Live data from Hacker News

Soatok's Informal Guide to Threat Models

soatok.blog

21–30 of 55 posts

Re: Soatok's Informal Guide to Threat Models

#21

Earlier quoted context omitted.

> you made the argument that we should abandon ECC by not doing hybrid, Where did I ever make that argument? In both TFA and my previous blog post, I've made it abundantly clear that I'm pro-hybrid. My argument is simply: 1. The claimed benefits of ECDH hybridization evaporate immediately the moment Q-Day happens. No one disputes this. 2. Harvest Now, Decrypt Later (HNDL) is the primary threat we face today during th…

In your PQ safety blanket article https://soatok.blog/2026/04/13/hybrid-constructions-the-post... you make it pretty clear the reason you support hybrid is tactical, not cryptographic. Your wording ("Once Q-Day happens") strongly suggests Q-Day will happen, like, it’s so certain you don’t even need to state it explicitly, you can just assume it will. And your references to the PQ timeline give the impression that you…

> In your PQ safety blanket article https://soatok.blog/2026/04/13/hybrid-constructions-the-post... you make it pretty clear the reason you support hybrid is tactical, not cryptographic.

What does it matter that my public arguments are tactical? Hybrid gets us to PQ faster, which makes progress on plugging up the HNDL risk.

> Your wording ("Once Q-Day happens") strongly suggests Q-Day will happen, like, it’s so certain you don’t even need to state it explicitly, you can just assume it will.

The literal opening section is talking about recent changes in direction from large Internet providers about quantum computing risks.

The rest of the article is predicated on "these companies' risk assessment turns out to be correct".

Separately, in https://soatok.blog/2024/09/13/e2ee-for-the-fediverse-update... I wrote more about my actual beliefs about the likelihood of Q-Day.

> It’s pretty clear from there that you think ECDH is now technically useless, and the only real justification for hybrid schemes (as opposed to pure PQ), is to reassure the people still unsure about the likes of ML-KEM. Sure you still do recommend going hybrid, but from what I can tell, you would have preferred a world where we go pure PQ right away.

You are extrapolating from the subsidiary clause of an if statement whose truth value I do not claim to know.

> And so would I to be honest (if ECC is a bust): one algorithm is simpler and faster than two.

Sure.

Re: Soatok's Informal Guide to Threat Models

#22
post #16

Maybe I shouldn't, but I stopped taking the author seriously for their lack of nuance/extremely biased views favouring Signal in every article about E2EE applied to IM. But I do agree that threat modeling is just a support to formalize and document the variables in the threat equation. It doesn't say anything about whether the threat is reasonable, legitimate and grounded in reality, so it's only knocking the subject…

Does one have to be nuanced in everything one says? I'm not a fan of Signal's threat model, especially their historical threat models (e.g. acting like it's safe to link users to phone numbers, and then advertise which phone numbers are and aren't using Signal), but Signal's main protocol seems pretty solid, especially compared to some other systems.

Re: Soatok's Informal Guide to Threat Models

#23
post #16

Maybe I shouldn't, but I stopped taking the author seriously for their lack of nuance/extremely biased views favouring Signal in every article about E2EE applied to IM. But I do agree that threat modeling is just a support to formalize and document the variables in the threat equation. It doesn't say anything about whether the threat is reasonable, legitimate and grounded in reality, so it's only knocking the subject…

Does one have to be nuanced in everything one says? I'm not a fan of Signal's threat model, especially their historical threat models (e.g. acting like it's safe to link users to phone numbers, and then advertise which phone numbers are and aren't using Signal), but Signal's main protocol seems pretty solid, especially compared to some other systems.

Maybe it's because I'm a bad writer, but I've heard from at least a half dozen people in recent years that they think I'm too pro-Signal when my actual stance wasn't "Signal is good" but rather "all these so-called alternatives suck ass when it comes to cryptography implementations".

Signal pisses me off in a lot of ways.

If someone joins a group chat and posts horrific content, the admins cannot clean it up. This extremely basic functionality doesn't meet the most basic bar for group moderation and safety tools. This means a troll posting a high-frequency flashing GIF to a group chat full of epileptic people is going to cause real harm. This means someone joining a chat and posting unsolicited CSAM will legally imperil everyone present and the admins are powerless to intervene at all. They seem really indifferent on fixing this.

I would love for an alternative app to materialize that provided the same level of cryptographic excellence as Signal but without the enormous ego of their marketing teams or evangelists, which actually put a microgram of care into user experience and community safety. None of the alternatives people raise meet the bar, and I find it extremely disingenuous when people insist their privacy (which is a second-order property from their cryptographic implementations) is somehow "better than Signal". So when people do this, I tend to 0day their favored apps.

https://soatok.blog/encrypted-messaging-apps/

We, collectively, as an industry, should be able to do better. That we haven't is depressing.

Re: Soatok's Informal Guide to Threat Models

#25

Earlier quoted context omitted.

Does one have to be nuanced in everything one says? I'm not a fan of Signal's threat model, especially their historical threat models (e.g. acting like it's safe to link users to phone numbers, and then advertise which phone numbers are and aren't using Signal), but Signal's main protocol seems pretty solid, especially compared to some other systems.

Maybe it's because I'm a bad writer, but I've heard from at least a half dozen people in recent years that they think I'm too pro-Signal when my actual stance wasn't "Signal is good" but rather "all these so-called alternatives suck ass when it comes to cryptography implementations". Signal pisses me off in a lot of ways. If someone joins a group chat and posts horrific content, the admins cannot clean it up . This e…

You've written about the minimum bar before (https://soatok.blog/2024/07/31/what-does-it-mean-to-be-a-sig...). Have you written up your Signal criticisms / desired features anywhere? (Or, do you know where anyone else has?)

I have my own ideas about requirements, but they're not concrete enough to say "requirements analysis done, let's start programming"; and most people I talk to haven't thought about this enough to be helpful.

Re: Soatok's Informal Guide to Threat Models

#26

Earlier quoted context omitted.

Maybe it's because I'm a bad writer, but I've heard from at least a half dozen people in recent years that they think I'm too pro-Signal when my actual stance wasn't "Signal is good" but rather "all these so-called alternatives suck ass when it comes to cryptography implementations". Signal pisses me off in a lot of ways. If someone joins a group chat and posts horrific content, the admins cannot clean it up . This e…

You've written about the minimum bar before ( https://soatok.blog/2024/07/31/what-does-it-mean-to-be-a-sig... ). Have you written up your Signal criticisms / desired features anywhere? (Or, do you know where anyone else has?) I have my own ideas about requirements, but they're not concrete enough to say "requirements analysis done, let's start programming"; and most people I talk to haven't thought about this enough…

I've posted on the Signal Discourse and even had a colleague ask the Signal devs at Real World Crypto this year about this missing feature.

No dice on either approach.

Re: Soatok's Informal Guide to Threat Models

#27
post #16

Maybe I shouldn't, but I stopped taking the author seriously for their lack of nuance/extremely biased views favouring Signal in every article about E2EE applied to IM. But I do agree that threat modeling is just a support to formalize and document the variables in the threat equation. It doesn't say anything about whether the threat is reasonable, legitimate and grounded in reality, so it's only knocking the subject…

Does one have to be nuanced in everything one says? I'm not a fan of Signal's threat model, especially their historical threat models (e.g. acting like it's safe to link users to phone numbers, and then advertise which phone numbers are and aren't using Signal), but Signal's main protocol seems pretty solid, especially compared to some other systems.

> Does one have to be nuanced in everything one says?

no, but unlike a computer, the real world isn't binary, and recognising that it's flawed and full of compromises generally heightens your chances of affecting it (by your ideas or actions).

> I'm not a fan of Signal's threat model […] but Signal's main protocol seems pretty solid, especially compared to some other systems.

My main gripe with Signal is that no amount of protocol sophistication can undo the problems linked to it being a centralised service. Soatok seems unable to acknowledge that centralisation is a real (privacy, security, reliability, political, …) concern here, nor to see value in the decentralised (federated/P2P) alternative protocols implementing the same double-ratched/PFS crypto primitives.

Re: Soatok's Informal Guide to Threat Models

#28
post #27

Earlier quoted context omitted.

Does one have to be nuanced in everything one says? I'm not a fan of Signal's threat model, especially their historical threat models (e.g. acting like it's safe to link users to phone numbers, and then advertise which phone numbers are and aren't using Signal), but Signal's main protocol seems pretty solid, especially compared to some other systems.

> Does one have to be nuanced in everything one says? no, but unlike a computer, the real world isn't binary, and recognising that it's flawed and full of compromises generally heightens your chances of affecting it (by your ideas or actions). > I'm not a fan of Signal's threat model […] but Signal's main protocol seems pretty solid, especially compared to some other systems. My main gripe with Signal is that no amou…

> Soatok seems unable to acknowledge that centralisation is a real (privacy, security, reliability, political, …) concern here, nor to see value in the decentralised (federated/P2P) alternative protocols implementing the same double-ratched/PFS crypto primitives.

I genuinely do not understand where this impression is coming fron. The only thing I've ever written about this topic acknowledges that centralization has risks, but a perfectly decentralized system that doesn't properly encrypt data end-to-end is bad for user privacy.

The cryptography needs to be excellent. "But decentralization" doesn't cut it.

https://soatok.blog/2025/07/09/jurisdiction-is-nearly-irrele...

Disagreeing with me is one thing, but claiming I seem "unable to acknowledge" anytbing is dishonest.

Re: Soatok's Informal Guide to Threat Models

#29

This is the best gay furry blog post about threat modeling I've seen all day!

> Please remember that Dhole Moments is a furry blog before complaining about the furry art. It gets exhausting. Articles about cybersecurity gets 100% credibility when made by furries.

I wonder what the reaction would be if the folks beyond the HN crowd understood the extent to which the internet runs on queer / trans / catgirl / furry power?

Re: Soatok's Informal Guide to Threat Models

#30
post #16

Maybe I shouldn't, but I stopped taking the author seriously for their lack of nuance/extremely biased views favouring Signal in every article about E2EE applied to IM. But I do agree that threat modeling is just a support to formalize and document the variables in the threat equation. It doesn't say anything about whether the threat is reasonable, legitimate and grounded in reality, so it's only knocking the subject…

perhaps not the kind of nuance you mean, but this post criticizes signal for not having a threat model
Post reply on HN