Live data from Hacker News

Three lessons from Threema: Analysis of a secure messenger

breakingthe3ma.app

31–40 of 55 posts

Re: Three lessons from Threema: Analysis of a secure messenger

#31
post #6

Not directly related to the topic but how is it that Threema is the only popular secure messenger where you have a random ID to give to people to communicate with and not a phone number (Signal) or have your name show up across all your contacts / groups (Telegram)?

Wickr was decently popular but unfortunately is now owned by Amazon

Re: Three lessons from Threema: Analysis of a secure messenger

#32

Threema messages of Marian Kočner, a contorversial Slovak businessman who allegedly ordered a murder of a local journalist, were somehow obtained with the help of Europol. [0] The part of his trial where a security expert explained how the police got the messages was purposely not made public. [0] https://spectator.sme.sk/c/22216551/threema-saga-kocner-repo...

Is there some reason that's interesting? What they do here is just hack the phones, so get access to all the texting apps from the client side... Was there some implication they did otherwise in that case?

There is always some trust with private communication apps. No way one can get a completely trustless system. Signal tries to build trust by being open source and by publishing the same documents it sends in subpoenas[0] (i.e. transparency in how they respond to government requests). The lack of understanding how the information was obtained is worthy of increased suspicion albeit not abandonment. There is added suspicion in that I cannot find an official response by the Threema team. We do not know if the encryption was broken or if there was access (physical or remote) to the phone. Do note that Threema is open sourced[1]. But there can still be concern if access to the phone was gained through other means and then access to the app was gained. There's a brush off of "if physical access is gained, not our problem" but that's not nearly enough (it still shouldn't be trivial). Assuming user error first is not a good methodology in response to these types of attacks (which there is some brushing off in this manner in Threema's response to this thread's link). People are still probing a black box at the end of the day.

[0] https://signal.org/bigbrother/

[1] https://threema.ch/en/open-source

Re: Three lessons from Threema: Analysis of a secure messenger

#33
post #6

Not directly related to the topic but how is it that Threema is the only popular secure messenger where you have a random ID to give to people to communicate with and not a phone number (Signal) or have your name show up across all your contacts / groups (Telegram)?

Wickr was decently popular but unfortunately is now owned by Amazon

And new users can’t sign up anymore and it’s being totally turned off at the end of this year.

Re: Three lessons from Threema: Analysis of a secure messenger

#34
post #19

Earlier quoted context omitted.

You're right; this isn't directly related to the topic. It's a recapitulation of every thread we have ever had about Signal, on a story that has very little to do with Signal and that unveils new cryptography research. Unfortunately, this is a big dynamic on HN, not just on cryptography threads, but especially on threads rooted in stories with intense technical details. It's time consuming to bring yourself up to spe…

It makes sense to talk about Signal in these types of threads, despite not being about Signal, because Signal is still the de facto private messenger. The userbase is much larger than that of Threema so it is worthwhile to compare how these platforms are doing things differently. Especially in the context of if users should switch. Just like how in threads about Signal it is similarly appropriate to discuss WhatsApp…

Compare with respect to the research? Sure. Compare in all other respects? No.

Re: Three lessons from Threema: Analysis of a secure messenger

#35

Earlier quoted context omitted.

Is there some reason that's interesting? What they do here is just hack the phones, so get access to all the texting apps from the client side... Was there some implication they did otherwise in that case?

There is always some trust with private communication apps. No way one can get a completely trustless system. Signal tries to build trust by being open source and by publishing the same documents it sends in subpoenas[0] (i.e. transparency in how they respond to government requests). The lack of understanding how the information was obtained is worthy of increased suspicion albeit not abandonment. There is added susp…

The Threema server isn't open source, is it?

Re: Three lessons from Threema: Analysis of a secure messenger

#36
post #6

Not directly related to the topic but how is it that Threema is the only popular secure messenger where you have a random ID to give to people to communicate with and not a phone number (Signal) or have your name show up across all your contacts / groups (Telegram)?

Another one is Tox (completely distributed, no servers involved!): https://tox.chat/

I do like this feature a lot. I think converting to passphrases (random words) as well could be a good idea (to make it easier to share) -- I think it's a good simple way to make decentralized/secure systems.

Re: Three lessons from Threema: Analysis of a secure messenger

#37
post #14

The attacks in this paper are much less damaging than the attacks in the Nebuchadnezzar paper were against Matrix. But somehow, Threema comes out looking even worse: * Threema's end-to-end inner protocol, the one used to exchange messages between actual humans, is based on a single X25519 key, used bidirectionally. It has no forward secrecy. Worse, to prevent otherwise-trivial replay attacks made possible by the simp…

> But somehow, Threema comes out looking even worse

A lot of those issues fall into the category of warning signs that foretell impending doom beyond the immediate problem being identified. Like looking at a house you're thinking of buying and seeing a giant hole in the wall and looking at a different house with a damp mildew smell in every room. The hole in the wall is a more immediate and obvious problem, but the smell suggests the more significant concern.

Cryptographic systems in particular seem good at generating these kind of warning signs, since there is a significant overlap between "I can't immediately catastrophically break this" and "WTF are you doing?". Arguably, making these kinds of terrible cryptographic choices suggests something fundamentally broken in your design process that isn't fixed by just addressing specific weaknesses. This seems especially true in the secure messaging arena, where if you can't articulate an extremely good reason you can't use an existing protocol, the default position should be to avoid your product.

Re: Three lessons from Threema: Analysis of a secure messenger

#38
post #6

Not directly related to the topic but how is it that Threema is the only popular secure messenger where you have a random ID to give to people to communicate with and not a phone number (Signal) or have your name show up across all your contacts / groups (Telegram)?

I think Signal takes its community temperature from their forums rather than other places that people normally talk on the internet like HN, Reddit, or Twitter. It is rather odd and those forums are pretty trash if I'm to be honest. There are a lot of people that fight tooth an nail on there to make Signal as static as possible, meaning no new features or anything else. A particularly interesting one I saw was a user…

[deleted]

Re: Three lessons from Threema: Analysis of a secure messenger

#39
post #21
post #19

Earlier quoted context omitted.

You're right; this isn't directly related to the topic. It's a recapitulation of every thread we have ever had about Signal, on a story that has very little to do with Signal and that unveils new cryptography research. Unfortunately, this is a big dynamic on HN, not just on cryptography threads, but especially on threads rooted in stories with intense technical details. It's time consuming to bring yourself up to spe…

I get your point but this is not a thread about Signal. Threema is a lot less common of a topic on HN than Signal and the only reason I’m using it and am familiar with it is this feature so I don’t think it’s such an off topic question to ask.

Repetitive discussions are off-topic so hanging one off a different, more specific topic is a lot more than somewhat off-topic, it end up being thread vandalism, however well-intentioned or outright unintentional.

Re: Three lessons from Threema: Analysis of a secure messenger

#40
post #24
post #23

Earlier quoted context omitted.

To be fair, they also mentioned telegram and the subject of the comment was a really good feature of threema.

The thread is about new cryptographic research. Or it was, and should be.

I don't disagree but I don't think asking what the point of good cryptography is, if it is practically unusable, entirely offtopic but a discussion about the specifics of the research is what I think should take place as well.
Post reply on HN