5 ms·
I believe you consider phone numbers pseudo-anonymous identifiers, which I believe Matrix names also qualify as. Is there any technical reason why Matrix serve
by fiter 6y ago
I believe you consider phone numbers pseudo-anonymous identifiers, which I believe Matrix names also qualify as.
Is there any technical reason why Matrix servers would have to store contact lists?
Both Signal and Matrix would have store message metadata to deliver it.
I searched for what the significant difference is, but could not come up with a good document to read.
- badrabbit 6y agoPhone numbers are the most identifying piece of information. They are precise identifiers not pseudo-anonymous. A non-burner phone can easily be converted to a complete background check on the person for under $50 ,for a higher price it can be converted to current realtime physical address.
- ChristianBundy 6y ago> easily be converted Could you link to a reputable resource for this? I've always imagined that phone number background checks were mostly scams with a bit of public information sprinkled on top. I'd be very surprised to learn that I could purchase a burner phone, give you the phone number, and have you be able to tell me my address and criminal history.
- fwip 6y agoThey just said "non-burner phone."
- snazz 6y agoFor non-burner phones, just Google the phone number---you'll probably get a sketchy "look this person up for $XX.YY" telephone directory page that will contain their full name and age, if not their address.
- tialaramex 6y agoSo, I just Googled my phone number, and the phone numbers of several friends. In each case I got dozens of the same flavour of site, which I've seen many times before, it has a paginated list of every possible phone number that could exist, and an advertisement. These sites are pretty cheap to build and presumably over their lifetime they bring in enough advertising revenue to justify renewal costs, hosting and so on. But they don't offer (and couldn't deliver) personal information about any of us, since that isn't publicly available.
- tptacek 6y agoAt any rate all of this misses the point; Signal doesn't use phone numbers because phone numbers are an especially good identifier, but as a UX tradeoff to keep metadata off their servers.
- badrabbit 6y agoI have good reason to believe this UX "tradeoff" is being actively abused. Several vectors,but the main one has to do with contacts of a compromised target,or when a target adds you as contact. In practice,it's worse than having to use your SSN. You don't need SSN to sign up with all the major apps and sites (including free email),but you do need a phone#.
- fossuser 6y agoCan you go into a little more detail (or link me somewhere that does)? This sounds like an interesting trade off, but I'm not totally following how using phone numbers and contacts avoids the metadata on server issue.
- Arathorn 6y agoI think it boils down to the fact that in Signal the server can't see which conversation messages belong to - and if sealed sender (aka secret sender) is enabled, the server can't see who they're from. (As far as I know, the server still tracks the phone number of accounts and thus the recipients though - looking at https://github.com/signalapp/Signal-Server/blob/2b987e6e9301a290648ccc77402172b275083933/service/src/main/java/org/whispersystems/textsecuregcm/controllers/AccountController.java#L185-L198 https://github.com/signalapp/Signal-Server/blob/2b987e6e9301...) Unsure how this relates to contact lists though (other than that secret sender is apparently only available for messages from people in your contact list?) Matrix on the other hand isn't a message-passing system like Signal (or IRC or XMPP or SMTP) - instead it's a way of securely storing your conversations (more like NNTP or IMAP). This means that when you log into a new Matrix client you can get at your conversation history, and it means that even if you lose all your clients you don't lose your history. The compromise is that Matrix ends up storing the metadata of who spoke to when in the conversation history which is stored on the server. However, we're working on mitigating this with P2P Matrix (where you run the server clientside, unless you explicitly want to pin that conversation to a serverside server), as per https://fosdem.org/2020/schedule/event/dip_p2p_matrix/ https://fosdem.org/2020/schedule/event/dip_p2p_matrix/ - and it even works :)
- mirimir 6y ago> I'd be very surprised to learn that I could purchase a burner phone, give you the phone number, and have you be able to tell me my address and criminal history. OK, so even if you pay cash, there's video surveillance in the store, and surveillance (license tag, video, etc) on the route. And that's linked to the number. Then there's the number that you call from to activate the burner phone account, which may have some identity information. Plus geolocation data for that, and for the burner phone.
- mirekrusin 6y agoWhen I was living in Brazil to buy any kind of SIM card you had to give your CPF or whatever it was called number from your residency card. I believe many countries have this rule as coiner terrorism measure or whatever. Of course for bad guys it’s trivial to go around those restrictions.
- vinay427 6y agoAnd that's a near best case scenario in the US, UK, etc. In most of Europe and many other countries, you have to officially register a SIM card with an ID/residence document to use it.
- mirimir 6y agoHuh. Is that more or less recent? I guess that I'm a few years out of touch. There's no ID requirement in the US, I think.
- badrabbit 6y agoNo legal requirements, hence burners. But as a rule carriers enforce it.
- vinay427 6y agoI don't believe this is true. It's very trivial to find a prepaid SIM in the US that one can just purchase, activate, and top-up with reload cards (which in turn can also be purchased with cash). Postpaid plans do often require ID verification because of the credit that is being extended, which I think is more than reasonable.
- badrabbit 6y agoI said a non-burner phone
- tptacek 6y agoSignal's servers store no contact lists at all. It's not that phone numbers are some especially good anonymizing identifier; obviously, they are if anything the opposite. It's that everyone who uses Signal already has a local contact list keyed on phone numbers, which Signal's client applications can access, which means the server doesn't have to know about contact lists in the first place.
- gojomo 6y agoBut this ostensible "Signal's servers store no contact lists at all" policy also incurs several serious risks: * The Signal client regularly re-sends your complete local contact phone numbers to the Intel SGX contact-intersection code on Signal servers. So, potential flaws in that process would mean Signal servers continually receive, & could possibly log, far more metadata than competing systems that upload all your contacts' phone numbers. * Signal leaks that your phone number has enrolled with the Signal service to anyone who chooses to query it.
- tptacek 6y agoYou are comparing the possibility that something could go wrong and expose contact graphs to systems in which exposure of the contact graph is a foregone conclusion, because the servers store them, durably, online, in plaintext. The point of the Signal design is not having to do that thing, and, indeed, it doesn't, unlike other secure messengers that do.
- gojomo 6y agoNo, I'm comparing Signal to desirable properties of a secure messenger for many important uses. It's great that Signal has devised a system that, ostensibly, obviates the need for them to keep persistent lists of everyone's correspondents. But as that same system requires the constant, repeated uploading of phone-number-identifiers, and complete trust in Intel SGX™, it misses the primary thing most want from an end-to-end, open-source solution: no reliance on remote personnel or systems. Signal's created a fancy 'Maginot Line' that ultimately reduces to the same core flaw as much-simpler architectures: if a small number of hard-to-monitor key people or servers are compromised, even temporarily, the metadata is also compromised. You tout that "Signal's servers store no contact lists at all". But can you prove that? Signal's servers are still sent all the same data that would be required to do that. Meanwhile, other secure messengers manage to: * avoid ever knowing a users' phone number, or revealing a users' phone number to their correspondents * avoid broadcasting the fact of a user's participation to anyone who cares to query It's important to remember these caveats & tradeoffs when alleging Signal stores no contact lists at all.