10 ms·
This isn't really the issue. From further down on the article: """ There's a very effective attack here. Let's say Eve wants to break into Alice and Bob's exi
by flafla2 8y ago
This isn't really the issue. From further down on the article:
"""
There's a very effective attack here. Let's say Eve wants to break into Alice and Bob's existing conversation, and can get in the middle between them. Alice and Bob have been in contact for years, having long ago TOFU'ed.
Eve simply makes it look to Alice that Bob bought a new phone:
Bob (Eve): Hey Hey
Alice: Yo Bob! Looks like you got new safety numbers.
Bob (Eve): Yeah, I got the iPhone XS, nice phone, I'm really happy with it. Let's exchange safety numbers at RWC 2020. Hey - do you have Caroline's current address? Gonna surprise her while I'm in SF.
Alice: Bad call, Android 4 life! Yeah 555 Cozy Street.
So to call most E2E chat systems TOFU is far too generous. It's more like TADA — Trust After Device Additions.1 This is a real, not articifical, problem, as it it creates an opportunity for malicious introductions into pre-existing conversation. Unlike real TOFU...by the time someone is interested in your TOFU conversation, they can't break in. With TADA, they can.
"""
The quote you linked is relevant because it means that you can't simply ignore this problem; resets are fairly common, common enough that you can't just delete the key-loser's account (for example). However it doesn't have anything to do with the actual security flaw (if we want to call it that, it's really more of a UX / messaging problem) being discussed.
- thinkloop 8y agoThat exchange is not realistic, it's easy to ID family or friends by how they conversate. At worst you can ask a challenge question. The prompt that a device has changed is perfect to heighten senses for a quick ID. I disagree that physical contact is necessary as TFA (and industry lore) seem to recommend: > You must now reestablish identity, and in almost all cases, this means meeting in person and comparing "safety numbers" with every last one of your contacts Perhaps the alert could be a little more alerty and in red and read something along the lines of "Hey! Your buddy's safety code has changed, make sure they sound normal and aren't acting weird and creepy asking for information"
- dabernathy89 8y agoHow many people are realistically going to pester their friends & relatives with "challenge questions"? I bet even the majority of folks in the HN crowd don't/wouldn't.
- thinkloop 8y agoI'm not saying you have to know their first pet's name. I'm saying it's usually pretty obvious through regular conversation if someone is who they say they are, and worst case, if you're suspicious, you can ask about some shared past event without them knowing that they're being challenged.
- dabernathy89 8y agoI could see some people doing this if they notice obviously suspicious behavior on top of the safety number change, but I suppose that depends on the skill of the attacker.
- skybrian 8y agoYou are basically saying that social engineering never works, but there are many stories about how social engineering sometimes works.
- feanaro 8y agoWhy does it have to never work? No technique is perfect.
- geofft 8y ago"I'd love to chat, but I'm lost in a foreign country. Can you just Venmo me some money so I can get home and then we can talk about $shared_past_event later?"
- deleted 8y ago[deleted]
- OJFord 8y agoI was impressed that my non-technical parents challenged my brother when he (or someone claiming to be him) (claimed to have) lost his phone and other possessions travelling. I think as long as the meta message about the change of key is prominent/scary enough, even non-HNers will be as on edge as necessary.
- allannienhuis 8y agoThis is exactly the weakness that phishing exploits all the time - they only need to succeed a small percentage of the time. If they rely on users being vigilant or noticing odd behaviour, they are guaranteed to succeed some percentage of the time. That's a flawed system, not something you should blame on the user.
- dchest 8y agoAt worst you can ask a challenge question You can NOT verify anything by asking a challenge question. Man-in-the-middle attack means there's a "man in the middle". That is, the attacker can relay challenge question and answer between the contacts it attacks.
- tialaramex 8y agoThe _protocol_ can be arranged to help you do this, but yes just asking a challenge question inline doesn't protect against a MITM. If Alice and Bob know a good secret (say a 128-bit AES key) then they can definitely just use that secret to protect their communications against the MITM. This only requires updating the protocol to allow such a secret to be introduced. Mallory can continue to relay messages, but they are now passive and don't learn anything beyond traffic analysis or have any ability to tamper with the messages. But chances are Alice and Bob don't have such a secret (and of course they can't use the potentially MITM'd channel to agree one) I _think_ if Alice and Bob know a weak human secret they can do something here with a Balanced PAKE. A PAKE lets two parties agree a key based on knowing some relatively weak secret, Mallory can try to guess but only gets one chance each time this is done and failure is detectable by Alice and/or Bob. Again this requires support in the chat protocol itself.
- e12e 8y ago> It's more like TADA — Trust After Device Additions. Indeed. Or, "TA-DAA"! (trust after device addition/alteration, again) I'm not comfortable with this "secure" device held key. Maybe a private key that's pass-phrase derived could anchor the trust? So that the device key just becomes a trusted sub key/cert? With maybe a 30 day validity before renewal. (renewal ux being: please enter your pass phrase to insure continued integrity...)?
- geofft 8y agoThis is the idea of cryptocurrency "brainwallets," and the result seems to be that people are really bad at picking high-entropy passphrases. One of the nice things about cryptocurrency from a cryptography point of view is that it provides a direct, real-world monetary benefit to attacks. So we don't have to wonder if people will pick good passphrases or they'll be brute-forced—the experiment happened, and it wasn't promising. Using a passphrase alongside some online verification mechanism by a semi-trusted third party (e.g., your initial Signal app generates a secret, encrypts it to your passphrase, and stores it on Signal's servers who only return the encrypted secret to "your" new phone if it has your phone number too) might be enough.
- e12e 8y agoYeah, "cryptographically secure" and "something you remember" doesn't mix well. 128 bits (say) is a lot of data to memorize. Having it be a real approximation to random doesn't help. I suppose the pgp/ssh model of secure device holding the master key plus the ability to backup (eg qr code printout in a safe). An approximation for phones would be a random key locked in the device with a pin, an the ability to transfer and backup keys as you mention. Other than that - I've not really heard of gpg keys or ssh keys being brute forced - but that may be because by the point you gain access to the (encrypted) private key - you already have access to everything else? [ed: for example there are 52 cards in a normal deck of cards, meaning each card encodes about 5.7 bits(2^5=32,2^6=64). You could represent a ~128 bit key as a sequence of ~23 random cards. Or add add a few checksum bits and use half a deck (26 cards). Note, shuffling a deck isn't a great source of randomness, but you could use dice or a computer to generate the key - then map it to a sequence of cards.]
- hinkley 8y agoI'm seeing more multi-device verification logic finding its way into various systems (as with many advances in software, it started with a popular game), where the system tattles on every new device that shows up claiming to be you and you have to use an old device to vouch for the new one. But even if you do that well, you still have a MITM attack at registration time. The surface area is very small here, but a state or even corporate backed individual could certainly afford to perform such an attack. If there is no specific target, hacking an Apple store or a Best Buy to spoof all registration traffic and substitute your own would probably catch a lot of fish in your net.
- mirimir 8y agoI use KeyBase. Not long ago, one of my contacts deleted all their devices. So I got the skull-and-crossbones warning. Then they messaged me as a new account. Now this is an anonymous contact. There is no way that we will authenticate in meatspace. So I said "sorry", and pointed out that they should have shared a public GnuPG key with me before triggering a reset.
- mirimir 8y agoVery belated edit: That comes across as a bit heartless. I mean, we have no clue who each other are in meatspace. So why is a potential identity change so problematic? It's just the TFA example: > Bob (Eve): Hey Hey > Alice: Yo Bob! Looks like you got new safety numbers. > Bob (Eve): Yeah, I got the iPhone XS, nice phone, I'm really happy with it. Let's exchange safety numbers at RWC 2020. Hey - do you have Caroline's current address? Gonna surprise her while I'm in SF. > Alice: Bad call, Android 4 life! Yeah 555 Cozy Street. Now, I and my iffy correspondent have never shared anything actionable about third parties. But I do know a little about what he's doing, and have offered advice. And it would be very hard to continue doing that, without the risk of revealing potentially damaging information.
- jrochkind1 8y agoWait, how did you authenticate them the _first_ time? An anonymous contact who you will not meat in physical space who had no possible way to share a public GPG key with you prior to your original authentication...?
- mirimir 8y agoThey're just someone who contacted me, and asked for help with identity management, VMs, VPNs, OPSEC, etc, etc, etc. It's not uncommon, given how much I write online about that stuff. Sometimes, if they want too much hand holding, I request payment (Bitcoin). Sometimes I actually configure and test stuff for them, if they're willing to pay. But I have no clue who they are, and vice versa. Indeed, I emphasize that I don't want to know anything about what exactly they're up to. They could be hobbyists like me. Or criminals. Or cops. I mean, I have no way to know. So I don't worry about it. Basically it's TOFU. Ideally, they contact me via GnuPG encrypted email. So who they are is their public key, and an email address. Sometimes, for convenience, we more to Keybase or some other secure channel. But whatever, their identity is their public GnuPG key.