Live data from Hacker News

Encrypted messengers: Riot, not Signal, is the future

titus-stahl.de

171–178 of 178 posts

Re: Encrypted messengers: Riot, not Signal, is the future

#171
Riot? Can we talk about the edgy names? Think about how much differently history might have been if Napster was named Library of Alexandria.

"According to Galen, any books found on ships that came into port were taken to the library, and were listed as 'books of the ships'. Official scribes then copied these writings; the originals were kept in the library, and the copies delivered to the owners."

https://en.wikipedia.org/wiki/Library_of_Alexandria

Sounds like Napster, yes? Think about how much harder it would be for Congress to pass laws shutting down the digital equivalent to a library sharing the world's music.

But no. We get names like Riot, and Felony (https://github.com/henryboldi/felony). Congress sends you a "Thank you" every time you put an edgy name on something disruptive.

Re: Encrypted messengers: Riot, not Signal, is the future

#172
post #59

Earlier quoted context omitted.

I agree. Mostly because they're asking for all of those permissions prematurely. What if I never want to share my location, take pictures, or send files? And then some things, like calendar access, aren't even used right now.

> What if I never want to share my location, take pictures, or send files? Don't use these features and / or disable the corresponding permissions.

I get that. I'm just saying that it wouldn't look as bad if they just didn't ask for the permissions upfront.

If I'm about to take a picture for the first time using it then I'll understand it asking for camera access.

Re: Encrypted messengers: Riot, not Signal, is the future

#173

Earlier quoted context omitted.

conflating the specific binary instantiation with the general cryptosystem. Regardless, depending on your threat model, you can take increasingly { reasonable | paranoid } precautions like manually compiling and loading Signal, as it's OSS. edit: "private group" can encompass a lot, especially in other ecosystems like Google and FB. If said "private group" adversary is, say, a prominent and wealthy Silicon Valley bus…

> like manually compiling and loading Signal, as it's OSS. Except, I’d have to modify the code, as the current version depends on Google’s proprietary libs, which I can’t inspect. And I lose half of the functionality, as RedPhone is also proprietary. > by coercing Google or Facebook engineers to run you a Hadoop query or conditionally inject malicious JS. The same can be done by coercing OWS engineers to backdoor the…

> And I lose half of the functionality, as RedPhone is also proprietary.

The source code for the Redphone client is here: https://github.com/WhisperSystems/Signal-Android/tree/master...

The source code the redphone-audio library is here: https://github.com/WhisperSystems/Signal-Android/tree/master...

Stop spreading misinformation.

Re: Encrypted messengers: Riot, not Signal, is the future

#174
post #158

Earlier quoted context omitted.

Which they will ignore.

Cool. If they ignore the great big banner which says "do not enter any personal info, bank info, etc etc into this window" and they're attacked, obviously they didn't care much. In the meantime, people who actually understand security can make a reasonable decision.

Not cool.

First, that's why people like Signal: it just works (TM) encryption with no user gotchas.

Second, any communication is only as encrypted / safe as the minimum of the people with access to it. So if someone ignores warnings and enters that chatroom, he or she puts everyone at risk. Because sometimes she/he really is being MITM or surveilled by someone/oppressive government du jour.

Re: Encrypted messengers: Riot, not Signal, is the future

#175
post #174

Earlier quoted context omitted.

Cool. If they ignore the great big banner which says "do not enter any personal info, bank info, etc etc into this window" and they're attacked, obviously they didn't care much. In the meantime, people who actually understand security can make a reasonable decision.

Not cool. First, that's why people like Signal: it just works (TM) encryption with no user gotchas. Second, any communication is only as encrypted / safe as the minimum of the people with access to it. So if someone ignores warnings and enters that chatroom, he or she puts everyone at risk. Because sometimes she/he really is being MITM or surveilled by someone/oppressive government du jour.

The point is that you wouldn't be able to enter a chatroom at a higher version than your server+client supports - how would the old code be able to understand it, after all? You'd be in pre-upgrade chatrooms, which would display the banner for everyone until relevant people upgrade/get kicked, and you could possibly start new chats with people, which would display the banner for all participants, but if you were on version 5 and #megolm:matrix.org was on version 6, you just couldn't join it until you upgraded.

Re: Encrypted messengers: Riot, not Signal, is the future

#176

Earlier quoted context omitted.

> like manually compiling and loading Signal, as it's OSS. Except, I’d have to modify the code, as the current version depends on Google’s proprietary libs, which I can’t inspect. And I lose half of the functionality, as RedPhone is also proprietary. > by coercing Google or Facebook engineers to run you a Hadoop query or conditionally inject malicious JS. The same can be done by coercing OWS engineers to backdoor the…

> And I lose half of the functionality, as RedPhone is also proprietary. The source code for the Redphone client is here: https://github.com/WhisperSystems/Signal-Android/tree/master... The source code the redphone-audio library is here: https://github.com/WhisperSystems/Signal-Android/tree/master... Stop spreading misinformation.

So it finally got opened? Still doesn’t help me, considering that the Firebase Messaging library compiled into the client is still proprietary.

I can not build Signal from source today.

Re: Encrypted messengers: Riot, not Signal, is the future

#177
post #160

Earlier quoted context omitted.

This is a common misconception: NSLs are a legal tool that can be used to extract certain types of information (such as subscriber information and maybe a little bit of transactional information) that a service provider already has stored on their servers [0]. However, they cannot be used to force a service provider to write and deploy code. [0] NSLs are not magic - https://www.youtube.com/watch?v=YN_qVqgRlx4&t=20m16…

He mentions "technical assistance orders" but doesn't really elaborate any more on them. I'm having a difficult time finding any information on these orders, does anyone else have information on the capability of these orders?

Replying to my own comment, as I found some more information in a Black Hat talk regarding technical assistance orders:

https://youtu.be/PX2RjJAfTYg?t=770

Re: Encrypted messengers: Riot, not Signal, is the future

#178
post #125
post #64

Earlier quoted context omitted.

The scenario I'm imagining is that Google and OWS receive NSLs requiring them to push a modified APK that could do nefarious things.

Google/Apple could also receive a NLS ordering them to write and install a keylogger on your specific device in their next OS update. There's really not much you can do about that.

[dead]
Post reply on HN