Live data from Hacker News

Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

ndss-symposium.org

151–160 of 206 posts

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#151

Earlier quoted context omitted.

In time I expect all OSes (mobile and desktop) will provide a "give false data" option. So Sandboxed+false inputs, sort of a digital Descartes deceiver. Because you know the slimy app developers will refuse to work if you don't hand over your full contact list. and people will just accept that. So the end game is a completely adversarial relationship, even on your own device.

> In time I expect all OSes (mobile and desktop) How much time? This has been a thing in one form or another since j2me. Some j2me platforms actually supported this kind of behavior, but that was all lost once Android and iOS came along. Same with fine-grained permissions over network access (eg, user having complete control over what networks/etc an app can access). We /had/ all of this in the days of BlackBerry, an…

I didn't know that (Blackberry). I would like to know about it, if you have any links.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#152

This scientifically-looking paper could have been written by Captain Obvious himself. It is beyond obvious that contact discovery in any major messenger or social network is facilitated by uploading all contacts from the user’s address book, with all the implied drawbacks. If users' behaviour has shown us anything, it's that they love it. And for all the dangers of their privacy loss, they happily trade it for the co…

"They love it" but they often aren't given the choice, nor are they fully aware of the consequences (I expect many would choose not to accept if the findings in this paper were presented to them in a clear understandable way). The average person barely knows what a server is. They install e.g. WhatsApp on their phone, they are likely to think that the app on their phone is doing the work of telling them who else is o…

In my experience, even after having made fully sure that they understand the risks involved, "the average person" will happily switch back to a walled garden IM platform the moment the next stupid feature comes in.

Last time it was the (I think Whatsapp?) feature that allows, when replying to a message with an attached picture, to highlight a portion of the attached picture. That's it. There was no network effect at this point whasoever. This pseudo-feature was enough for an adult person to decide to switch back to Whatsapp and fuck my and everyone's privacy. THEN the network effect kicks in in favor of Whatsapp, because of course Whatsapp is a walled garden, so everyone is forced to switch to Whatsapp.

I have seen this already happen several times network-wide and I will see it happen again. Non-walled garden IM networks are just set-up to lose.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#153
post #21

Earlier quoted context omitted.

I'm actually fine with the wire approach. But it would be nice if the sender could be notified that the message was never delivered.

Each Wire message has a user-visible status: Failed, Sent or Delivered. It's not obvious, but if status never changes from "Sent", then it wasn't "Delivered".

There's a new icon now as well with an "eyeball" that tells you if the message was viewed. The option for this read receipt can be enabled in the options if both parties enable it.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#154
post #78

Wire (from the creators of Skype) does not mandate a mobile phone number (SIM cards are tied to government identity in many countries). Only an email address is required to open a free account. Nor does Wire mandate upload of your phone's address book with personal social graph of contacts. Free for consumers with paid teams offering for enterprises, optional on-prem server. Open-source clients and server. Cross-devi…

Wire is massively underrated in general. It’s got a slick UI that’s easy for non techies, it’s got native clients on all major platforms, and it has everything you really need from an e2e IM without the fluff. I’m surprised it doesn’t come up more in these discussions and people just “settle” for Signal or another service that needs your phone number etc.

Agreed. I've been using it for years, and much to my surprise I've been able to convert most of my extended family into using it. The fact that our parents (60s-70s) are using it successfully to post and share pictures as well I think is a good sign of it's accessibility. The rich media, good voice/video support, and ease at making multi-user discussions are all excellent. The persistence across devices is excellent, and I love that it's just as easy to use on the desktop as it is on mobile.

I do think there's some improvements that can be made, such as a better visibly into how to sign up without a phone number (I think this is still the default on the phone app) and a more visible download option on their website (the free version is buried under "Resources" -> "Downloads". You can make backups, but there's no easy method to do a plain text export. I get the feeling sometimes messages get "Stuck", and there's been issues in the past with notifications not being sent or push notifications not getting through certain Android sleep states. Sometimes I'll edit a message just to "resend" it such that it's delivered.

Overall though, It's still my secure messanger of choice by far. Glad to see it discussed here.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#155
post #110

Earlier quoted context omitted.

I can't seem to find any information about their free version on that page.

https://app.wire.com/auth/?hl=en#register It's a bit hard to find, looks like they've given up trying to compete for non-business users, but the client has a registration form open to everyone. I think they'll keep supporting this because inviting those 'guest' accounts into rooms of business users is a big feature. We regularly collaborate with people via Wire (customers or freelancers, who can just use their person…

I love wire, but this is one of my biggest pet peeves right now. I can't tell someone to just "go download Wire" on the desktop without giving them navigation instructions ("Resources" menu at the top, then "Downloads" because there's so much focus on the paid products.)

Not a pro move in my opinion.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#156

Imagine my surprise when one can actually give up MORE revealing information about yourself and your contacts just by installing BOTH Telegram and Signal apps. Signal: when you’re most concerned about privacy of your message content. Telegram: when you’re most concerned about association with contacts. WhatsApp: when you’re most concerned about losing your ability to reach out and contact someone. Nothing is absolute…

Matrix: when you are most concerned about losing your message history.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#157

Every time I open the Snapchat Android app it prompts me with a Snapchat-styled (not the system) dialog to share my contacts. Every time I hit "Don't allow". Every time it prompts me again. This is an inexcusable dark pattern. Two things need to happen: 1. The operating system needs to provide a "screw you, never" option for any permissions. 2. We as engineers need to say "screw you, never" to requests to implement b…

The system does have a "screw you, never" option for all permissions. The issue is that Snapchat (in your case, as I don't have this happen on v11.23.3.36) is told that they wont get the permission and wont be able to ask for it either. And so they perform their own inhouse permission request to you. There is nothing that can be done from the system's point of view for that.

The system could supply an empty contact list.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#158
post #130
post #113

Earlier quoted context omitted.

> dumbed-down desktop client That used to be true, but now the desktop client has almost all the feature of the mobile clients. Which feature do you miss there? > Signal clearly has more users (while being worse on privacy) I assume you're talking about the phone number requirement? This is fair criticism, but what about the rest? Signal leaks way less metadata than Wire, which is more similar to WhatsApp in that reg…

For metadata you just have to trust them. Sealed sender doesn't solve that[1], even if it's better than nothing. It's also better than nothing to require no phone number in the first place (Wire), or not to require a payment (like Threema does) which is roughly as hard to make anonymous as getting an anonymous phone number. But either way, they can track everything you send, it's a matter of wanting to. The only way…

> The only way to avoid that is by not sending personal data to semi-/untrusted parties at all (Matrix).

With Matrix you still end up trusting the server sysadmin (both in terms of ethics and technical abilities), it's not like it solves the problem for mass communication where at least one user has to agree on a 3rd-party instance.

> those contacts connect to Signal with an IP address and are doing other things like updating their profile or registering their delivery keys for their account from that same IP address.

Correct me if I'm wrong, but I think that happens within SGX. This in itself is its own can of worms, but assuming it's secure, I don't think you can do this association IP / account that easily. At least it seems so easy to work around that I would expect it to be like this (given that they already use SGX for other things). Now of course SGX is not secure, but it still makes the attacks more expensive and complex than they would be otherwise. If you have access to a Wire server, it would take you minutes to get all the group memberships of one user. If you have access to a Signal server, you'd need to log connections over some time, and do some statistical analysis to extract useful information. Not impossible, but far more costly and less reliable.

In terms of privacy Wire might be better with respect to the phone number requirement, but otherwise Signal has an edge.

The IP address is also something you can solve independently (VPN / Tor), so it makes sense not to solve it within Signal. But it would be nice to have some integration with Tor eventually.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#159
post #106
post #78

Earlier quoted context omitted.

Wire is massively underrated in general. It’s got a slick UI that’s easy for non techies, it’s got native clients on all major platforms, and it has everything you really need from an e2e IM without the fluff. I’m surprised it doesn’t come up more in these discussions and people just “settle” for Signal or another service that needs your phone number etc.

The clients are not actually native, at least on desktop it's just Electron and the mobile clients (Android, iOS) don't feel fast either, but frankly rough edges like these are my only real complaint. Features are available and work everywhere (unlike Signal which has a dumbed-down desktop client and no web client at all), it does everything you generally need and the search is actually superb (better than Telegram e…

The Wire iOS native Arm client is fast and can be made officially available for M1 Arm-based Macs. Looking forward to that, as the Slack iOS Arm client is way faster on my M1 Macbook than the desktop memory-hogging Slack.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#160

Every time I open the Snapchat Android app it prompts me with a Snapchat-styled (not the system) dialog to share my contacts. Every time I hit "Don't allow". Every time it prompts me again. This is an inexcusable dark pattern. Two things need to happen: 1. The operating system needs to provide a "screw you, never" option for any permissions. 2. We as engineers need to say "screw you, never" to requests to implement b…

>We as engineers need to say "screw you, never"

The engineers have spoken. They say, "I'm getting paid too much to care."

Or they look at it from my perspective- who cares? According to you this is an issue but from another perspective there are clueless users who accidentally denied the permission and are grateful later. Can we really afford to have every engineer constantly objecting to the slightest subjective interpretation of what makes a dark pattern?

That's not for me to decide.

Post reply on HN