Live data from Hacker News

Signal Secure Backups

signal.org

311–320 of 460 posts

Re: Signal Secure Backups

#311

> Losing it means losing access to your backup permanently, and Signal cannot help you recover it. Oof... That's going to be tough to explain to normal users. "Sorry you've been paying for backups all this time, but you should have written down this code that you will only ever use once somewhere safe and remembered where it is. All your data is gone." Not the right security trade-off for most people.

The implementation feels uncharacteristically crude for Signal. Instead of seamless protections, you just get handed 64 characters you’re told to “store securely.” That’s not realistic: most people will screenshot it, and those screenshots will end up in unencrypted cloud backups.

Sure but the key is still in a separate location from the backup. Signal can't decrypt the backup and if Signal is hacked someone would still need to get your screenshot to decrypt the backup. Not perfect but far better than an unencrypted backup.

Re: Signal Secure Backups

#312

I can't believe Signal is doing this. Signal is known for its cutting-edge cryptographic protocol, but this feature has the effect of throwing that out the window and replacing it with a single static key. If a device with this enabled goes through the whole advanced protocol to receive a message (double ratcheting etc), then turns around and uploads it back to Signal’s servers with a static key, isn't that a roundab…

If you're in a group and someone is backing up the messages, it only affects your messages in that group. All of your other chats are still secure as long as you're not using the backup frature.

You (and Signal) can't control how the recipient handles your messages if you're not using disappearing. They could be copying and pasting your messages or taking screenshots. I don't see how the backup feature is any different.

Re: Signal Secure Backups

#313
post #172

What is the UX for the 64 characters key? Does it at least use a wordlist (e.g. like BIP 39)?

Just 64 characters but they do integrate with a password manager and have a 1-click button to add it. The integration was pretty seamless and saved it in 1Password.

Re: Signal Secure Backups

#314
post #4

This looks brilliant. I just hope they make it easy to do test restores. In particular, I want to test restore without perturbing my main device. Let me restore using the secret key on a new device. When I install Signal on a computer it won't show me message history. Will backups allow me to view _all_ my message history on a computer? A big screen is very helpful for browsing lots of messages.

As of a few months ago, when setting up Desktop you do actually get an option to copy your message history to it

Re: Signal Secure Backups

#315

Earlier quoted context omitted.

Giving people a 64-character key also feels uncharacteristically crude for Signal. It's not realistic to hand people 64 characters and tell them to “store this securely.” Most people will screenshot it, and those screenshots will end up in unencrypted cloud backups. That's less of a problem when the backups are local, because access to the local backups implies access to the device, but if the backups are in the clou…

I get your point but is a large set of dictionary words or 5-digit numbers (see the current backup passphrase) so much better? At the end of the day, recording entropy will always be cumbersome and there is no way around it. > Most people will screenshot it, and those screenshots will end up in unencrypted cloud backups. At least on Android apps can disable screenshots, though, which might be a simple way to deter pe…

> is a large set of dictionary words so much better?

Yes, much easier to type

Re: Signal Secure Backups

#316
post #142

> In the past, if you broke or lost your phone, your Signal message history was gone. this and completly useless multi-device support is the reason I don't use Signal... Telegram is not fully e2ee but it's way more convenient here. Even XMPP with PGP would be lightyears ahead.

>"Telegram is not fully e2ee but it's way more convenient here." Yeah convenient way to hand your data to a Russian oligarch. PGP has no forward secrecy and OTR in XMPP lacks future secrecy, multi-device support etc. Signal introducing end-to-end encrypted backups is exactly how Telegram should've done it decade ago.

Future secrecy?

PGP does multirecipients natively, so any restrictions there would be in the XMPP client.

I have actually tried out PGP over XMPP and is was nice once it was set up. Absolutely no state. If the message somehow gets to you it just works. Sucked when the keys expired though:

* https://articles.59.ca/doku.php?id=pgpfan:expire

PGP support on XMPP isn't really that great. Forward secrecy might be a nice addition, even if it was semi-manual. There are compatibility problems between clients for encrypted media. You don't end up with an always encrypted archive like you do with email, but that could be considered an inherent weakness of instant messaging...

Re: Signal Secure Backups

#317

I can't believe Signal is doing this. Signal is known for its cutting-edge cryptographic protocol, but this feature has the effect of throwing that out the window and replacing it with a single static key. If a device with this enabled goes through the whole advanced protocol to receive a message (double ratcheting etc), then turns around and uploads it back to Signal’s servers with a static key, isn't that a roundab…

You can't have forward secrecy for something you want to keep for an indefinite interval. How many Signal users actually achieve forward secrecy anyway? They tend to want to keep their old messages available to them.

Re: Signal Secure Backups

#318

Hi @greysonp > Once you’ve enabled secure backups, your device will automatically create a fresh secure backup archive every day, replacing the previous day’s archive. So IIUC backups will not be incremental and I will have to re-upload my 15 GB backup archive every day? Why is that? What's the security risk here? (Obviously I'm not suggesting encrypting & uploading each message & media file individually but splittin…

Hi there! > So IIUC backups will not be incremental Nope! It's very much incremental :) At least the media is. There's one blob of containing all of your messages+metadata which does have to be re-uploaded every night, but for most people that's gonna be somewhere in the low-tens of MB. Your attachments are uploaded incrementally one at a time, typically as they're sent/received, so you usually don't even have to wai…

> Nope! It's very much incremental :)

That's great to hear, thanks so much!

Re: Signal Secure Backups

#319

Earlier quoted context omitted.

Really? Ever since Android devices ceased to be regular USB storage devices and switched to MTP, this has never worked well for me. MTP is incredibly slow.

What method do you find to be faster?

Pretty much any other: Connecting my phone to my computer as USB storage (when it was still possible), connecting a thumb drive to my phone, syncing files using Syncthing, using adb, …

Re: Signal Secure Backups

#320
post #308
post #306

> If securely back up all* of your text messages and the last 45 days’ worth of media for free. > If you want to back up your media history beyond 45 days, as well as your message history, we also offer a paid subscription plan for US$1.99 per month. So after so many years of having a serious design flaw this poor substitute of a backup where you can't even save all your text for free is all they've managed to come u…

I guess the reason WhatsApp lets you save all your text for free is they are making money off sucking up your data. I think ultimately this model will win, but I sympathise with Signal's approach.

WhatsApp offloads the storage to Google/Apple.

https://faq.whatsapp.com/481135090640375

Post reply on HN