Live data from Hacker News

Saying goodbye to encrypted SMS/MMS

whispersystems.org

41–50 of 78 posts

Re: Saying goodbye to encrypted SMS/MMS

#41

Perhaps not call the app TextSecure then? I think Moxie is a total dude but wasn't SMS encryption the Unique Selling Point of TextSecure? It was the reason I installed the app and go through the inconvenience of typing a very long string into the app every time the app restarts. I undertsand the logic of what Moxie is saying, if that's the case then the conclusion should be, "We need to shut down the entire app", not…

The next version is called Signal, so there you go.

The reasons make sense - SMS as a transport is almost unworkable, there's a lot of crap involved with MMS bugs that it would be good to rip out, and it can never be compatible with iOS.

A replacement for GCM/push/etc for wakeup would be nice - I wonder what that would look like? - but it'll do for now.

Re: Saying goodbye to encrypted SMS/MMS

#42
post #14

That's unfortunate. Encrypted SMS/MMS has been my primary use for TextSecure. For contacts that have intermittent or expensive data connections, especially while roaming, the ability to use SMS was a selling point vs other messaging systems. Telco's in my country record and store SMS data for a period and knowing this data was encrypted and unreadable by them was another useful feature of TextSecure.

How much data is this actually likely to use? Effectively plain text data doesn't seem like it should be expensive. Even with something like .odt you're looking at a few KB a 'page.'

There are other concerns than just the amount of KB transfered. When connectivity is poor SMS is much more likely to work than data (2G/3G/4G). AFAIK. GCM is not a "true" push service, it just provide an API that makes it seem like one. Battery use is much higher for data, especially when you are in a location with bad connectivity. Some people prefer disabling data when they don't need it, for the reasons above and for other reasons.

Re: Saying goodbye to encrypted SMS/MMS

#43
post #31

We don’t want the state-run telcos in Saudi, Iran, Bahrain, Belarus, China, Egypt, Cuba, USA, etc… to have direct access to the metadata of TextSecure users in those countries or anywhere else. Sad to see that the 'land of the free' has become bundled (in a relatively short period of time) into a category of oppressive states that have little or no respect for the privacy of its citizens.

I read this bundling as a deliberate rhetorical/political move. You could have bundled the US with other surveillance-happy Western nations such as Australia or the UK, which as far as I understand do not behave in a qualitatively different manner.

Not only do the UK, Australia, or Canada and New Zealand for that matter, not behave qualitatively differently, but as the "Five Eyes" surveillance states, they'll spy on one another's citizens (and occasionally their own) for one another, effectively gutting any legislative prohibitions on domestic surveillance.

https://plus.google.com/u/0/104092656004159577193/posts/2ncB...

Tipped off to me by SoftwareMaven here at HN: https://news.ycombinator.com/item?id=9077061

(Links are described in more detail in my G+ post above)

http://www.theguardian.com/world/2013/nov/20/us-uk-secret-de...

http://www.theguardian.com/world/2013/dec/02/revealed-austra...

http://www.theguardian.com/politics/2013/jun/10/nsa-offers-i...

http://uk.reuters.com/article/2013/06/21/uk-usa-security-bri...

Re: Saying goodbye to encrypted SMS/MMS

#45
post #30
post #28

I'm disappointed that TextSecure is moving from one of the last deployed federated platforms (SMS) to their own closed transport. :(

Not sure if "federated because ITU members can hook up their own processing" is federated in any meaningful way.

If the system used SMS proxied by TextSecure, that would have at least avoided net-of-endpoint pen trace. You'd know who TextSecure's customers were, and could probably use time-based analysis to see who is likely to be talking to whom (a steady stream of non-content messages would otherwise have to be used to mask significant messages).

The context analysis sideband leakage is the big win here for a data-based approach.

Re: Saying goodbye to encrypted SMS/MMS

#46
post #4

"We don’t want the state-run telcos in Saudi, Iran, Bahrain, Belarus, China, Egypt, Cuba, USA, etc… to have direct access to the metadata of TextSecure users in those countries or anywhere else." I <3 Moxie.

The flip side is that identifying all users running TextSecure will get a lot easier, I presume. Previously telcos saw encrypted SMS (sometimes) and connections to GCM. Now they will see connections to TextSecure.

There are possible ways to mask that, though they'd likely still draw attention.

Assuming that any given endpoint was already a surveillance target, the advantage here is that the traffic cannot be used (or is less readily used) to determine contacts -- who's talking to whom.

Re: Saying goodbye to encrypted SMS/MMS

#47

Earlier quoted context omitted.

How much data is this actually likely to use? Effectively plain text data doesn't seem like it should be expensive. Even with something like .odt you're looking at a few KB a 'page.'

There are other concerns than just the amount of KB transfered. When connectivity is poor SMS is much more likely to work than data (2G/3G/4G). AFAIK. GCM is not a "true" push service, it just provide an API that makes it seem like one. Battery use is much higher for data, especially when you are in a location with bad connectivity. Some people prefer disabling data when they don't need it, for the reasons above and…

Most people disable their mobile data when roaming, because fees are set to bleed the unfortunate few who forget to dry. If you live in a country that is only a few hours drive to neighboring ones, that's something you do quite often. So SMS is not only more likely to work, it is absolutely required.

Re: Saying goodbye to encrypted SMS/MMS

#48
post #31

We don’t want the state-run telcos in Saudi, Iran, Bahrain, Belarus, China, Egypt, Cuba, USA, etc… to have direct access to the metadata of TextSecure users in those countries or anywhere else. Sad to see that the 'land of the free' has become bundled (in a relatively short period of time) into a category of oppressive states that have little or no respect for the privacy of its citizens.

I read this bundling as a deliberate rhetorical/political move. You could have bundled the US with other surveillance-happy Western nations such as Australia or the UK, which as far as I understand do not behave in a qualitatively different manner.

And I guess there's a school of thought that from this perspective Australia and the UK are different countries in name only and are following US policy as dictated? True or not it's reasonable rhetoric I guess.

Re: Saying goodbye to encrypted SMS/MMS

#49
post #4

"We don’t want the state-run telcos in Saudi, Iran, Bahrain, Belarus, China, Egypt, Cuba, USA, etc… to have direct access to the metadata of TextSecure users in those countries or anywhere else." I <3 Moxie.

The flip side is that identifying all users running TextSecure will get a lot easier, I presume. Previously telcos saw encrypted SMS (sometimes) and connections to GCM. Now they will see connections to TextSecure.

More reason to use it and encourage your friends to use it while you still don't really need to.

Re: Saying goodbye to encrypted SMS/MMS

#50
post #31

We don’t want the state-run telcos in Saudi, Iran, Bahrain, Belarus, China, Egypt, Cuba, USA, etc… to have direct access to the metadata of TextSecure users in those countries or anywhere else. Sad to see that the 'land of the free' has become bundled (in a relatively short period of time) into a category of oppressive states that have little or no respect for the privacy of its citizens.

It seems pretty clear that more or less every advanced country should be included on that list. America needs a new constitutional amendment to address what the 4th Amendment means in the 21st century.

I think you are seeing what it means to those in power- and those are the folks who would draw it up. It would be quite a remarkable revolution to put normal citizens in the legislature to rewrite the laws. I'm not sure my country can handle that. Too much funny laugh-track stuff on TV.
Post reply on HN