Live data from Hacker News

Bridgefy, the messenger promoted for mass protests, is a privacy disaster

arstechnica.com

21–30 of 49 posts

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#21
The only usable tool for any organization of resistance is Telegram. Anything else is garbage. Here's why:

Bluetooth/Mesh based local broadcast apps such as FireChat and Bridgfy are literally extreme low signal to noise streams of thoughts coming from everyone around you. We don't even need to get to the privacy or security part to eliminate it due to it being completely unusable in areas with more than a couple people.

Signal:

Slow, requires phone number to register and access to contacts. Users still receive messages after leaving a group, and the history still remain on the desktop app. Disappearing messages disappeared on the phone you'll still get it after it purported it have disappeared.

Wire:

Extremely slow.

Why is Telegram good?

* Super fast

* Good balance of security and usability.

* Early flaws in mtproto has largely been fixed.

* You can choose a username, instead of a phone number

* Good privacy settings to select who can find you, how to find you, who can call you, who can pull you into group chats etc.

* Desktop app has feature parity with the mobile apps. No glaring flaws found in Signal.

* Operationally extremely battle tested by successful protests around the world such as Hong Kong, Iran and Belarus.

* Any problems found on the ground, when reported, will be fixed in a matter of days to weeks by Telegram. They are that responsive.

Words of advise to Silicon Valley companies and security professionals in general. Stop bashing Telegram and actually go and try using your proposed alternatives in protests. Most if not all of these so-called secure chats are completely unusable for any organizations trying to avoid being arrested or be used as evidence against you.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#22
post #15

Does anyone have a design that works for this kind of adhoc meshing network with good privacy guarantees? It seems like a really hard problem to solve, especially the social graph problem because inherently messages will take time to propagate through the network based on proximity. Maybe adding random wait and hop count increments? Efficient routing kind of depends on being able to discover the network graph.

Briar works quite well, but due to the darknet nature you only exchange data with those you paired with (by exchanging a "link" via some other channel or meeting in-person and scanning a QR code on each other's device (then followed by a short wireless p2p exchange to properly exchange all required information)).

It's afaik android-only, and doesn't use nodes as relays for private messages.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#23
post #4

I have noticed that since the protests began there has been a huge influx of my contacts onto Signal and I've gotten a few questions about how to use PGP. I'm glad folks are starting to take privacy in their messengers more seriously, but a lot of the privacy-focused messengers are pretty bad (with Bridgefy being a particularly egregious case). Unfortunately there seems to be a trade off continuum between user friend…

My money is on p2p matrix. It doesn't solve the immediate case Bridgefy does yet (I think it expects to have an internet connection), but it does solve the 'we have to trust central services like signal and or have incredibly difficult ux' scenario somewhat. Metadata resistant to a point etc. Cwtch.im (pronounced couch) is an app I'm looking closely at but doesn't seem to have much movement in terms of shipping new r…

I can't wait to see more progress with p2p matrix. I hope there will be one flavor that will allow privacy/anonymity.

I mean I see the advantages of p2p for a more resilient network. Which is great when the internet is shut down but I also hope there will be some way to protect the people's identities.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#24
post #8

From the article these attacks allow for: * deanonymizing users * building social graphs of users’ interactions, both in real time and after the fact * decrypting and reading direct messages * impersonating users to anyone else on the network * completely shutting down the network * performing active man-in-the-middle attacks, which allow an adversary not only to read messages, but to tamper with them as well This ap…

> Doesn't that qualify as some sort of fraud or false advertising?

Fraud typically requires some sort of mens rea. It sounds to me like Bridgefy is just really bad as making secure applications.

> If not, I wonder if we need further regulation to protect the public from developers that are either incompetent or straight malicious.

There is a long history of people trying to create liability for software bugs. It was a bad idea then and it's still a bad idea today.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#25
post #21

The only usable tool for any organization of resistance is Telegram. Anything else is garbage. Here's why: Bluetooth/Mesh based local broadcast apps such as FireChat and Bridgfy are literally extreme low signal to noise streams of thoughts coming from everyone around you. We don't even need to get to the privacy or security part to eliminate it due to it being completely unusable in areas with more than a couple peop…

> You can choose a username, instead of a phone number

Unless this has changed recently -- and I can't find any indication that it has -- this is not true. You can choose a username in addition to a phone number, but you must have a phone number. Your username is effectively an alias for your number; your account is tied to the number, not the username.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#26
post #21

The only usable tool for any organization of resistance is Telegram. Anything else is garbage. Here's why: Bluetooth/Mesh based local broadcast apps such as FireChat and Bridgfy are literally extreme low signal to noise streams of thoughts coming from everyone around you. We don't even need to get to the privacy or security part to eliminate it due to it being completely unusable in areas with more than a couple peop…

But in Hong Kong's case, a number of Telegram chat room operators have been prosecuted by the police for anti-government activities. If TG is really secure then this shouldn't have happened.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#27
post #21

The only usable tool for any organization of resistance is Telegram. Anything else is garbage. Here's why: Bluetooth/Mesh based local broadcast apps such as FireChat and Bridgfy are literally extreme low signal to noise streams of thoughts coming from everyone around you. We don't even need to get to the privacy or security part to eliminate it due to it being completely unusable in areas with more than a couple peop…

But in Hong Kong's case, a number of Telegram chat room operators have been prosecuted by the police for anti-government activities. If TG is really secure then this shouldn't have happened.

How can you be sure the chat rooms weren't simply infiltrated?

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#28
post #21

The only usable tool for any organization of resistance is Telegram. Anything else is garbage. Here's why: Bluetooth/Mesh based local broadcast apps such as FireChat and Bridgfy are literally extreme low signal to noise streams of thoughts coming from everyone around you. We don't even need to get to the privacy or security part to eliminate it due to it being completely unusable in areas with more than a couple peop…

> You can choose a username, instead of a phone number Unless this has changed recently -- and I can't find any indication that it has -- this is not true. You can choose a username in addition to a phone number, but you must have a phone number. Your username is effectively an alias for your number; your account is tied to the number, not the username.

Good point. I think a better description is both the phone number and the username are tied to the account, and you can change both at will. There are enough privacy settings in Telegram that can effectively turn off having your phone number show up anywhere. You disable contact syncing and even delete synced contacts.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#29

>A key shortcoming that makes many of these attacks possible is that Bridgefy offers no means of cryptographic authentication, which one person uses to prove she’s who she claims to be. Identity is critical in encrypted messaging. Identity is a hard problem in practice. Very few things do an adequate job. The things that do are awkward and require concepts that few people understand.

Somebody needs to expend a bunch of effort to provide identity. It doesn't have to be you (in a PKI the effort is expended by the Certificate Authorities and those overseeing them, not by Relying Parties) but it does have to be somebody you trust. For personal identity the most plausible outside authority is government, and it's unlikely that people protesting a government would trust it to identify them - after all…

> But trust isn't transitive so PGP's apparently more powerful offering doesn't actually do anything ...

Trust in the abstract isn't inherently transitive, agreed. I'd argue that employing PGP as though it were is misusing the tool (that might well be easier to do than it ought to be, but that's a different conversation).

WoT as realized by PGP seems to me to be a very good tool for manually assessing whether to trust a previously unknown key for someone that a third (untrusted) party sends you.

I remain highly optimistic that some future take on the WoT concept will be advanced enough to tackle trust in general in a distributed manner.

Re: Bridgefy, the messenger promoted for mass protests, is a privacy disaster

#30
post #10

Learn to use radios (in mass balls-to-the-walls protests).

Isn't that even easier to eavesdrop and/or disrupt?

Probably harder to disrupt (cell networks, WiFi, and Bluetooth are all specialized, relatively low power radios after all).

In the US, legal radio usage would be easier to eavesdrop on (I believe encryption is effectively banned). But if you're willing to ignore that detail then it won't be easy to eavesdrop on you.

It would be trivial for a state funded adversary to triangulate broadcasters though.

Post reply on HN