Live data from Hacker News

Encrypted web traffic now exceeds 90%

netmarketshare.com

261–270 of 311 posts

Re: Encrypted web traffic now exceeds 90%

#261
post #242
post #162

Earlier quoted context omitted.

They don’t claim end to end encryption by default though. You make it sound as if there is a revelation you made here. Telegram has faults, I would even argue it has many, but it’s clear that only “secret” chats and voice/video calls are end to end encrypted. Whatsapp, however, does allow you to download all of your messages from your device using WhatsApp web, and they were recently shown to have an exploit/backdoor…

"They don’t claim end to end encryption by default though." They don't have to. The amount of my peers (i.e. who also major in CS) who think Telegram is more secure than e.g. WhatsApp, is staggering. People don't really think about the protocol, they only think what they hear on the news, or what their buddies think who have heard it in the news. And what they hear is "Telegram, the new encrypted messaging app, blah…

Telegram refused to provide decryption keys to Russia, US, China governments. That is great sign to me.

Meanwhile Whatsapp has web interface(sic!) where law enforcement agents can request user specific information and probably chat logs for whatever fake reasons they could come up with.

Telegram is 300mil users and growing.

Re: Encrypted web traffic now exceeds 90%

#262

Earlier quoted context omitted.

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

Accessing chats from a new device has no technical relation (or constraint) to the lack of end to end encryption. Wire encrypts all chats end to end, and still provides syncing conversations to multiple devices on multiple operating systems. It does limit the sync to the last 30 days, but that’s mostly because of cost reasons rather than technical reasons. Edit/correction: Neither Wire nor Signal sync conversations t…

If you can view your old conversation from a fresh installation on a new devices then this automatically implies that some 3rd party has access to your keys. I.e. your conversion cannot be considered truly private.

Re: Encrypted web traffic now exceeds 90%

#263
post #126

Earlier quoted context omitted.

And even if they get a key, they will show up in the CT Logs eventually and the attack becomes public.

The effectiveness of CT logs isn't a thing unless the website uses CT monitoring or is a huge company. A [delegated or non-delegated] DNS takeover, or IP address release (eg. cloud providers re-assigning an IP to another customer) could allow you to generate a certificate for some-forgotten-subdomain.medium-sized.company.com using the ACME http challenge. Of course this is mitigated by properly managing your DNS, and…

crt.sh offers a RSS Feed, I use that to track all certificates issued for my domain. Doesn't really need anything expensive or complicated.

CT Logs don't mitigate any of the attacks but they make them very very very visible if they happen. Especially if a CA goes rogue, this will be immediately visible and provable.

Re: Encrypted web traffic now exceeds 90%

#264
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

Are you saying that when you log into Telegram on a new phone it downloads the chat logs from somewhere? And that this only requires a short password?

At best this'd mean the logs are encrypted using the password as the key...

Are you sure the user isn't copying anything between devices? Chat logs and a keyfile maybe?

Re: Encrypted web traffic now exceeds 90%

#265
post #242

Earlier quoted context omitted.

"They don’t claim end to end encryption by default though." They don't have to. The amount of my peers (i.e. who also major in CS) who think Telegram is more secure than e.g. WhatsApp, is staggering. People don't really think about the protocol, they only think what they hear on the news, or what their buddies think who have heard it in the news. And what they hear is "Telegram, the new encrypted messaging app, blah…

Telegram refused to provide decryption keys to Russia, US, China governments. That is great sign to me. Meanwhile Whatsapp has web interface(sic!) where law enforcement agents can request user specific information and probably chat logs for whatever fake reasons they could come up with. Telegram is 300mil users and growing.

Telegram founder also lies a lot. First he says that Telegram developers are not in Russia, out of the FSB reach, but later proofs emerge that they work for Russia from the same office where VK developers worked from. Google Anton Rosenberg and his lawsuit. [1] The public position of Durov ("this man is just crazy freak") is very unconvincing, to say the least. I'd even suspect that it is plausible that Russian authorities have some leverage on Telegram, and all this conflict with RosComNadzor is just a publicity stunt. After all, the only "loss" of a Russian government is RosComNadzor reputation, which is bad anyway.

[1] https://medium.com/@anton.rozenberg/friendship-betrayal-clai...

Re: Encrypted web traffic now exceeds 90%

#266
post #247
post #165

Earlier quoted context omitted.

There have been fradulent certificates in the wild in the past but the CAs doing it usually get kicked out pretty quickly. That's what Google's certificate transparency project is for. And they are increasing requirements further and further. Hopefully one day we'll get to a state where the infrastructure of multiple independent companies in different countries needs to be compromised in order for one successful forg…

The problems is, companies like VeriSign offer LEA services Quoting https://papers.ssrn.com/sol3/papers.cfm?abstract_id=1591033 “Verisign also operates a ‘Lawful Intercept’ service called NetDiscovery. This service is provided to ‘... [assist] government agen- cies with lawful interception and subpoena requests for subscriber records.’ If you now try to search for NetDiscovery or LEA services for CAs, you won't find…

The CA doesn't have anything that helps you do Lawful Intercept. They just vouch for people's identities.

If you can persuade them to fraudulently vouch for your agency as being some other subscriber then this unavoidably produces a smoking gun which everybody can see, just like when Israel produces fake passports so its agents can travel abroad to murder people.

It doesn't let them passively intercept. The CA could not, gun to its head, help you do that. The mathematics just doesn't work that way, any more than the US Federal Reserve could intervene to make three dollars twice as many as five dollars.

Re: Encrypted web traffic now exceeds 90%

#267

Earlier quoted context omitted.

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

Are you saying that when you log into Telegram on a new phone it downloads the chat logs from somewhere? And that this only requires a short password? At best this'd mean the logs are encrypted using the password as the key... Are you sure the user isn't copying anything between devices? Chat logs and a keyfile maybe?

Well that DO have an optional 2factor auth, and yes, they definitely DON'T copy any keys between devices (like WhatsApp does when launching a web version).

Re: Encrypted web traffic now exceeds 90%

#268
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

Snowden played no role in HTTPS adoption, because people don't seriously expect HTTPS to defeat NSA. Most peoples' threat models are much more modest.

HTTPS adoption has a lot more to do with Google and Mozilla pushing it in their browsers, and Let's Encrypt making getting certificates easy. I have mixed feeling about that - the cost of easy certificates was making spoofing far easier.

Re: Encrypted web traffic now exceeds 90%

#269
post #236

Earlier quoted context omitted.

How is iMessage worse versus Hangouts? Is Hangouts even end-to-end encrypted? IIRC it isn’t, neither is Google Chat (a product which is replacing Hangouts from what I can tell), just Allo and Duo.

iMessage has several problems: 1. iMessage uses RSA instead of Diffie-Hellman. This means there is no forward secrecy. If the endpoint is compromised at any point, it allows the adversary who has a) been collecting messages in transit from the backbone, or b) in cases where clients talk to server over forward secret connection, who has been collecting messages from the IM server to retroactively decrypt all messages…

Very interesting post, thank you for sharing !!

> 2. The RSA key strength is only 1280 bits.

This reminds me that in france, unless cryptography is not used for authentication, it is considered a military weapon, and civil usage is restricted in its key strength. Above a certain strength, you technically have to give your key to the government !!...!!!

I don't have a source, but fr.wiki [1] says that in 1999, the government allowed for 128 bit keys to be publicly used without depositing it to the government. It also says that PGP was illegal in france until 1996 (considered a war weapon of category 2, whatever that means).

So I wouldn't be surprised if it were illegal over here to use key strengths above 2048 for end to end encryption in france...

[1] https://fr.wikipedia.org/wiki/Chiffrement#En_France

Re: Encrypted web traffic now exceeds 90%

#270
post #186

Earlier quoted context omitted.

MITM is not mitigated at all by HTTPS. What makes you think that? Do you understand how certificate signing works?

Literally the only reason TLS uses certificates is to mitigate Man-in-the-Middle attacks. Establishing a shared secret with another party over a public channel is not that hard (Diffie-helman, RSA). The hard part is to ensure the other party is who they say they are. Certificates tackle this by having a trusted party (CA) cryptographically bind the shared secret to an identity. There are issues here, but if you can r…

Technical corrections:

The binding is over a _public key_ not a _shared secret_.

Also that last sentence is confusing and I'm not sure how best to fix it. Maybe the last word should be 'meaning' not 'traffic' or maybe the word HTTP should be inserted?

Post reply on HN