Live data from Hacker News

Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

ndss-symposium.org

91–100 of 206 posts

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#91

Wire (from the creators of Skype) does not mandate a mobile phone number (SIM cards are tied to government identity in many countries). Only an email address is required to open a free account. Nor does Wire mandate upload of your phone's address book with personal social graph of contacts. Free for consumers with paid teams offering for enterprises, optional on-prem server. Open-source clients and server. Cross-devi…

I'm amazed that they still don't have any kind of 2FA after nearly four years.

https://github.com/wireapp/wire/issues/85

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#92
post #12

There needs to be two lists of contacts. One which I allow to be shared with apps And another which are my contacts I use with my dialer. People don't need their messenger apps knowing the phone number of their doctor

It would be much smarter if your contacts could chose to allow you to share or not share their details.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#93

Earlier quoted context omitted.

there is always Matrix app. Some may argue that Matrix still a centralized server by the virtue of seeding your group info somewhere. But this seeding can be done via paper-only thereby it is still a true decentralized messaging server.

No, there is always xmpp. Matrix is just an app, and we need a federated protocol. I think that Matrix will never have an alternative server implementation made by a competing party, which makes it's main selling point void.

Manyverse (Sweden) app does Matrix well.

But it’s design intent isn’t FEDERATION, not at all.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#94
post #90
post #76

Earlier quoted context omitted.

There is no such thing as an anonymous transaction, for a fully informed definition of anonymous. Bitcoin isn't... neither is cash in hand. Neither is a drop. Someone knows. A discussion of 'anonymity' in this context is one of increasing the difficulty of discovery, not thinking that the discovery is impossible. If a major world government is after you, good luck with "anonymous"

Monero is.

You could convert Monero ou Zcash to Bitcoin at an exchange before paying. I don't know which exchanges currently allow to do that without verifying your identity, though.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#95

This scientifically-looking paper could have been written by Captain Obvious himself. It is beyond obvious that contact discovery in any major messenger or social network is facilitated by uploading all contacts from the user’s address book, with all the implied drawbacks. If users' behaviour has shown us anything, it's that they love it. And for all the dangers of their privacy loss, they happily trade it for the co…

Is there a "scientifically-looking" paper that shows that users love it?

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#96

It didn't take long after the first social graph was created to realize that your contacts define you as much or even more than your other indicators do. That's why so many companies are gunning for this information.

A quote I saw on the Internet long ago went, "You're the average of the five people spend the most time with". I used to interpret it only in its original, prescriptive sense: if you want to become a different person, make appropriate changes to your social life.

It took me way too long to realize it's even more applicable in the descriptive sense: the people you spend most of your time with are a good statistical predictor of who you are.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#97
post #73

Earlier quoted context omitted.

I didn’t login on Wire for 3 months and “for my security” messages that were sent to me during that time were just... lost. I think my history was deleted too. This happened 2 or 3 years ago, but it made me just switch to something else (Telegram).

This is one of those replies that should be put in some kind of HN canon. It perfectly shows why there are so few privacy or security respecting options. They did the correct thing for security and you switched. As I've observed for a long time: UX is more powerful than anything else except maybe cost, and even then one driver for user preference for "free" apps is not having to dig out a card... so cost is also UX.

That’s a bit unfair. I value privacy for some things but for other things I value more not losing my message history. Telegram is not as secure as other options by default, but for me it strikes a good balance between convenience/usability and privacy, as I can optionally open a self-destroying secret chat when I need it.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#98
post #37

Earlier quoted context omitted.

I didn’t login on Wire for 3 months and “for my security” messages that were sent to me during that time were just... lost. I think my history was deleted too. This happened 2 or 3 years ago, but it made me just switch to something else (Telegram).

So you want them to just hold on to your messages on their servers indefinitely? I realize this is the norm nowadays, but is this really what you actually want?

I think it should be an option, at least.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#99

Wire (from the creators of Skype) does not mandate a mobile phone number (SIM cards are tied to government identity in many countries). Only an email address is required to open a free account. Nor does Wire mandate upload of your phone's address book with personal social graph of contacts. Free for consumers with paid teams offering for enterprises, optional on-prem server. Open-source clients and server. Cross-devi…

Matrix tools like Element is decentralised which is preferred, wire is not.

The company keeps a list of all the users you contact until you delete your account.

Source: https://archive.fo/ARZe4#im

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#100
post #90
post #76

Earlier quoted context omitted.

There is no such thing as an anonymous transaction, for a fully informed definition of anonymous. Bitcoin isn't... neither is cash in hand. Neither is a drop. Someone knows. A discussion of 'anonymity' in this context is one of increasing the difficulty of discovery, not thinking that the discovery is impossible. If a major world government is after you, good luck with "anonymous"

Monero is.

So you think if a notorious terrorist or whatever moved millions of dollars through Monero to fund a terror attack, American or other intelligence agencies wouldn't be able to identify the transaction?

It could be done truly anonymously when up against the full weight and might of US, Western, Israeli etc intelligence budgets and methods?

Post reply on HN