Live data from Hacker News

Signal partners with Microsoft to bring end-to-end encryption to Skype

signal.org

251–260 of 350 posts

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#251
post #153

Earlier quoted context omitted.

Yes, but decentralization is a difficult problem. I think eventually it will become like email, where everyone just uses GMail. NAT, Firewall, etc all make it very difficult to do true P2P as well.

>I think eventually it will become like email, where everyone just uses GMail. Or Outlook(Office365), Ymail, Zoho, GMX, iCloud, Yandex, Proton.

Let's be real here, the vast majority of people use Gmail or Outlook. And importantly, businesses. iCloud breaks into the consumer market though, but these are by far the leaders.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#252
post #226

Earlier quoted context omitted.

This doesn't explain why after the change Skype started routing calls between machines on the same LAN through Microsoft servers.

It is difficult to make a p2p app on a mobile device work even between devices on the same LAN . A simplified explanation: Mobile devices will often ignore almost all incoming network traffic to reduce battery usage. The only way to reliably communicate with the device is through a centralized push notification service (e.g. APN and GCM).

Quit the b/s, will you. It's not difficult at all.

You use a central server to do the discovery and bootstrap the connection between two devices. For each device it looks like they are connecting out. This works for UDP and this works for TCP. It works both for NAT'ed and LAN peers. For the latter it works 100% of time. This is a 10 year old tech. It worked back then and it works now.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#253

Earlier quoted context omitted.

Please note that of the technologies tptacek listed, the only one which can operate in distributed fashion is Matrix.[0] Wire is attempting to pursue decentralization, but federation is not (yet) in their roadmap.[1] [0] https://github.com/matrix-org/synapse [1] https://medium.com/@wireapp/wire-server-code-now-100-open-so...

I don't know why but Signal has always scared me - I think it was when I noticed it sharing my contacts with their server to "find my friends" when I never consented. Matrix is looking good, but again not P2P only federated. This is why we are trying to do fully P2P end-to-end encryption like with https://hackernoon.com/so-you-want-to-build-a-p2p-twitter-wi... .

They don't.

https://signal.org/blog/private-contact-discovery/

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#255

The thing is. How will Microsoft and Skype handle backdoors now. As far as I understood the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. Not always the good countries. But this. This baffles me. Deeply.

That was my first thought. This is how they kill Signal. It was how they killed Skype. Take a P2P communication system that is difficult to spy on, give Microsoft a big pile of money on the sly to buy it and re-engineer it to be a centralized system and restore spy-ability. It almost seems so laughably obvious as to be childishly unwise to attempt.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#256
post #203

Earlier quoted context omitted.

Seems like there's a demand for an objective layman friendly list like this (only more accurate). Wonder if that'll ever happen. I suspect security will remain a privilege of the technical elite or those that can pay the technical elite. I guess maybe that's OK, but a bit concerning at a consumer level where it could be another factor increasing the class gap.

This press release is about security being increased in a product that has massive reach amongst those who are not the technical elite. There doesn't appear to be any extra fee for it as well.

I don't think things are nearly as bleak as the GP poster sees them - my optimistic guess is that e2e encryption will be the default in most messaging systems within 10 years.

On the other hand, this sort of integration is a symbolic baby step of little practical impact or increase in security. Not only are these features not enabled by default, they're so deeply buried in the UI they're hard to find even when you know they're there. It's easier to accidentally send someone an animated gif of tapirs playing poker and smoking cigars on FB Messenger than it is to deliberately start an encrypted conversation. Skype and Allo are not much better.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#257

The thing is. How will Microsoft and Skype handle backdoors now. As far as I understood the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. Not always the good countries. But this. This baffles me. Deeply.

>the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. That seems like pretty unreasonable tinfoil. There is no reason for Microsoft to want to give information to governments. I assume they don't pay, and the cost is consumer trust. Makes a lot of sense to rearchitect such that you can't give in to government demands.

Without addressing the tinfoilery... ummm... have you ever actually looked at the size of government contracts in the US? They're usually the largest customer any Fortune 500 company has, so large that losing them as a customer would destroy the company. There are a handful of exceptions, but for most companies, they are very much not going to bite the hand that feeds them. If daddy asks for access, daddy gets access. That's one of the reasons I support making ISPs a municipal public utility. Municipal governments will tell the government to pound sand if they don't have a court order with a judges seal. Any private company in the US will only open the door for them and ask if they've had a chance to review their bid on the latest government contract.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#258
post #240

This means we can still trust Signal right? That's the app I use because some large security experts said it was one of the best.

Nothing about Signal itself is changing. This is Microsoft adopting the Signal Protocol for a new feature in Skype.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#259

Earlier quoted context omitted.

Please note that of the technologies tptacek listed, the only one which can operate in distributed fashion is Matrix.[0] Wire is attempting to pursue decentralization, but federation is not (yet) in their roadmap.[1] [0] https://github.com/matrix-org/synapse [1] https://medium.com/@wireapp/wire-server-code-now-100-open-so...

I don't know why but Signal has always scared me - I think it was when I noticed it sharing my contacts with their server to "find my friends" when I never consented. Matrix is looking good, but again not P2P only federated. This is why we are trying to do fully P2P end-to-end encryption like with https://hackernoon.com/so-you-want-to-build-a-p2p-twitter-wi... .

We’ve designed the Signal service to minimize the data we retain about Signal users, so the only information we can produce in response to a request like this is the date and time a user registered with Signal and the last date of a user’s connectivity to the Signal service.

Notably, things we don’t have stored include anything about a user’s contacts (such as the contacts themselves, a hash of the contacts, any other derivative contact information), anything about a user’s groups (such as how many groups a user is in, which groups a user is in, the membership lists of a user’s groups), or any records of who a user has been communicating with.

All message contents are end to end encrypted, so we don’t have that information either.

https://signal.org/bigbrother/

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#260

The thing is. How will Microsoft and Skype handle backdoors now. As far as I understood the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. Not always the good countries. But this. This baffles me. Deeply.

Microsoft used centralised servers because the Skype prior to that was a curse to mobile devices running on battery power. Particularly cellphones. Skype worked as a p2p network, where some peers where marked as super peers and would help with peers behind firewalls (UDP-holepunching), and routing through the super peer. If your phone became a super peer, you could expect to essentially work like a server, with the "…

Yup. The whole P2P and Supernode architecture didn't just fail when it came to mobile devices. The Christmas 2010 outage was also caused by the reliance on supernodes.
Post reply on HN