3 ms·
Signal is great as an all in one solution if encrypted messaging is a hobby. It is also very good for mobile and encrypted occasional messages. If you try to a
by mapgrep 6y ago
Signal is great as an all in one solution if encrypted messaging is a hobby. It is also very good for mobile and encrypted occasional messages.
If you try to actually build a secure environment within a group that tries to maximize security while getting real work done you find you want to be encrypted by default at least with each other. Signal is pretty suboptimal for heavy volumes of messages. If you and I have three threads going they are all jumbled together. If I want to send to more than one person I have to whip out my phone and form a group and name it.
PGP is imperfect but with the right settings and defaults it is far better than having email default to clear text. And in any long term endeavor with more than a few people you will find you want email.
Signal is great for what it does. It is not designed to be a high volume working tool like email though.
- skyfaller 6y agoSo you're saying that if you're building a professional secure environment, you don't need forward secrecy and it's ok to leak metadata? This doesn't make sense to me. The US gov't kills people based on metadata: https://ssd.eff.org/en/module/why-metadata-matters https://ssd.eff.org/en/module/why-metadata-matters It's not possible to make email secure, the flaws are on the protocol level. To fix it, you would need to change it until it is no longer email.
- mapgrep 6y agoI’m saying people will use email in any decent sized group over any significant length of time and it is very good to encrypt that email by default. If you’re saying Signal is strictly more secure I agee 100%. It’s just not suitable for using for large amounts of comms within a group. I wish they’d improve it and have even detailed features I think they should add (I made an HN thread when they got that donation from the whatsapp guy). For now it’s not realistic to expect people to know how to put ALL sensitive comms in Signal. You need to build an environment where as many channels as possible are secure by default. Setting everyone up with GPG and using it by default actually works in group settings and is much better than not doing it. The “just use Signal” meme is wrong. Because you can’t. Not at high volumes. (Also, metadata is a lot less important in the context of a group that openly associates with one another as a great many do. It does suck that subject lines leak. But better to encrypt the message body than throw up hands and give up because no perfect substitute exists. One learns not to put much info into subject lines. You can always just not use them. Signal does not have them.)
- skyfaller 6y agoWhat about Matrix/Element for heavier communications? It's at least encrypted by default now, although I haven't carefully studied their security otherwise.
- sudosysgen 6y agoMatrix is probably the only real alternative to email, I agree. Hopefully it becomes dominant.
- zajio1am 6y ago> and it's ok to leak metadata? How could Signal (or other client-server protocol) not leak metadata? It is true that OpenPGP leaks more metadata than necessary (e.g. Subject), but seems to me that any efficient message protocol needs to leak at least three most important metadata - source, destination, time. One could avoid leaking destination by broadcasting encrypted to many receivers (when only the true one can decrypt it) and therefore server does not need to know true destinations, but that is rather inefficient.
- skyfaller 6y agoSignal has been working on features like "sealed sender", which encrypts the source metadata: https://signal.org/blog/sealed-sender/ https://signal.org/blog/sealed-sender/ I don't know if they can do anything about destination or time, but even hiding the source seems like a significant advancement.
- JetSpiegel 6y agoHow does that even work? The only way to encrypt the sender is to send every (encrypted) message to everyone and let the clients drop the ones they can't encrypt. On a Phone. I hope they give out free batteries. The post mentions some kind of "short-lived" pseudo-sender, which is vulnerable to the same metadata analysis.
- sobani 6y agoEncrypting the sender is pretty easy. Deliver the encrypted message+sender at the destination. Only the receiver will be able to decrypt it and see who the sender was. Encrypting the receiver is a lot harder though. It will probably involve dropping off the message at some central location and some very fancy cryptography. Secure multi-party computation [0] will probably be involved. I don't know if it can be made scalable though. [0] https://en.wikipedia.org/wiki/Secure_multi-party_computation https://en.wikipedia.org/wiki/Secure_multi-party_computation
- 6y ago
- rendx 6y agoSignal pumps all traffic across AWS infrastructure, where the simplest of all traffic analysis can deanonymize its users. Signal relies on phone numbers (for reasons), which again is not exactly the best "metadata" to carry around. If you look at the NSA material in the Snowden cache, it becomes clear that the whole "US kills based on metadata" is fed by piggybacking exactly on such systems, like deanonymization of simple VPNs and other "streams of data with simple proxies in between". PGP can be used to encrypt headers such as Subject. Mail addresses can be temporary and pseudonymous much more easily than phone numbers. One could imagine building something like "Signal" on top of PGP and "email" that has all the "metadata hiding" properties of Signal, and more, e.g. by introducing delays and random relaying order on SMTP level. Deltachat is an example of an open project in that space: https://delta.chat/ https://delta.chat/
- tptacek 6y agoAh, the "sufficiently sophisticated PGP usage", where everyone uses ephemeral email accounts for each message, subjects are encrypted, nobody can reply plaintext, and nothing runs over an infrastructure that can be traffic-analyzed. That "Deltachat" doesn't accomplish this is besides the point, of course.
- jrochkind1 6y agoOne can imagine all sorts of thing. Are you saying that you routinely send PGP email with Subject headers encrypted, using temporary mail addresses and pseudonyms? This is your routine email use, with a bunch of correspondents who do the same? Or, along with "random relay ordering on SMTP level", it's just something you're imagining? If you're saying the PGP use you imagine would be more secure than the Signal use that actually exists... I mean, I guess that's cool.
- dane-pgp 6y ago> If you're saying the PGP use you imagine would be more secure than the Signal use that actually exists... To present an iron-man argument instead of a straw-man, imagine they were comparing Delta Chat to Signal, and pointing out that Delta Chat does encrypt subject headers[0], and that Signal users typically don't use temporary phone numbers (which are harder to obtain than temporary email addresses). If you want, you could try comparing Signal's proprietary network versus the global SMTP network in terms of how secure they are against traffic timing analysis. [0] https://delta.chat/en/help#how-does-delta-chat-protect-my-metadata https://delta.chat/en/help#how-does-delta-chat-protect-my-me...
- lmm 6y agoIf you're building a professional secure environment, forward secrecy is a tradeoff that you need to tune (and OpenPGP gives you the tools for doing so, viz. subkeys and expiration), you absolutely need federation, and identifying contacts by phone numbers (as Signal does) is a zillion times worse than leaking email headers. It's not possible to make Signal secure, the flaws are on the protocol level. To fix it, you would need to change it until it is no longer Signal.
- jrochkind1 6y ago> it is far better than having email default to clear text You have your email set up to "default" to PGP? Can you say more about what you mean by that?