Live data from Hacker News

Signal 2.0 released with private messaging support

whispersystems.org

171–174 of 174 posts

Re: Signal 2.0 released with private messaging support

#171
post #169

Earlier quoted context omitted.

That's like saying that SSH isn't more secure than Telnet unless you personally drive to the data center and verify the fingerprints of every single server by hand. In reality, TOFU is a form of key verification and it is highly effective against MITM attacks because there's no way for an adversary to reliably determine whether or not a user is seeing a fingerprint for the first time. If at any point the fingerprint…

I'm talking about absolute terms and you're replying with relative terms. I didn't say that SSH isn't more secure than telnet, I said that you can't be secure against an active MITM unless you verify the keys. That's a fact, I'm not sure how one can argue against it. Sure, TOFU is better than nothing, and might even be very good, but there's still a way for an active adversary to MITM you.

Yeah, I don't think we actually disagree. Key verification is important, which is why it's a feature in Signal.

In order for an active adversary to perform a successful MITM attack against a TOFU scheme they would need to successfully determine when someone is seeing a fingerprint for the first time (or get lucky) and then successfully maintain their MITM position across every single network the device uses, forever. If they fail at either of those, the user will be warned.

I keep bringing up SSH because it's an example of a fingerprint verification system based on TOFU that works incredibly well at preventing MITM attacks. No one is having key signing parties with their servers, and yet connections remain secure.

Re: Signal 2.0 released with private messaging support

#172
post #171

Earlier quoted context omitted.

I'm talking about absolute terms and you're replying with relative terms. I didn't say that SSH isn't more secure than telnet, I said that you can't be secure against an active MITM unless you verify the keys. That's a fact, I'm not sure how one can argue against it. Sure, TOFU is better than nothing, and might even be very good, but there's still a way for an active adversary to MITM you.

Yeah, I don't think we actually disagree. Key verification is important, which is why it's a feature in Signal. In order for an active adversary to perform a successful MITM attack against a TOFU scheme they would need to successfully determine when someone is seeing a fingerprint for the first time (or get lucky) and then successfully maintain their MITM position across every single network the device uses, forever.…

I agree, but it's much easier for me to tell a friend "hey is this your key?" when we're together than go all the way up to my server and connect directly to it. That's why I think that there should be a UI element that says "you're pretty secure, but if you just check this you're golden".

Re: Signal 2.0 released with private messaging support

#173
Seems like it's not tested well. I updated to Signal 2.0 on an iPhone 6 with the latest iOS 8.x. It said that none of my contacts have Signal (that's true) and had a link titled "Invite your friends". Tapping on that took me to the home screen. Killed it and tried a few more times. No use. If it were as usable as Telegram, I'd insist my contacts to switch. But not right now.

Re: Signal 2.0 released with private messaging support

#174
post #77

Earlier quoted context omitted.

Try these: * https://whispertool.cyanogenmod.org/ * https://github.com/daveio/whisperpush-unregister Set up TextSecure with the Voice option, then go to Settings -> untick "Push messages". That should perform unregistration, then you can re-register.

Someone should warn cyanogenmod that their SSL cert is expired: https://www.ssllabs.com/ssltest/analyze.html?d=whispertool.c... (although I guess at 5 months over, it falls squarely into the couldn't-be-bothered bucket)

I went through the steps and unregistered. It looks like it worked. As for the SSL, my hope is that the EFF and Mozilla project will make it easier to deploy https certificates everywhere.
Post reply on HN