4 ms·
This wouldn't be such a problem if Moxie hadn't removed the ability to communicate using SMS. SMS is federated and very difficult to block without disrupting e
by fgrte 10y ago
This wouldn't be such a problem if Moxie hadn't removed the ability to communicate using SMS.
SMS is federated and very difficult to block without disrupting essential services.
See: https://github.com/WhisperSystems/Signal-Android/issues/2818 https://github.com/WhisperSystems/Signal-Android/issues/2818
Of course going the route of using centralized services allows later monetization my Moxie and his brogrammers.
- jagermo 10y agoA little harsh, isn't it? They have several good arguments for ditching SMS, as explained here: https://whispersystems.org/blog/goodbye-encrypted-sms/ https://whispersystems.org/blog/goodbye-encrypted-sms/ Especially this one: SMS and MMS are a security disaster. They leak all possible metadata 100% of the time to thousands of cellular carriers worldwide. It's common to think of SMS/MMS as being "offline" or "peer to peer," but the truth is that SMS/MMS messages are still processed by servers--the servers are just controlled by the telcos. We don't want the state-run telcos in Saudi, Iran, Bahrain, Belarus, China, Egypt, Cuba, USA, etc... to have direct access to the metadata of TextSecure users in those countries or anywhere else.
- fgrte 10y agoNot such a problem if there is no real name attached to the phone
- sliken 10y agoJust because the government doesn't know your name doesn't mean they can't hurt you.
- kuschku 10y agoYet, Signal leaks the exact same metadata, if one serves an NSL to OWS. In a way, Moxie's argument (don't tie things to phone numbers, don't use a centralized system for message transport) is exactly why Signal itself is so problematic.
- sliken 10y agoWhisper systems did get a subpoena: "the only information we can produce in response to a request like this is the date and time a user registered with Signal and the last date of a user's connectivity to the Signal service." https://whispersystems.org/bigbrother/eastern-virginia-grand-jury/ https://whispersystems.org/bigbrother/eastern-virginia-grand...
- kuschku 10y agoRetroactively, yes. But the NSA could just require them to log all messages they relay between any two users – and they’d get the same metadata as from TextSecure.
- lorenzhs 10y agoI do hope you see the differences between those scenarios, though? OWS doesn't have a presence in Egypt. If Egypt tried to serve them with some legal document requiring OWS to provide such metadata, they'd be laughed at. Telcos, on the other hand, are usually based in the country in which they do business (and often have separate businesses in each country, e.g. Vodafone). As we've seen many times, it's pretty easy to get them to cooperate (voluntarily or by law). Much easier to get all the metadata you need that way.
- haffenloher 10y agoNSLs are not magic [0]. They are a legal tool that can be used to extract certain types of information (such as subscriber information and maybe a little bit of transactional information) that a service provider already has stored on their servers. However, they cannot be used to force a service provider to start collecting data or build a backdoor. [0] https://www.youtube.com/watch?v=YN_qVqgRlx4&t=20m16s https://www.youtube.com/watch?v=YN_qVqgRlx4&t=20m16s
- kuschku 10y agoSure, of course they cannot. And PRISM has never existed either. I'm not going to rely on the US government adhering to its own laws when they've shown they won't do exactly that. Instead, cryptography is supposed to prevent OWS from even being able to implement a backdoor.
- Crosseye_Jack 10y agoAndroid as a fork of TextSecure called Silence https://github.com/SilenceIM/Silence https://github.com/SilenceIM/Silence but the metadata would be easily accessed when sending encrypted sms. While the contents of the message may be secure who and when you were talking would be easily accessed.
- sliken 10y agoGenerally it seems that tying things to a SIM card (required for SMS) generally hurts privacy. Seems much better to replace centralized servers with a more distributed approach. Much like the original skype with it's supernodes. The problem is that generally smartphones (at least on the WAN) do not accept incoming network connections except those blessed by the OS provider (Apple and Google). Said push notifications are tightly controlled and not particularly feasible as a p2p network transport. I think what would solve this problem is a 2 level p2p system. The supernodes would be raspberry pi's,a plug computers [0], or even a wifi router. They can accept incoming connections, don't pay as much for bandwidth, could be shared among friends/family/neighbors. Even a 64GB microsd + arm would handle substantial messaging traffic. Then the more network and power constrained phones could check in with their preferred supernode, ideally falling over to other supernodes if necessary. Messaging traffic is tiny, so storing it 3-4 times on redundant supernodes would still be cheap. Said supernodes would earn reputation with their direct peers in the form of providing bandwidth, storage, and forwarding packets. That way it would be much harder to censor, fairly robust, and ideally still easy to use. Whoever writes the software could charge an extra $20 for a turn key raspberry pi or plug computer. [0] https://en.wikipedia.org/wiki/Plug_computer https://en.wikipedia.org/wiki/Plug_computer
- madez 10y agoI would love to see that implemented in Tox.