical applications/implications/threat model where this makes sense?
It's for when you trust someone but don't want to risk either your or their device being compromised in the future. For instance: - if your or their phone gets taken at a border crossing - if your or their phone gets taken by the FBI (which is how they recovered encrypted WhatsApp/Signal chats from Michael Cohen's phone) - etc
Months later the relationship turns sour, and they are fired or denied a promotion. They can't then go through the archives any more to take the screenshots.
Re: Keybase Exploding Messages
#133Earlier quoted context omitted.
That would only work if everything else about the photo was identical - device, resolution, carrier, time, battery level. Seems very unlikely one could substitute even identical text in a screenshot with enough accuracy to get the same hash from an image file.
The md5sum would be of the message itself, not the illicit screenshot.
Re: Keybase Exploding Messages
#134Earlier quoted context omitted.
The most important purpose of these exploding message capabilities is destruction of data that doesn’t need to be archived. The primary threat is compromise of a device. Keybase allows you to revoke keys but that assumes you are aware that the device has been compromised. Which is already too late for sensitive messages. The average user doesn’t understand data persistence, or secure destruction of data. Manafort is…
As a user of messaging services, I nearly never want to delete a message. I want to be able to use my digital memory extension (phone) to store messages so that I can easily recall my conversations. Rarely do I want to delete a message. In fact, I would only want to delete it if it's sensitive: I rarely message such sensitive things. Most people fall into this camp. It's rare for someone to never want any message to…
Re: Keybase Exploding Messages
#135As a security layperson my initial reaction was "how can cryptography help with expiring messages, once it's decrypted it's decrypted, that doesn't sound right", but I'm curious if I'm understanding correctly that this is actually two separate features: 1) clients voluntarily respecting "please delete this message at X time" and 2) forward secrecy. And Keybase has tied them together for UX reasons since people tend t…
Re: Keybase Exploding Messages
#136Earlier quoted context omitted.
As a user of messaging services, I nearly never want to delete a message. I want to be able to use my digital memory extension (phone) to store messages so that I can easily recall my conversations. Rarely do I want to delete a message. In fact, I would only want to delete it if it's sensitive: I rarely message such sensitive things. Most people fall into this camp. It's rare for someone to never want any message to…
I deliberately don't pay for Slack because of this. The 10,000 message limit is perfect for "enough memory to be useful, not enough to be dangerous". I'd love to see it as a feature in other messaging apps (i.e. "permanently erase all messages over 6 months old")
Re: Keybase Exploding Messages
#137Earlier quoted context omitted.
> SnapChat, as far as I know, has none of the cryptographic implementation of Keybase. And yet it has likely protected hundreds of thousands of kids from severe bullying. Is this true? (Asking with no implication of criticism or being a leading question - I just genuinely don't know the answer) I can believe both that these teens were going to sext each other anyway and Snapchat is keeping them safer, or that they we…
I would also expect people's propensity to take screenshots to be correlated to how sensitive the image is. For example, I would expect many people to take a screenshot of a nude pic their partner sent just so they can look at it for longer than the default timeout of a snapchat message; this is even more likely for teenagers who may be less mature about not betraying the other person's trust.
Re: Keybase Exploding Messages
#138Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you se…
I love this! And I love the bomb gif. I still miss your original logo, but have come to like the little girl. Anyway, maybe it's just me, but I never communicate anything to anyone that would be hugely problematic if published. That is, for that persona. Which is carefully compartmentalized from other personas. So Mirimir has rather restrictive limits. My meatspace identity has even more restrictive limits. But some…
Re: Keybase Exploding Messages
#139Earlier quoted context omitted.
Photo, audio, and video evidence should already be dismissed until one is able to verify the integrity and source. All of these can already be believably faked - it's just a matter of educating people that a layperson can easily create fake things by using tools developed by research teams. Fake text is the easiest to fake if you can identify the font used - any image editor will work. HN uses 9pt Verdana, even witho…
Not even that much effort, just open the browser's dev tools and change the text in the post to say whatever you like.
Re: Keybase Exploding Messages
#140Earlier quoted context omitted.
I'm not entirely sure what your issue is here. Why not reprovision (either with a different provisioned device or your paper key) and give it a new name?
Because it's the same device as before. I only have one name for it.