Live data from Hacker News

Saying goodbye to encrypted SMS/MMS

whispersystems.org

61–70 of 78 posts

Re: Saying goodbye to encrypted SMS/MMS

#61
post #53

Well that's disappointing. I have worked hard inviting my friends to textsecure, i used to tell them: "Textsecure is just a simple text messaging app but with encryption, why not to change your default one to this, what do you have to lose, you still can message all the others." Now, however, it's not going to be a simple text messaging app anymore, but just another Whatsapp + real crypto. Which is going to make wayy…

TextSecure is getting rid of ENCRYPTED SMS/MMS, not SMS/MMS capability all together. So from a lay-person's perspective, I don't see what the major change is. They can still use TextSecure as their texting app, while occasionally being able to communicate securely with contacts that also use TextSecure Protocol clients. SMS/MMS just isn't being used as a secure transport anymore.

If we'd drop "Secure" from "TextSecure", from a lay-person perspective there are quite a lot of appealing alternatives for an SMS/MMS texting app.

Re: Saying goodbye to encrypted SMS/MMS

#62
post #59

Earlier quoted context omitted.

TextSecure is getting rid of ENCRYPTED SMS/MMS, not SMS/MMS capability all together. So from a lay-person's perspective, I don't see what the major change is. They can still use TextSecure as their texting app, while occasionally being able to communicate securely with contacts that also use TextSecure Protocol clients. SMS/MMS just isn't being used as a secure transport anymore.

"occasionally being able to communicate securely with contacts that also use TextSecure Protocol clients." "Occasionally" is not what I desire. Being abroad and not being able to use data due to huge roaming fees leaves me vulnerable something like 80-90days a year. Leaking metadata is still better than leaking the contents which is why I'm feeling rather skeptical about this decision

Absolutely. Dropping GCM and rolling their own for that is great.

But SMS still is the more reliable protocol. When I'm in a subway without stable data, and I tell my girlfriend I have an expectation for reliability of delivery that is shaped by SMS. So does she.

Roaming data is disabled by default on Android for good reasons, I pay insane amounts for it on my otherwise fantastically cheap data plan. So I am in Paris and all of a sudden her messages don't get through.

If there is an intelligent fall back to unencrypted SMS this could be a boon though. The risk of undelivered messages very strongly outweighs the risk of these messages being read in these use cases, so if SMS can not be made secure and usable, unencrypted fall back is absolutely fine.

Re: Saying goodbye to encrypted SMS/MMS

#63
post #14

That's unfortunate. Encrypted SMS/MMS has been my primary use for TextSecure. For contacts that have intermittent or expensive data connections, especially while roaming, the ability to use SMS was a selling point vs other messaging systems. Telco's in my country record and store SMS data for a period and knowing this data was encrypted and unreadable by them was another useful feature of TextSecure.

How much data is this actually likely to use? Effectively plain text data doesn't seem like it should be expensive. Even with something like .odt you're looking at a few KB a 'page.'

Yeah, but you need to then configure your phone to make sure only TextSecure uses roaming. If anyone knows an effective way of doing this (that is not manually disabling everything else) I would love to hear it.

Re: Saying goodbye to encrypted SMS/MMS

#64
post #59

Earlier quoted context omitted.

TextSecure is getting rid of ENCRYPTED SMS/MMS, not SMS/MMS capability all together. So from a lay-person's perspective, I don't see what the major change is. They can still use TextSecure as their texting app, while occasionally being able to communicate securely with contacts that also use TextSecure Protocol clients. SMS/MMS just isn't being used as a secure transport anymore.

"occasionally being able to communicate securely with contacts that also use TextSecure Protocol clients." "Occasionally" is not what I desire. Being abroad and not being able to use data due to huge roaming fees leaves me vulnerable something like 80-90days a year. Leaking metadata is still better than leaking the contents which is why I'm feeling rather skeptical about this decision

I'm not sure that it makes sense to optimize a service to be as effective as possible under roaming situations. They were obviously spending a lot of engineering resources dealing with SMS edge cases.

They even justified focusing on their own open protocol over data as being useable by more people in the world. Any time you make a change, your going to impact usability for some people. But it sounds to me that they're going in the direction that increases global adoption and mind-share of encrypted communication. It's way too early, and adoption is way too low to sacrifice broad adoption (by not focusing enough) in favor of supporting current edge use cases.

Re: Saying goodbye to encrypted SMS/MMS

#65
post #59

Earlier quoted context omitted.

TextSecure is getting rid of ENCRYPTED SMS/MMS, not SMS/MMS capability all together. So from a lay-person's perspective, I don't see what the major change is. They can still use TextSecure as their texting app, while occasionally being able to communicate securely with contacts that also use TextSecure Protocol clients. SMS/MMS just isn't being used as a secure transport anymore.

"occasionally being able to communicate securely with contacts that also use TextSecure Protocol clients." "Occasionally" is not what I desire. Being abroad and not being able to use data due to huge roaming fees leaves me vulnerable something like 80-90days a year. Leaking metadata is still better than leaking the contents which is why I'm feeling rather skeptical about this decision

Wifi?

Re: Saying goodbye to encrypted SMS/MMS

#66

Earlier quoted context omitted.

whatsapp and fb messenger work perfectly without google play services installed. whatsapp even manages to update itself. i see no reason why TextSecure could not do it. It's an app that is focused on privacy, and as such should work without closed source software from the largest data collector in the world installed on the phone.

Facebook and WhatsApp are much bigger players with massive infrastructure that Whisper Systems doesn't have. I agree it would be a lot better if it didn't require Google Play Services, but I'm not sure how realistic that is. Google has worked hard to make the Play APIs indispensable for anyone trying to work with Android.

This. TextSecure is a tiny player that's already had a tremendously outsized impact. It's completely unrealistic to expect them to be able to support every edge case and provide as smooth an experience as these billion dollar companies can.

TextSecure and their Open Whisper Systems' involvement in Whatsapp have done more for the adoption of end-to-end encrypted peer to peer communication than the combination of just about anything else that could be brought up as a contributing factor. When they say that SMS is a net hurdle to adoption, then I trust their judgement on that count.

Re: Saying goodbye to encrypted SMS/MMS

#67
post #10

That makes no sense because SMS-compatibility is the trojan horse to get adoption. Without SMS it's just another messaging app with huge network-effect adoption challenges.

You can still send unencrypted SMS messages to people who don't use TextSecure. You can still send encrypted messages to people who do use TextSecure. All you lose is the ability to send encrypted SMS messages to people who are already using TextSecure; instead you must send messages through the Internet.

Well, as of this morning (after updating to v2.6) all I am able to do with my one other TS contact is send unsecured SMS. No encrypted SMS nor encrypted push. Frustrating to say the least!

I have been struggling for over a year now to get this one contact and I to have a smooth & reliable secure channel. Sometimes it works great and others times it just doesn't exist. And I usually have to jump through all kinds of hoops to get it to work again. Which makes it nearly impossible for me to recommend TS to others who are a little less technical than my one TS contact and myself.

I really want this to work smoothly, Moxie, I really do! If it does, then I can recommend it to everyone.

edit: spelling

edit2: Moxie has quickly replied to my issue on github and will be pushing v2.6.1 soon.

Re: Saying goodbye to encrypted SMS/MMS

#68

For me, an year ago, TextSecure's primary selling point was that it wasn't reinventing the wheel, but was layering above the already existing network. Something very resembling how one installs an OTR plugin for their XMPP client, except for being an app (since, unfortunately, I have yet to see an mobile messaging app with a sane plugin system). I've perceived their own proprietary data transport as progressive enhan…

Their protocol and implementations are fully open source. https://github.com/WhisperSystems

Re: Saying goodbye to encrypted SMS/MMS

#69
post #35

Earlier quoted context omitted.

Do people really think that having your texts read is comparably oppressive to living in Belarus?

No one said that except you. Nice rhetorical strategy. Moxie said 'state-run telcos'. Which is accurate.

Moxie didn't say it but the comment seems to imply that they are in fact comparable.

Re: Saying goodbye to encrypted SMS/MMS

#70

Earlier quoted context omitted.

whatsapp and fb messenger work perfectly without google play services installed. whatsapp even manages to update itself. i see no reason why TextSecure could not do it. It's an app that is focused on privacy, and as such should work without closed source software from the largest data collector in the world installed on the phone.

Facebook and WhatsApp are much bigger players with massive infrastructure that Whisper Systems doesn't have. I agree it would be a lot better if it didn't require Google Play Services, but I'm not sure how realistic that is. Google has worked hard to make the Play APIs indispensable for anyone trying to work with Android.

> Facebook and WhatsApp are much bigger players with massive infrastructure that Whisper Systems doesn't have.

even kik (http://www.kik.com/) works without google play services, and it has no massive infrastructure.

but even then, it makes no sense to say that chatsecure is secure and client side encrypted, when it NEEDS, and BUILDS ON closed source software of (one of) the largest data collector companies in the world.

Post reply on HN