7 ms·
On Ghost Users and Messaging Backdoors
- merlincorey 8y agoApparently some researchers from the GCHQ in the UK are proposing that "secure" messaging systems like iMessage and WhatsApp which manage group chats centrally in a manner that bypasses the end to end encryption should: - Add "ghost" users/devices to existing chats - Suppress notifications of these additions to users This would perpetuate a currently known bug in secure communication protocols, effectively turning it into "feature" for law enforcement. Fortunately, systems like Signal and Briar have already moved past this flaw.
- EGreg 8y agoWhat does that mean, “manage centrally in a manner”... and how does Signal not manage it centrally?
- vonseel 8y agoSignal groups are managed by the client devices. The details are quite complicated, but some are documented here: https://signal.org/blog/private-groups/ https://signal.org/blog/private-groups/ Perhaps another user with stronger familiarity on the subject can expand on this (ELI5 would be great!).
- EGreg 8y agoInteresting. Compare https://safenetworkprimer.com/ https://safenetworkprimer.com/ by the way
- zzzcpan 8y agoSignal client is centrally managed and can be updated for every user. And it's quite ridiculous claim that Signal can't implement a backdoor in the client because of some arbitrary design choice.
- gepoch 8y agoYeah security is not really "proveable" in any software system. However, a few points to consider: 1. The signal server can't "see" the group. Clients are just sending N messages to everyone in the group with some encrypted metadata that says it's a group message. 2. The client app is open source. You can go look for a ghost user or backdoor mechanism yourself. 3. The build is reproduceable. You can build it yourself and sideload your own APK, or compare it to the APK coming from the play store. I don't think it's impossible to put a backdoor in, but I think it at least makes vigilance a good defense. Smart serious people are paying attention.
- maxerickson 8y agoBinaries are not opaque gibberish, it is possible to analyze them. And of course for major apps, there are people doing so.
- hinata 8y agoAre these analysis efforts publically viewable?
- xorcist 8y ago> The build is reproduceable. You can build it yourself and sideload your own APK, or compare it to the APK Have you tried this? Most people seems content that there is some source available and trust the binary. That may not be an option for everyone.
- goblin89 8y agoKeybase Teams—also featuring e2e-encrypted group chat—appears to be proof against the ghost-user-based attack. It would be interesting to compare its implementation to how Signal does group messaging in TextSecure v2. [0] https://keybase.io/blog/introducing-keybase-teams#anyway-teams-have-signature-chains https://keybase.io/blog/introducing-keybase-teams#anyway-tea...
- maxtaco 8y agoThanks for the mention! We designed Keybase with these exact attacks in mind.
- zzo38computer 8y agoWhat is need is open protocols. Users can write their own implementation if they do not want to use the existing ones. WhatsApp uses XMPP according to Wikipedia, so you could implement your own according to XMPP, I suppose. You might also just use your own programs and protocols. If the messages are encrypted with the recipient's key then nobody else can know what is the message, but only that there is a message. So, you can implement encryption on client the server does not need to know about it.
- Tsubasachan 8y agoSignal is great and all but does it scale? If half a billion people sign up tomorrow can they cope? How deep are their coffers?
- tivert 8y ago> Signal is great and all but does it scale? If half a billion people sign up tomorrow can they cope? How deep are their coffers? At least $50 million, courtesy of a WhatsApp founder: https://www.wired.com/story/signal-foundation-whatsapp-brian-acton/ https://www.wired.com/story/signal-foundation-whatsapp-brian...
- RcouF1uZ4gsC 8y agoWith the spread of misinformation and rage using messaging apps that have literally resulted in people getting killed by mobs (see for example https://www.nytimes.com/interactive/2018/07/18/technology/whatsapp-india-killings.html https://www.nytimes.com/interactive/2018/07/18/technology/wh...) maybe we should re-evaluate our belief that making it impossible for governments to see what is spreading through messaging apps is an unmitigated good?
- Spooky23 8y agoI agree. There’s often an extreme point of view here with respect to this.
- jeklj 8y agoMaybe we should consider that goods can still be worthwhile despite their mitigations.
- RcouF1uZ4gsC 8y agoI agree, but when you do that, you need to actually make an accounting of the costs/benefits. If you look among programmers and security specialists on say HN there is not even a debate or discussion about this, but rather an absolutist position that this is good and that the only reason to think this is bad is if you are a totalitarian government wanting to oppress your people.
- rosser 8y agoI think you're conflating two different positions, which do admittedly co-occur in many people: 1. The technical, that any such "backdoor" is necessarily a backdoor, with all that implies, and thus to be eschewed on a "fundamental principles of good security" basis, and 2. The moral, that any such backdoor is crime against humanity, or whatever, because some of the people who have the technical capability will be leveraging it in order to oppress, and all of them will be doing so in order to act in a manner contrary to the user's interests. Who do our tools serve? Is it just that they should be made to serve someone else, against us? Where, exactly, is the line on one side of which it's justified, but on the other it's abuse? How do you build a system that prevents abusive uses, but allows appropriate ones? Decrying absolutist positions is all well and good, but it is a nigh-on tautology-level truth that a system with a flaw or backdoor, will be exploited — usually in multiple ways, and well beyond any potentially intended such.
- tjoff 8y agoInstead of creating a ghost user account and attempt to join a chat, why not just copy they key of one of the participants?
- bigiain 8y agoIn a "properly designed system", the service only ever sees public keys not private keys.
- tjoff 8y agoIf the point of a law is to circumvent encryption you shouldn't be surprised that it doesn't satisfy anyone who wants the encryption to be safe. Either the backdoor works and the system is bad. Or the backoor doesn't work and the system is illegal. At least if the law doesn't have a loophole. So not sure why the article complains about the design whereas the intent and goal are the real issue. Seems like the design works as intended.
- maxerickson 8y agoConsider that the article may be written for people on the law enforcement/policy side of the debate.
- tjoff 8y agoNot sure what that changes. If I was law enforcement / pro backdoor I'd say that this article supports my view. The main complaint seems to be that Over time what seems like a “modest proposal” could lead us to world where GCHQ becomes the ultimate architect of Apple and Facebook’s communication systems. But that is of course inevitable if the proposal is to be successful. What other solution would the author propose?
- tptacek 8y ago"Ghost users" are also a class of protocol and UX bug in secure messengers that are worth looking for; you will find secure chat programs where it's possible to add a member to a group with a very strong chance of not alerting other members of the group, whereupon the E2E encryption scheme of the system does all the work of decrypting the messages for you.
- deleted 8y ago[deleted]