14 ms·
Technology Preview: Signal Private Group System
- tptacek 7y agoAgain, in the theme of "features every group messaging system had already, but Signal didn't, because they hadn't figured out a way to implement it without turning Signal's central servers into a database of who's talking to who about what". Signal didn't even have user profiles until recently, for the same reason. Here, they've slightly expanded the state of the art in MAC-based anonymous credentials to accomplish their goal. One interesting aspect of this is that Signal gets to do this, because they have immense goodwill with the cryptographic research and engineering communities; though it's no guarantee of soundness, they have the advantage of having the feature designed, implemented, and ultimately reviewed by cryptography engineers that aren't generally/economically available to other messaging projects. This is either a reason you love Signal (raises hand) or can't stand Signal. My take is, if you're in the latter group, that's fine; I use Slack, too.
- noja 7y ago> This is either a reason you love Signal (raises hand) or can't stand Signal. Eh? Why either or? (and why are there people who can't stand it?)
- fnordsensei 7y agoI wouldn't say I can't stand it (indeed, I am using it), but I've had problems with it. Disappearing messages and the like: being contacted via another medium by a person, asking why I hadn't responded, with no record of there ever being a message on my end. It's OK in my books: a symptom of there being no server to step in and enforce a universal truth. You just have to understand what you're getting in exchange for the occasional inconveniences.
- myu701 7y agoI love Signal, and upsell it whenever I can. Signal has its ideosyncratic parts, some of which are being worked on, others not so much. Some of the more visible ones are IMO: Signal forces users to use phone numbers; some people don't like this because they want to use multiple ephemeral usernames so they can be 'Joe' to friends, 'kleptoclown' to their github group, 'dungeonmaster42' to their DND group, 'joesolutioner' to anyone who browses their personal website or business card, etc. that way they are not having to give out the phone number to strangers which represents Sim-jacking and spam risks. If you create a signal group and invite folks to it, you cannot remove members from the group (this is being worked on now) without them clicking the 'leave' button or creating an entire new group sans whoever needs to go, which causes loss of group history. Signal cannot have multiple mobile clients, only one mobile client and a single desktop version. WhatsApp Riot etc. all support clients in as many spots as you can login from. Again -> these are focused nitpicks, but in most cases Signal is much better for upholding the promise of 'you send someone a message and you have a reasonable sense that ONLY THEY will be able to read it' compared to the likes of Line/WhatsApp/FB messenger etc.
- tptacek 7y agoIt's really an engine for revealing people's true preferences for messaging, which, for many people, tend to be that they want all the ergonomics of Slack a lot more than they want cryptographically sound secure messaging. What's hopeful in all this is that Signal is, slowly, catching up. Slack can roll out new features just by assigning a couple developers to it, and Signal has to coordinate new cryptographic research --- not just new cryptographic research, but research that produces something deployable at scale within the resources of a project like Signal! --- so Slack (and Wire and Keybase) are at a permanent advantage here. But over time, Signal gets more and more usable without having to consider tradeoffs.
- pgeorgi 7y ago> that they want all the ergonomics of Slack a lot more than they want cryptographically sound secure messaging. So you consider accounts not tied to a phone number "Slack ergonomics"? Before WhatsApp that was the default.
- tptacek 7y agoI said it was a reason to hate Signal, not the only reason.
- juped 7y agoWhy would Signal (a drop-in SMS replacement) be compared to Slack?
- yarrel 7y agoIt's a great piece of software, so people love it. But the sometimes uncritical love people have for it doesn't help when it has issues. The main categories of people I've encountered who aren't absolute Signal fans are: * People who don't want to give out their phone number to random men. * People who weren't impressed by Signal's security issues coming up at the same time that it was being pushed as the replacement for GPG.
- JoshTriplett 7y agoHonestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup file and writing down a 30-digit passcode, completely separate from the normal Android process of moving to a new device. People keep long histories of messages, going back a decade, containing pictures and memories that aren't stored anywhere else. Message history is valuable data. This doesn't seem like a "new cryptographic research" problem, this seems like a "well-established crypto (encrypted files) plus integration with standard device backup/migration" problem. I really like Signal, I think they're doing things very well, and I wish I could use it without being constantly at risk of data loss. And this doesn't seem like an uncommon request, from what I've found. Is there something I'm missing that makes this a hard problem? Or is it just a problem that nobody has prioritized?
- Tomte 7y ago> ability to keep identity and full message history when moving to a new device. I would love that. But even with WhatsApp it never worked for me. Last three device switches: Windows Phone to Android: Not supported. Android to Android: something went wrong. Android to iPhone: Not supported.
- foota 7y agoMaybe the concern is exfiltration? Making it easier to move phones may also make it easier for a hacker to exfil your data from a local hack or your phone's cloud (i.e., just hack your Icloud and trigger restore to a new phone)
- JoshTriplett 7y agoUnencrypted data/keys should never be in the backup, only data encrypted to some passphrase. It's perfectly fine (and necessary) to require a passphrase to recover backed up logs on the new device.
- stilisstuk 7y agoBeen using signal since textsecure I think (I even think there was another name before that). In all that time, one thing keeps me thinking about backing out: phone numbers. When a contact decides to uninstall signal, I lose contact. Signal still thinks that the recipient has a signal account, and hence won't deliver messages via SMS.
- jblwps 7y agoAssuming you're talking about the Android app, but you can actually force sending with SMS. The option to do so in a conversation/thread can be found by long-holding the send button, which then pops up a context menu to send via Signal or SMS.
- stilisstuk 7y agoThis is not a long term solution :)
- rvense 7y agoIt's a per-conversation preference, as far as I remember. You only have to do it once.
- stilisstuk 7y agoIn that case: Thanks a lot! Did not know.
- commoner 7y agoFormer Signal users can unregister their phone numbers from Signal on this page: https://signal.org/signal/unregister https://signal.org/signal/unregister
- stilisstuk 7y agoYes i know that. So when people don't reply, I check three messages has not been delivered and try to find a why to tell my contacts how to unregister. Which is an unreasonable burden I put on people who try signal and decides it's not for them.
- SheinhardtWigCo 7y agoThe point of this seems to be hiding the identity of users when they fetch or modify group attributes - but why? The user’s identity is otherwise known to the server: they know that account X was accessed by IP address Y, and that IP address Y fetched metadata for group Z, therefore account X is in group Z. They can also figure out group membership by tracking clusters of messages that are sent simultaneously. What am I missing?
- 0xCMP 7y agoThey do not know that information unless they’re monitoring on-the-server in the clear. They simply know they’re talking to Signal servers. This new feature protects in the case of Information Requests because they themselves don’t know who is in what groups.
- SheinhardtWigCo 7y agoYou either have to trust the server operator not to keep logs, or assume they are keeping logs and _do_ know what groups you’re in. In either case, what is this fancy crypto scheme actually buying you?
- Forbo 7y ago> You either have to trust the server operator not to keep logs You don't have to trust, you can verify. This has been proven in court: https://signal.org/bigbrother/eastern-virginia-grand-jury/ https://signal.org/bigbrother/eastern-virginia-grand-jury/
- tptacek 7y agoThe fancy crypto is what allows them not to (effectively) keep those logs in the first place. If you build this feature without the fancy crypto, then even if you say you're not logging this stuff, you (effectively) are, because your system depends on durable access to that metadata in order to function. This is, for instance, the major security difference between Signal and Wire. One strong indication you have that Signal isn't logging this stuff is that they had to wait until they were able to advance the state of the art in anonymous credentials in order to implement group access control at all.
- pepijndevos 7y agoI really want Signal to succeed. Or rather, I want anything that has decent cryto and is not FAANG to succeed. The problem is not which messaging app I want to use, it's which messaging app my friends are using. That said, if I had to choose, I think Matrix has a slight edge in my books because it's a protocol rather than a silo. Even though Signal is private and open source, they are hostile towards people running their own Signal builds on company servers, and unwilling to federate with other servers. Essentially, you run the official Signal app on the official Signal servers, or GTFO.
- tptacek 7y agoMatrix and Signal aren't comparable from a security perspective. Because Matrix is a protocol rather than a silo, many (most?) of its implementations don't even support E2E, and because Matrix has its roots in an ecosystem where E2E was a nonstandard add-on, Matrix will never be as safe as Wire or Signal.
- e12e 7y agoNever seems a bit strong? Surely over the next decades we could have a Matrix 2.0 that is still federated, but mandates e2e (especially with Signal doing some of the research)?
- comex 7y agoTrue. On the other hand, there are some aspects in which Signal will never be as safe as Matrix. The big one is SMS verification. If someone loses their keys and has to reauthenticate over SMS, Signal notifies their conversation partners, but legitimate users do this all the time (in part because Signal lacks good key migration mechanisms), so said partners usually don’t see this as suspicious and often don’t bother reverifying the user’s identity. On Matrix’s side, I’m not sure how well it handles key migration (I don’t use it, for unrelated reasons), but it’s almost certainly less vulnerable to account theft in the first place. Matrix’s identity servers could of course be hacked or legally compromised, but they’re probably not as willing as cellular carriers are to hand over accounts to random people on request! Signal could improve its situation by getting better key migration support, but as long as it’s rooted in phone number identities, it will ‘never’ be as resistant to account theft. Another aspect is that Matrix, if you’re technical enough, lets you set up a custom server for your secret group, which is somewhat less vulnerable to centralized metadata interception (though there are holes, like centralized mobile notification relays). Admittedly, this is mostly out of scope for Signal, which focuses on security for non-technical users. Finally, to state the obvious, for many use cases, pseudonymity is safety. Along the lines of the “$5 wrench” XKCD, in practice the single most likely way for your secure messages to be disclosed is not through some clever protocol hack, but by their being pulled at rest from some conversation participant’s device – often with their active cooperation. Similarly, Signal’s deniability feature is cool, intentionally allowing users to forge cryptographically valid messages supposedly sent to them by others. But in practice, messages are typically leaked via screenshots, with no attempt made to detect forgery in the first place. In such an environment, the most effective defense overall is probably self-destructing messages, which Matrix... apparently doesn’t support, but will soon. (Yikes – like I said, I don’t use it.) But in cases where the people you’re talking to don’t need to know your real identity, pseudonymity is a close second. Its weakness is that people are bad at separating identities and maintaining opsec, but it’s still better than nothing. It’s strongest in cases where you’re part of a large group (say, of protesters): this greatly increases the chance that the adversary will be able to read your messages (with a mole in the group), but also means that they probably don’t care about you personally and would prefer to go after low-hanging fruit. Or even if everyone is equally protected, it increases the amount of time they have to spend going after each person, reducing the number of people they can find. Anyway, I don’t want to be too negative. The world is certainly better off for Signal’s existence. Maybe Signal will add non-phone-number account support someday, solving two of the issues I mentioned in one blow. Maybe it won’t, but it’ll still be useful to many people, and its continuing cryptographic research will strengthen other messengers, including ones that target use cases Signal does not. Still, I feel like there’s some dissonance. From a cryptographer’s perspective, Signal is head and shoulders above the pack; they really know what they’re doing, to an extent that practically nobody else does. But in other areas, Signal is just okay. Not bad, often better than average, but rarely outstanding. And that includes areas that impact security, like key transfer and the other things I mentioned.
- e12e 7y agoOverall cool stuff. It feels like this has implications for auth/authz schemes in general, like a variant of kerberos, or a way to do auth/authz for a ssh like service - maybe even a way to anchor trust (in user principals and service principals - like ssh keys and/or certificates)? If we replace "the signal server" with "the authentication/authorization service ("the AD service" / the organization's internal certificate authority")...? Maybe I'm just needlessly afraid of the complexity of managing a real world certificate authority (keeping it secure, keeping it running, keeping as much as possible off line..).
- badrabbit 7y agoVery nice (seriously!). Now, please let people use the platform without needing a valid phone number. The one major issue I have is that. Phone numbers are the new SSN, just like SSN is being misused by traditional businesses, phone numbers are also misused thse days (due to how you generally can be tracked down to a physical area for antifraud and how "everyone" has a cell phone) to uniquely identify users. I don't get why users can't be addressed by both phone numbers and a "signal id", if you opt-in to use a phone number for addressing, your phone will be verified and signal will resolve it to your signal id. If you opt out people will need your signal id to address you and you can't use it for SMS. What are the challenges with that? If I have a signal private group system, signal can find out a ton about me and my associations with others using only that information. Many other messaging platforms do not nees this very sensitive information from me to function. And it does not support a desktop only app even if you give them a phone number and verify you control that number. I am always reminded of General Hayden (Former NSA chief) was saying how they love PGP at the NSA because they can sniff metadata and know who talks to who, it lets them easily find who has something to hide so they can target them. Not that I have the NSA in my threat model but I am very sensitive to unnecessary metadata being generated
- bmarquez 7y agoWhat you're asking for is exactly how Telegram works, you can add someone with a phone number or by username, but if you add someone via username they don't see your phone number. Of course, Telegram chats are not encrypted by default, and there is some controversy over the encryption protocol. https://telegram.org/faq#q-if-someone-finds-me-by-username-messages-and-i-reply-will-they https://telegram.org/faq#q-if-someone-finds-me-by-username-m...
- Semaphor 7y agoLast time I checked, the only option to login was using a phone number. And at least the web client only has the phone number as login. I do not want to give them my phone number. Full stop. They can tie my account to my email, to my domain, to a chosen username, whatever. But if your service requires a phone number to use it, it’s not something I will use.
- beyprotester 7y agoUsing a throwaway for obvious reasons... I am grateful these are being worked on because they are extremely needed for some use cases. I have been part of a group organizing protest in Beirut and I was surprised there was no clearly go to app that provided the security features we need. We started off with WhatSapp because that's what everyone used before security became a concern. We then moved to Signal mostly to get auto-deleting messages. We then ran away to Telegram because there was no way to kick a compromised phone outside of a Signal group. We considered using Wire which seemed to have what we needed but the interface was a bit clunky and it did not run well on all the phones of the group... We are currently evaluating an considering Keybase.io which seems to have all the feature too, but not sure how it will handle about a hundred people in the group... If anyone has ideas about which apps are recommended for that (or has additional useful things) please help, the main things we need are: - Encryption E2E is nice to have but not a deal breaker. - Possibility to kick a user from the group, deal breaker ( a thug stole someone's phone in the protest once and another time we got a message saying someone's security code changed then they became inaccessible) both incidents ended up ok but there was no way to kick the person out of the group and proceed while clearing things out with signal. - no old history kept of the conversation. Either auto-deleting messages set to short duration like signal, or if not possible we can survive with an admin at home deleting old messages constantly and clearing the chat for everyone in sensitive situations ( like telegram allows) - Free. For various reasons, some people can't buy apps no matter how cheap. - easy to use. Most protesters are not too technical. - possibility to display sender and group but not the content of messages in the notifications. - having an easy way to add password to the app itself. (nice to have) - making screenshots inconvenient to take (just nice to have). - Not tied to phone numbers also really nice to have but not mandatory. Our main threat is riot police and pro government thugs taking protesters phones and forcing people to unlock them or running away before the phone is locked then snooping around. Very rarely are people alone when this happens so we almost always get a notification that X is compromised, so we clear chats and kick them out of the group before their phones are really compromised. I don't think the government is running sophisticated deep packet inspection. I don't think our group has been infiltrated but that is always a possibility. We are also trying to find some free device management solution to remotely track / lock and maybe wipe phones when they get taken. Sorry for the wall of text... just though now might be a good time to ask...
- RustyRussell 7y agoWhat I really want from Signal is the ability to use it as an application transport. In particular, I want to authorise certain people to request my phone's location. At the moment I share it with Google so I can share it with friends or family, which sucks.
- DrAwdeOccarim 7y agoMaybe ask the writers of Mr. Robot. They figured it out!
- unnouinceput 7y agoPlease. I hope that's sarcasm. Because if it's not, then may I steer you clear of that annoying series and into Breaking Bad + its follow up Better Call Saul?
- DrAwdeOccarim 7y agoNo, I'm being totally serious.../s
- Vinnl 7y agoThis is with Telegram (which I'm not a fan of), not Signal, but it might still be interesting to you: https://osmand.net/blog/osmand-telegram-released https://osmand.net/blog/osmand-telegram-released
- panda921 7y agoI noticed this from the paper: > Note that a user who has acquired a group’s GroupMasterKey and then leaves the group (or is deleted) retains the ability to collude with a malicious server to encrypt and decrypt group entries. We deem this risk acceptable for now due to the complexities in rapid and reliable rekey of the GroupMasterKey. Does this mean that the server and a deleted user can always collude to get the deleted user readded to the group? Also, is there no provable audit trail of who added or deleted whom? Unless I'm misunderstanding, it seems like deleting a user is therefore enforced only via server trust, but please correct me if I'm wrong.
- tialaramex 7y agoYes, this means the server and a deleted user could collude to re-add them, or anybody of the deleted user's choosing to the group, or to remove selected people from the group (the server doesn't need collusion to remove random people from a group) No, the members of the group would be able to see that the deleted user is back, or whatever else has happened to the list. Signal's server isn't responsible for deciding who gets the group messages, only for storing the agreed list in encrypted form. So members don't need to trust that the server did as it was told. Certainly if you have a group where you suspect a member of colluding with the Signal server to betray the group you should probably NOT remove that member but instead take the extra trouble to explicitly form a new group (without that member obviously).
- panda921 7y agoGot it. I was thinking that for bigger groups, it might be hard for members to keep track of who got deleted when and by whom, so it might be easier for a deleted user to slip back in without attracting notice. Your point that the deleted user and the server can collude to add a rando to the group seems like a bigger deal, since it would be harder to catch. To make the same point more critically, if the members need to constantly recheck the mapping of group name to membership list (to stop server cheating), then the scheme might not be buying much.
- jolmg 7y agoI think I know the answer already, but just in case: is there a way to use Signal to communicate with users using Whatsapp? IOW, can I receive Whatsapp messages in Signal? The only reason I use Whatsapp is because it's what all my contacts use. It's everywhere. It's the de facto standard for text communication. And I hate the app. I hate its guts. I read that whatsapp implemented the signal protocol, does that mean anything with respect to being able to communicate with people using a different app? Because I was hoping so, but I can't find a way to see my whatsapp messages in signal.
- unnouinceput 7y agoYup, you guessed right. By default that's a no. However, you can do a cow-helicopter by using a 3rd party that will be a proxy between your signal account and your whatsapp account. Hell, you can do whatever you want between any 2 services with a 3rd party. Problem is, you still need an account on both ends.
- anoncake 7y agoNeither the Signal guy nor Facebook like interoperability, so no.
- unnouinceput 7y agoI really hope Signal takes over the world from Whatsapp. I hate Whatsapp and yet I am forced to use it due to all my friends / family / parents use of it. I try to fight but is hard and currently FB mess and WA are the only ones with a consistent reliability of delivering notifications promptly, while rest of chat apps either are too hard to use for non-computer people or they lose notifications. I mean, c'mon Microsoft!!! Is it really that hard to make Skype reliable again?!!
- misrab 7y agoIs it a coincidence this came up on HN at the same time Telegram is getting dissed on HN? Can't help but think it was coordinated...which is sad for HN
- anon9001 7y agoPeople don't like Telegram because it's a centralized thing and maybe not trustworthy. I'm not sure if I'd trust the Telegram founders, and their commitment to open source seems questionable to me (no server, outdated clients). People advocate for Signal because it's arguably the least offensive of the available e2e options. Also the founder for Signal has a long history of doing good work in this area.
- anoncake 7y ago> People don't like Telegram because it's a centralized thing and maybe not trustworthy. Just like Signal. > I'm not sure if I'd trust the Telegram founders, and their commitment to open source seems questionable to me Meanwhile Moxie Marlinspike's opposition to free software is evident. You use the client he dictates or fuck off. There's closed source software that respects freedom more than Signal.
- anon9001 7y agohttps://github.com/signalapp/Signal-Android https://github.com/signalapp/Signal-Android Can't I build and use this if I want? It looks very open, but I haven't tried building my own client.
- anoncake 7y agoFree software is not about being able to compile and code Moxie Marlinspike allows you to use. It's about freedom that he opposes: https://github.com/LibreSignal/LibreSignal/issues/37#issuecomment-217211165 https://github.com/LibreSignal/LibreSignal/issues/37#issueco... Yes, Signal's licensing complies to the letter of how we define free software. But that is irrelevant as it violates the spirit.