9 ms·
How the Textsecure Protocol Works
- theduckling1883 10y agoNice overview. I only wish for there to be an implementation of the signal protocol that fits my needs. In WhatsApp and Allo there are concerns of ad companies using your metadata, and the Signal app is lackluster in the UX department and OWS's affinity with Google is rather disappointing also.
- weinzierl 10y ago> I only wish for there to be an implementation of the signal protocol that fits my needs. ...and which most of my friends used. I'm OK with Signal's UX, but the problem is that I know exactly two people who use it too, everyone else is on WhatsApp. I mean: Writing this implementation would be hard, but still tremendously easier than getting enough traction to make it useful.
- akvadrako 10y agoPeople can change fairly quickly to a new platform and it doesn't have to be all or nothing. I stopped using WhatsApp and have convinced most of my friends to install Signal for communicating with me in place of SMS. However it's hard to recommend because of the lack of features.
- FabHK 10y agoWire seems fairly fully featured, open source, and claim to have a feasible "freemium" business model, i.e. later selling premium services on the platform. They claim they use the Axolotl double ratchet, though Moxie/OWS claims Wire uses a variation of the protocol they don't recommend.
- oakwhiz 10y agoI would be interested to know exactly what it is about Wire that OWS doesn't seem to approve of
- qznc 10y agoIt might just be that they did not look into it.
- eatbitseveryday 10y ago> Wire does not use Signal Protocol, they used some of our code to create a protocol of their own devising that we do not recommend. 4 days ago, no follow-ups to questions for details. https://news.ycombinator.com/item?id=12688012#12690148 https://news.ycombinator.com/item?id=12688012#12690148
- niftich 10y agoIf you're interested about this topic, I recommend the following readings previously posted on HN and drawing your own conclusions. They are listed in no particular order: [1][2][3][4] [1] https://news.ycombinator.com/item?id=12148728 https://news.ycombinator.com/item?id=12148728 [2] https://news.ycombinator.com/item?id=12361410 https://news.ycombinator.com/item?id=12361410 [3] https://hn.algolia.com/?query=%22wire%20does%20not%20use%22%20moxie&type=comment https://hn.algolia.com/?query=%22wire%20does%20not%20use%22%... [4] (long but enlightening read) https://news.ycombinator.com/item?id=11725602 https://news.ycombinator.com/item?id=11725602
- Arathorn 10y agoIt's beta currently, but we're trying to fill this gap in matrix.org with the Olm & Megolm ratchets as showcased in the web version of http://riot.im http://riot.im. Once it's implemented on mobile too (around the end of October) it will hopefully be a compelling option!
- Zhenya 10y agoSince What'sApp uses textsecure, can we be sure that they are blind to the content of our messages? Is there any way for them to get the key, still claim it's e2e encrypted, except for when they want to hand the key over to various states etc?
- FabHK 10y ago- we don't have access to the source code, so who knows what they have implemented? - even if they have implemented it faithfully, you should compare fingerprints. If they don't line up, you might be subject to a MITM attack
- ChoHag 10y ago> Instead, copies of the server's role in the key negotiation are stored by a centralized server for potential clients to fetch and use. This "centralised" and "server" are just about the worst words you want to hear in the description of a system like this and yet they are just thrown in there in a flippant comment at the end of a section? I think a more detailed description of this glorified cache is warranted.
- ChoHag 10y agoOh it's not warranted is it? Does whichever butthurt shill clicked that button want to suggest why we don't need more detail on which central server stores what in this self-proclaimed "secure" system?
- stouset 10y agoPerhaps people are responding to your unwarranted, toxic tone, your rudeness elsewhere in the comments, and your inability to give even a modicum of respect to the developers who've not only designed and openly published groundbreaking advances in secure private messaging protocols, and not only implemented them and freely distributed those implementations, but have also worked to have those designs incorporated into the some of the most widely-used messaging software in history.
- ChoHag 10y agoIt lacks the most basic, fundamental property of a secure system: A demonstration (actual proof can wait!) that it can be trusted without handwavium. I don't care if it's the dog's bollocks or the bee's knees. If I can't trust it, it's useless for secure communication. I don't give the tiniest shit how many hours some twat on the internet, or well-paid collection of highly-trained twats, has poured into its creation if they can't even be arsed to give a basic description of its most fundamental property. And that moniker can remain until they do.
- Canada 10y ago
- Canada 10y agoThis post doesn't explain the protocol all that well. This is a great explainer: https://vimeo.com/117532499 https://vimeo.com/117532499 I can't seem to find the PDF of the slides of this talk anymore. These are also very useful for understanding: https://whispersystems.org/blog/advanced-ratcheting/ https://whispersystems.org/blog/advanced-ratcheting/ https://whispersystems.org/blog/private-groups/ https://whispersystems.org/blog/private-groups/ https://github.com/trevp/double_ratchet/wiki https://github.com/trevp/double_ratchet/wiki
- binaryanomaly 10y agoPDF of the talk can be found here: https://deepsec.net/docs/Slides/2014/TextSecure_and_RedPhone-bring_them_to_iOS_-_Christine_Corbett.pdf https://deepsec.net/docs/Slides/2014/TextSecure_and_RedPhone...
- Arathorn 10y agoisn't the "double ratchet" describing the presence of both a DH ratchet as well as a hash ratchet, rather than "send" and "receive"?
- Natanael_L 10y agoTriple DH + the double hash ratchet makes up two of the big (separate) parts of the crypto in the protocol. One does key exchange, the other does per-message PFS.
- deleted 10y ago[deleted]
- jlgaddis 10y agoIs there any information available (or has there been any analysis done) on the quality of any random number generators in use on mobile phones, especially Android and iOS?
- sdrapkin 10y agoAn important part of the Signal Protocol is Triple-DH. I did not find a good illustration of how it works, so I made one: https://twitter.com/sdrapkin/status/738419956371628033 https://twitter.com/sdrapkin/status/738419956371628033
- ChoHag 10y agoLet me paint you idiots a picture. I am Alice. I want to talk to Bob, securely. I call Bob into my Safe Space (we have those now, in C21). I lock the tinfoil. I encover the blankets. I intimately verify that Bob is indeed the Bob we all now and love. Bob and I are ready to communicate and we do so. Enthusiastically. Bob leaves (without even a cuddle!), but I have more messages I want to give to Bob. Bob is too cute to pass up. You remember your old acquaintance Mallory, except he never looked like Mallory. He looked like Charlie, or maybe the vaguely defined Dave or Eve or Fuckinghellmykidunderstandsthisbullshit. When you saw Charlie, he told you "Don't worry Alice I'm here for you. I can wait here in your Safe Space and pass messages to Bob even if you're busy on some other Fling. And you don't have to tell me what the message says says, just put it in this box and lock it using these keys Bob gave me (I'm not lying!)". You don't remember where Dave came from, you were just in the pub one day and after a few pints there he was, promising that he could help you commu^Wfuc^Wtalk to Bob even when Bob wasn't with you because he, Eve, would always be there no matter what and you could depend on him totally because you can trust him and he's totally alright even though he gets nothing back from you he's always got your interests at heart over his own because he's just so trustworthy. Holy fuck I just can't do it any more. If you can't see it by now then good luck with your life. Fuckinghellmykidunderstandsthisbullshit.
- sctb 10y ago> Let me paint you idiots a picture. > If you can't see it by now then good luck with your life. > Fuckinghellmykidunderstandsthisbullshit. Please leave these out of comments on Hacker News, it's simply not OK.
- ChoHag 10y agoYou're absolutely right - this place is not OK and it's shepherding its community down the same toilet as the rest of them.
- deleted 10y ago[deleted]