Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Switching from #WhatsApp / #Telegram to #Signal is not a solution if you really care about #privacy, #resilience and #autonomy

Switching from #WhatsApp / #Telegram to #Signal is not a solution if you really care about #privacy, #resilience and #autonomy

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
whatsapptelegramsignalprivacyresilience
4 Indlæg 2 Posters 7 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • arcanechat@fosstodon.orgA This user is from outside of this forum
    arcanechat@fosstodon.orgA This user is from outside of this forum
    arcanechat@fosstodon.org
    wrote sidst redigeret af
    #1

    Switching from #WhatsApp / #Telegram to #Signal is not a solution if you really care about #privacy, #resilience and #autonomy

    all of them are centralized services and depend on phone numbers, which makes them easy to censor, the best services are the one that don't require any personal data at all to register, like #ArcaneChat

    Keep the #family safe 💜✨

    #OpenSource #European #Europe #android #aws #bigtech #amazon #diday

    david_chisnall@infosec.exchangeD 1 Reply Last reply
    1
    0
    • arcanechat@fosstodon.orgA arcanechat@fosstodon.org

      Switching from #WhatsApp / #Telegram to #Signal is not a solution if you really care about #privacy, #resilience and #autonomy

      all of them are centralized services and depend on phone numbers, which makes them easy to censor, the best services are the one that don't require any personal data at all to register, like #ArcaneChat

      Keep the #family safe 💜✨

      #OpenSource #European #Europe #android #aws #bigtech #amazon #diday

      david_chisnall@infosec.exchangeD This user is from outside of this forum
      david_chisnall@infosec.exchangeD This user is from outside of this forum
      david_chisnall@infosec.exchange
      wrote sidst redigeret af
      #2

      @arcanechat

      From the web site:

      Fast, reliable, decentralized, anonymous, secure messenger. It's magic!

      Yes, that does indeed sound like magic because getting all of those is an open research problem. Given that you're spreading misleading FUD about Signal, my guess is that it's the 'private' that you're giving up and your approach is trivially vulnerable to passive traffic analysis for reconstructing the entire communications graph.

      I can't tell though because there's absolutely nothing on the web site about how the protocol does... anything. So perhaps you can answer:

      How do you ensure that a passive adversary who can see all messages going to and from a server in the network (a 100% realistic threat model post-Snowden, and one Signal was explicitly designed to address) cannot correlate senders and receivers and build a communication graph?

      arcanechat@fosstodon.orgA 1 Reply Last reply
      0
      • david_chisnall@infosec.exchangeD david_chisnall@infosec.exchange

        @arcanechat

        From the web site:

        Fast, reliable, decentralized, anonymous, secure messenger. It's magic!

        Yes, that does indeed sound like magic because getting all of those is an open research problem. Given that you're spreading misleading FUD about Signal, my guess is that it's the 'private' that you're giving up and your approach is trivially vulnerable to passive traffic analysis for reconstructing the entire communications graph.

        I can't tell though because there's absolutely nothing on the web site about how the protocol does... anything. So perhaps you can answer:

        How do you ensure that a passive adversary who can see all messages going to and from a server in the network (a 100% realistic threat model post-Snowden, and one Signal was explicitly designed to address) cannot correlate senders and receivers and build a communication graph?

        arcanechat@fosstodon.orgA This user is from outside of this forum
        arcanechat@fosstodon.orgA This user is from outside of this forum
        arcanechat@fosstodon.org
        wrote sidst redigeret af
        #3

        @david_chisnall

        > Given that you're spreading misleading FUD about Signal

        what part is FUD???

        > How do you ensure that a passive adversary who can see all messages going to and from a server in the network

        for a start, there is no single adversary that can observe the whole network, and switching from one relay to another and using several at the same time is easy, without losing your chats & data!

        how does signal, a central observer with access to all users' IP addresses is any better?

        david_chisnall@infosec.exchangeD 1 Reply Last reply
        0
        • arcanechat@fosstodon.orgA arcanechat@fosstodon.org

          @david_chisnall

          > Given that you're spreading misleading FUD about Signal

          what part is FUD???

          > How do you ensure that a passive adversary who can see all messages going to and from a server in the network

          for a start, there is no single adversary that can observe the whole network, and switching from one relay to another and using several at the same time is easy, without losing your chats & data!

          how does signal, a central observer with access to all users' IP addresses is any better?

          david_chisnall@infosec.exchangeD This user is from outside of this forum
          david_chisnall@infosec.exchangeD This user is from outside of this forum
          david_chisnall@infosec.exchange
          wrote sidst redigeret af
          #4

          @arcanechat

          what part is FUD???

          The part where you say:

          Switching from #WhatsApp / #Telegram to #Signal is not a solution if you really care about #privacy, #resilience and #autonomy

          Your only rationale in the comic is that they are hosted on AWS. Which is a problem for a secure private messenger only for a protocol that is not designed to avoid leaking any sensitive data including the shape of the communication graph to an adversary with complete control over the server.

          all of them are centralized services and depend on phone numbers, which makes them easy to censor

          This is misleading. The phone number in Signal is not used for message routing at all. It can be used to make you discoverable to contacts that were previously using the phone / SMS to connect to you. Being discoverable by your contacts is important for a private messenger because it gets you a big anonymity set quickly.

          for a start, there is no single adversary that can observe the whole network, and switching from one relay to another and using several at the same time is easy, without losing your chats & data!

          To take the two parts of this in turn: First, I would suggest you search for the term 'global passive adversary'. It's a core part of how any private messenger expresses its threat model. And, although a perfect global passive adversary doesn't exist, ones that monitor more than an entire country do exist.

          The second part is the real problem. How many people are there on each relay? I don't need to monitor the entire network to see what a person is doing, I need to monitor the servers that they talk to, and who those servers talk to. That's a much weaker adversary (achievable by a huge number of potentially hostile entities). And the way that you defeat an adversary like this is to have a large anonymity set, so that correlations between messages arriving and leaving are hard.

          how does signal, a central observer with access to all users' IP addresses is any better?

          We know, from the results of warrants, precisely what can leak from Signal: the timestamp at which you joined the network and the timestamp at which the client last connected to the network. What can a warrant with your protocol deliver?

          But if you're leaking things to a passive adversary that require an active compromise of another system then it doesn't matter if your system might be more resilient to an active attacker: an active attacker doesn't need to bother if people use your system. Just knowing which relay they talk to is already giving more data than a warrant against Signal delivers.

          But it also highlights the problem with a lot of distributed messaging systems: You can easily turn a single point of failure into a lot of points of failure. If a relay is operated by someone malicious, how much of the network's traffic can they observe?

          But, more importantly: you did not answer my question. You just attacked Signal. There are lots of things I dislike about Signal but you aren't even giving answers that tell me that you have solved the problems that they have solved, and you've got a design that introduces a load of hard problems that they don't have.

          Maybe try talking about how you've actually solved some hard problems with security and privacy, rather than starting off with an attack on other projects and claiming that you're better than them?

          1 Reply Last reply
          0
          • jowek@autonomous.zoneJ jowek@autonomous.zone shared this topic
          Svar
          • Svar som emne
          Login for at svare
          • Ældste til nyeste
          • Nyeste til ældste
          • Most Votes


          • Log ind

          • Har du ikke en konto? Tilmeld

          • Login or register to search.
          Powered by NodeBB Contributors
          Graciously hosted by data.coop
          • First post
            Last post
          0
          • Hjem
          • Seneste
          • Etiketter
          • Populære
          • Verden
          • Bruger
          • Grupper