14 ms·
Technology preview: Sealed sender for Signal
- StudentStuff 8y agoThis is an unexpected move, perhaps Briar, Matrix and other distributed platforms are putting more pressure on Signal to show forward progress on the serious metadata issue with Signal and most other centralized platforms? Its been a rallying cry/common complaint by those who are technically inclined and privacy conscious for years now, surprised OWS would choose to give credit to the problem.
- tptacek 8y agoNo mainstream messenger has ever done a better job with metadata than Signal. It took Signal several years after launch just to get user profiles with names and stuff, purely because of privacy concerns. Read the blog post they wrote about GIF sharing to get a sense of how seriously they take this, then compare how their features work to other mainstream messengers. There is one privacy issue people put pressure on Signal about, and that's the use of phone numbers. Apart from that, Signal has always led the field on privacy issues.
- StudentStuff 8y agoBriar is leading the field on privacy issues today, unlike Signal. There is no metadata leaking who you are sending messages to or from, just a connection to the Tor Network. This problem is still unsolved in Signal, with only partial protection of some messages looking to be added in the future, while mitigation tactics like running your own server are unsupported & discouraged by Open Whisper Systems. The post about Giphy integration was a great piece of writing about an interesting technical challenge, and Signal's solution to the problem (a TLS proxy run by them, with a client that only accepts Giphy's TLS certificate, making queries quasi-anonymous) is not a bad way to go about solving things.
- tptacek 8y agoI am willing to stipulate "short of running everything over Tor" for the sake of argument.
- StudentStuff 8y agoI'm not looking to argue with you, just pointing out the current state of affairs wrt why so many privacy minded, tech aware folks either won't use Signal or choose to move conversations off it as quickly as possible. The reasons for avoiding Signal (metadata leakage, mandatory phone number usage, questionable 3rd party dependencies, etc) are valid, despite how I often argue to the contrary in favor of getting as many people on Signal as possible and using it for daily communication. Talking common sense to this demographic is hard though, in the context of basic security concerns persisting year after year. On the flipside, the phone number as identifier issue has caused apps like Kik (super popular among the gay community, despite shit security), Wickr and Wire to become popular among the non-tech demographics, which is extremely disheartening.
- tptacek 8y agoOf those issues, I believe only mandatory phone numbers are valid, for what it's worth. And I'm fine with mandatory phone numbers; there are other options for people who have a problem with that.
- StudentStuff 8y agoYou obviously have a different opinion on what a standard threat model is then...
- trash_panda 8y agoThere is no such thing as a "standard threat model". That's why the threat modeling concept exists in the first place, so you can adapt different solution to different requirements. It is totally OK if you are extremely worried about hypothetical scenarios where the phone number you used to register to the Signal network can be correlated to your physical location and then a gas station camera filmed you and then all is lost; but I want to believe that really at risk people are smarter than that, and just get a burner phone and even pay a homeless person a few bucks to buy it for them. There are also ways to get a phone number through the Internet, so you don't even have to go to a physical location to buy it. I think that's why Signal isn't prioritizing this right now, phone numbers can be a problem? yes. Is it hard to get a fake phone number that is not traceable to you? not really. Next problem please. I think Signal is achieving the goal of being the default go-to secure messenger. I'm sure, even technical people who like to nerd out on alternatives, faced with a real world risky situation when they have to communicate with a non-technical person, would recommend Signal without a second thought.
- dbrgn 8y agoThreema had decentralized, user-controllable (yep/whitelist/nope) avatars for longer than Signal had their server-stored avatars :) And without the requirement of linking your identity to a phone number.
- bjoli 8y agoBut they still claim that TLS provides proper forward secrecy, which is of course is true for a passive attacker, but not for a malicious server.
- amaccuish 8y agoHere's an idea, Signal, how about removing the requirement that everything be tied to phone numbers? BBM back in the day worked great with their unique "PINs", that could be shared by QR code, and I could reject an "add" request.
- pishpash 8y agoExactly. Allow out of band establishment of identity. Phone numbers are more hackable, they are also not anonymous.
- AndrewDavis 8y agoAs long as they have both that would be amazing. Phone authentication is better than nothing and lowers barriers to adoption. Perhaps when manually verifying an identity via the QR code add an option to generate a new id not tied to the phone number.
- deleted 8y ago[deleted]
- badrabbit 8y agoSecond this. A phone number is tied to an individual. Even though the conversation is secure,it makes targeting easier since the attackers know who is talking to whom(comments on pgp usage and why the NSA loves pgp: https://www.theregister.co.uk/2016/01/27/nsa_loves_it_when_you_use_pgp/ https://www.theregister.co.uk/2016/01/27/nsa_loves_it_when_y... ,former NSA chief hayden also made similar remarks). Let'a say a journalist is targeted by a sophisticated attacker. The attackers want everything on the phone,why just calls and messaging? They won't even attack the protocol,they'll first try putting a RAT in place which will have access to everything. Signal does not promise to protect your communication after your phone is compromised(which only makes sense) but now the attackers don't just have access to your messages but also to your contacts. They now know the journalists sources and contacts by the phone number they used.
- walterbell 8y agoWire supports email-only registration at https://app.wire.com https://app.wire.com (from a desktop web browser). The account can then be used to login from mobile or web. This approach enables "easy" mode for casual users who prefer phone number registration, while supporting additional privacy for others.
- Confiks 8y agoCan the URL be changed to the Signal blog post at https://signal.org/blog/sealed-sender https://signal.org/blog/sealed-sender?
- dannyw 8y agoYes, I don’t understand why TechCrunch blogspam is exempt from the normal original source rules. They don’t add any value and reduce the amount of information.
- pvg 8y agois exempt from the normal original source rules. It's not. But if you want something fixed/looked into, your best bet is emailing the admins. They're super-responsive.
- tmin 8y agoHow to fight spam if sender identity is not known? Currently I get at least a few marketing calls a week and don't know how to make them stop other than blocking the numbers.
- deleted 8y ago[deleted]
- esotericn 8y agoThe sender's identity is known to the recipient.
- wskinner 8y agoFrom the Signal blog post: > To prevent abuse, clients derive a 96-bit delivery token from their profile key and register it with the service. The service requires clients to prove knowledge of the delivery token for a user in order to transmit “sealed sender” messages to that user.
- forapurpose 8y agoThey add: > Additionally, blocking a user who has access to a profile key will trigger a profile key rotation. People who don't know you can't use the new sender privacy beta feature, but if you are willing to risk spam then you can allow everyone to use it: > users who want to live on the edge can enable an optional setting that allows them to receive incoming “sealed sender” messages from non-contacts and people with whom they haven’t shared their profile or delivery token. This comes at the increased risk of abuse, but allows for every incoming message to be sent with “sealed sender,” without requiring any normal message traffic to first discover a profile key.
- faitswulff 8y agoYou can test out the sealed sender feature on the beta releases of Signal: https://support.signal.org/hc/en-us/articles/360007318471-How-do-I-join-Signal-s-beta- https://support.signal.org/hc/en-us/articles/360007318471-Ho...
- ngngngng 8y agoHow does signal do media messages? All the time i'll open signal and see someone sent a picture but I have to download it. If signal doesn't store anything on it's own servers but ip and timestamp, where is this media message stored after it's sent but before I received? Am I just downloading it from the device that sent it to me? That would explain why it's so unreliable.
- wskinner 8y agoSignal does store encrypted media on their servers until your client downloads it (and for some time after).
- windexh8er 8y ago"Unreliable" - It's not. I've been using it since the early RedPhone and TextSecure days. The only times it's been remotely unreliable is because of my connectivity. I can say I've never had either a lost picture or file sent to me that I can recall. My family and circle of friends (~40 people) use it daily. I just transferred my backup from my old phone to a new one (which by the way thank you for implementing real backups Signal devs!) and I was surprised that my backup sat at over 300 thousand messages. I do leverage many group chats that are repositories of pictures, but I was actually surprised at the volume. To say Signal is "unreliable" is bull shi*. It's a fantastic product and service that I would gladly pay for but am glad it's free. In the meantime I'll continue to donate as Signal has been very reliable in my years of use.
- akvadrako 8y agoSorry but you must see how that's obviously jumping to conclusions. Just because you haven't had issues with Signal doesn't mean it's reliable. I have been using it for 3 years and struggle to recommend it to people because I constantly have reliability issues, including messages delayed for hours, bugs where contacts get in an unusable state and other little weird things. Whatsapp doesn't have these issues, so even if it's due to not being online 100% of the time, Signal should deal with it.
- 8y ago
- geofft 8y agoI'm not sure I understand the feature. It protects the sender's identity from their servers, or from the recipient? What's the use case / threat model? I think it prevents their servers from correlating my identity and my IP address etc., but since I want replies and I'm asking the server about replies, doesn't that operation tell the server what my identity is anyway? (There are some comments here talking about anonymous messages, but that doesn't sound right since the phone number is apparently kept in the encrypted, inner envelope, and also how would you route replies if you didn't have an identity of some sort for the sender?)
- 9034725985 8y agoI think their servers. (This is my imagination and it might be completely wrong so please feel free to correct me) they mentioned spam problem which leads me to believe that if enabled, the sending client will encrypt the whole message using the recipient's public key and put all metadata other than recipient's identifier inside this bigger encrypted envelope. The receiver opens this envelope with its key and opens the smaller box inside which contains the sender's metadata. What we lose now with this is the server does not have much insight into who is sending messages (by design). This means if you allow sealed sender from everyone, someone could send you a lot of messages which you may not like.
- tptacek 8y agoIt prevents their servers from easily tracking (and, importantly, logging) who sent which messages to whom.
- geofft 8y agoOh, I see - it effectively hides the fact that a conversation occurred between two participants from their servers. They know that I'm at my IP, they know that you're at your IP, and they know that we're both sending messages, but this feature prevents them from knowing whether we're sending messages to each other.
- tptacek 8y ago
- tptacek 8y agoTwo observations: 1. You should look into what other messengers do with sender/receiver pairs information. One very popular competing messenger logs pairs permanently, serverside, in order to make UI features work. 2. One of the least popular attributes of Signal (on Hacker News, at least) is its lack of federation and ability to interoperate with third-party clients. This feature is a pretty crystalline example of the kind of protocol change you can make when you control all the mainstream clients, and that would be an absolute nightmare for a protocol where you didn't.
- foolfoolz 8y ago#2 is part of the trade off for more privacy vs ease of use. this goes all the back to classic pgp
- tptacek 8y agoThe PGP ecosystem is a pretty great example of what happens when you target unbounded interoperability.
- foolfoolz 8y agoand it’s adoption rate is a great example of what that does to user experience
- TheDong 8y agoAre you trying to paint PGP in a positive light with this comment? Putting "user experience" anywhere near PGP/GPG makes most gpg users immediately gag. gpg offered a solution to encrypting email. No one uses it because it's unusable. gpg offered a solution to releasing signatures beside releases with the idea that users could verify them through the web of trust. The exactly zero people who notice when the person signing changes or a technical error results in an invalid signature shows no one actually verifies signatures. XMPP, when it needed e2e encryption, could not use pgp/gpg because their effectively unusable in what it's doing. gpg's adoption rate is not great, and any adoption it has is entirely in-spite of its bad UX, not because of it.
- Paul-ish 8y agoWithout cover traffic, its not clear to me that this would prevent a correlation attack from an adversary with resources.
- kijiki 8y ago"These protocol changes are an incremental step, and we are continuing to work on improvements to Signal’s metadata resistance. In particular, additional resistance to traffic correlation via timing attacks and IP addresses are areas of ongoing development." It won't prevent correlation attacks, but it does make metadata attacks in general harder and less confident. An improvement is an improvement even if it doesn't completely solve a problem.
- bigiain 8y agoIf my IP address is my current VPN endpoint - I'm only worried about "the global passive observer" - and if I've got them curious about me there's no sensible technical measure I can take to prevent losing out to them. As James Mickens teaches us: "YOU"RE STILL GONNA GET MOSSAD'ED UPON"
- bjoli 8y agoI feel like the bar is constantly being raised. Which messengers provide cover traffic? To my knowledge it is only pond, which has been discontinued. Pond was limited to text at about 5kB/s. Sustained connections is not suitable for mobile phones, and unless you sustain a data flow or introduce random delays correlation attacks will always be possible. Signal could probably force TOR connectivity (forcing websockets for those connections), which would conceal the sender even more, but would not stop correlation attacks. This also wasn't made to stop correlation attacks. This is a measure to reduce metadata being stored on the server. Messages stored on the server won't have a "from" label that can be read by the server.
- akhilramolla 8y agoTO signal, Verify my identity, send me an OTP.
- esotericn 8y agoI'm confused here. It seems the identities are trivially linkable via the IP address. The Signal servers can't determine cryptographically that the message originates from Device A. But it is certainly from device A, because this isn't a peer to peer protocol. It seems to me like what you'd need to make this work is some sort of intermediate layer, a bit like onion routing, that would have messages arrive at the Signal servers without basically giving everything away in the source IP field. With general use of NAT there's a N-to-one mapping of identities to IP addresses, sure, but this seems to be technically true whilst in many cases completely erasing any benefit of this entirely.
- ric2b 8y agoI think the point is that they can simply discard IP addresses as soon as they receive the message. If later they get a request from the NSA to look at their database, the undelivered messages can no longer be traced back to the sender.
- esotericn 8y agoAha! I see now. So it's a temporal thing. Previously, an undelivered message would have to sit on Signal's servers with the sender's metadata in cleartext. Now, it doesn't.