11 ms·
What Is the Signal Encryption Protocol?
- upofadown 6y agoThis article mentions an important fact about forward secrecy: >Perfect forward secrecy is useless, it's important to note, if users don't delete their messages periodically. Then: >The Signal app offers disappearing messages that are automatically deleted after a certain time limit. Which is not turned on by default. The user has to somehow know that they have to do this to get the benefit of forward secrecy. This seems all too common with contemporary encrypted messaging stuff. Really great features that depend on having the users behave in a way they normally would not. Of course the app can do this wrong simply by failing to do a secure delete that actually removes the messages from the storage device. In the end the actual communications protocol doesn't make very much difference in the face of counter productive implementations; conceptual and/or technical.
- xiaomai 6y agoI think not having it disappear by default is reasonable. My biggest complaint about signal is how hard it is to preserve history (backing up / transferring to new devices). I think the normal expectation is that your data is not going to automatically disappear unless you ask it to.
- asquabventured 6y agoWhen was the last time you moved devices? I was able to wirelessly import my entire years old messaging and contact database when I switched iOS devices ~10 months ago. I don't recall if it used NFC, Bluetooth or having to be connected to the same WiFi network but it worked impressively well at the time.
- xiaomai 6y agoone thing i have done recently that definitely didn't work is syncing history from phone->desktop. i haven't gone phone->phone in at least a couple years though--good to hear that that's working better.
- bilal4hmed 6y agoThey recently improved it on iOS https://signal.org/blog/ios-device-transfer/ https://signal.org/blog/ios-device-transfer/ on Android you have to do it manually and its by no means easy or intuitive if you are an everyday user. Whatsapp nails this experience on Android with the back up and transfer capability
- Mediterraneo10 6y ago> Whatsapp nails this experience on Android with the back up and transfer capability Note that Whatsapp’s backups are in plaintext and sent to a Google property, while Signal’s backups (even if more cumbersome to set up) are encrypted with a key that only you know.
- bilal4hmed 6y agoyes good catch, I forgot to mention that. I wanted to highlight that for the average user being able to backup and move messages to a new device easily is a big plus even if its insecure. I hope in 2021 Signal can improve their new transfer method by allowing transfers between Android devices or even ( albeit far more difficult) android and ios
- fidelramos 6y agoBut WhatsApp backups are stored unencrypted on Google Drive. So either you have backups or you keep your privacy from Google and Facebook.
- jaywalk 6y agoThe iOS transfer process uses the same technology as AirDrop, what Apple calls Multipeer Connectivity: https://developer.apple.com/documentation/multipeerconnectivity https://developer.apple.com/documentation/multipeerconnectiv... The phones create their own ad-hoc Wi-Fi network, similar to Wi-Fi Direct.
- climb_stealth 6y agoI think the problem is losing access to a phone. For example because it gets dropped or stolen. The lack of good message backups on iOS makes me hesitant to recommend Signal more.
- Mediterraneo10 6y agoAt least on Signal for Android, you can make all the periodic backups of your Signal messages that you want: just be sure to copy the most recent backup file from your phone to another computer, and keep the encryption key (i.e. the sequence of numbers that Signal generates for you) written down somewhere. Then, if your phone does get dropped or stolen, you will have only lost messages since your last backup.
- pseudalopex 6y agoSignal for iOS goes out of its way to prevent this.
- izacus 6y agoThe Android backups are also to SD card only - you "just" need to manually handle cron jobs to copy off device, "just" make sure you copy of a really long key (you're not allowed to enter yourself) and "just" hope that a year down the road you still find all of those data. It's a horribly shitty user experience all but most mindful techies. The issue with Signal is that their developers fundamentally don't value the content of conversations in the way that millions of other people do - people send photos of their loved ones, have meaningful conversations and they fundamentally care about not losing them. Signal developers think that that's all worthless and needs to be destroyed ASAP.
- neckardt 6y agoI have the opposite problem where I can't turn disappearing messages on by default. Every time I create a new conversation I have to manually set messages to disappear after a week which I often forget to do.
- glitchc 6y agoI never understand this logic. You want end-to-end encryption, which entails building a complex, clever mousetrap so that only the device in your hands is capable of viewing the messages you receive, AND you want to back them up so that they can be retrieved later on a different device that was not part of the trusted setup?? If the backup is a priority, perhaps end-to-end encryption is not suited to your use case. And no, it's not simple at all to provide this technology in a meaningful way that is both as secure as you need and as convenient as you want. Nor should it be free if it ever exists.
- pseudalopex 6y agoThe Android and desktop versions already do this. Why shouldn't it be free?
- glitchc 6y agoDo they? Where are the encryption keys stored? Are you able to recover your backups if you lose your desktop?
- pseudalopex 6y agoDesktop stores the key on disk already. Android shows a key you write down.
- AnonC 6y agoYour viewpoint leaves out a larger number of people who want security (as recommended by experts) and convenience without having to understand all the nuances or complexities involved in a solution. Such a description also makes it very hard to recommend Signal to lay people because they don’t know or care much about security but do want convenience. If Signal is meant to be for a small echo chamber group to use, this is fine. If not, the convenience aspect cannot, and should not, be ignored to increase adoption.
- bonestamp2 6y agoI agree with both of you. It should be off by default, but it should notify users initially and periodically about the benefits of turning it on so they are aware of it.
- godelski 6y agoAs someone that doesn't fret with the saving history part I'm curious why people save their texts and back them up. Honestly it is a bit creepy to me. I can understand saving special texts (especially for a short time period) but it seems weird to me that people want to save texts from a year ago that talk about what I had for breakfast. There's something I'm not getting here, can someone enlighten me? Like I've never searched my texts for something that is more than a few weeks old. Any further back than that and I just directly ask the person (it is way faster).
- im3w1l 6y agoPeople drift apart or even die.
- mikem170 6y agoOne reason may be that some people are hoarders. It's in our genes, like squirrels packing away nuts for the winter. Another may be that texts are like emails for some people, and some people have reason to save important emails. I know a real estate agent that does a ton of stuff via text. I delete texts after I process them. If I get a pic I want to keep I save it and back it up on the computer. I don't really save emails, either (I empty my trash every couple of months) EDIT: added email comparison
- godelski 6y agoI'm not sure the email comparison is good. We usually do a lot of business via email. So it makes sense to have records. Whereas texting we are just casually having conversations. Most people don't use it for business, though I'm sure some do. I do completely understand archiving specific texts (sorry if this wasn't clear in my original statement), but the mass saving is weird to me. It feels akin to having a conversation with my friend and them just pulling out a microphone and recording our conversation. And then when asking why the answer is "for my records" or "it's my data". And I'm accused of being the weird one. I guess I just fundamentally don't understand.
- pseudalopex 6y agoSaving history doesn't have to mean saving every message.
- jolux 6y agoAs far as I know, you still get some benefit even with it off; it means that MITM attacks are much less valuable.
- jooize 6y agoI tried arguing for being able to delete messages from all parties of a conversation. [1] They were feature-averse back in 2014 for good reasons, but perhaps now they would consider implementing Delete Messages When Requested on a per-conversation basis. [1] https://github.com/signalapp/Signal-Android/issues/1764 https://github.com/signalapp/Signal-Android/issues/1764 (2014)
- godelski 6y agoI've participated in some form conversations on the topic. At least people on the form are very against message deleting. Although Signal does have a bidirectional "delete for everyone" feature now. But you can only do it within 3 hours of sending the message.
- AnonC 6y agoThree hours is a very short duration, IMO. In my opinion, it should be at least a day (24 hours) or cover more than one’s average sleep duration so that any messages sent in haste can be removed once better senses prevail. Considering time zone variances across the people involved in chats, I think something more than 12 hours would be good. We all have a need to amend our messages after ruminating on them for sometime. The three hour limit doesn’t gel well with how humans work (on this matter, even the HN edit limit duration is very short).
- godelski 6y agoYeah so I'd encourage you to write that on the signal forums. The discussions are very one sided. The arguments against deleting are "it's my device, so my data." The people there are very unhappy with the fact that you can even delete now (feature is like 2 months old).
- JoshTriplett 6y agoThat argument alone should suffice. Down that path lies trying to lock down other people's devices, people complaining that they deleted a message but others have screenshots, etc. Once you've sent a message, the message is sent. Once it's on my device, it's mine. If you don't want someone to have a message, don't send it.
- tzs 6y agoI thought that the purpose of perfect forward secrecy was to protect against eavesdroppers who had recorded your encrypted traffic in the case of your secret keys somehow leaking. Protecting messages at rest at the source or destination is out of scope for perfect forward secrecy.
- schoen 6y agoYes, for example your key could be stolen through electromagnetic eavesdropping (Cryptography Research had an amazing demo of a practical side-channel attack at the RSA conference one time), but that doesn't mean that all of your message contents are exposed that way. Or, malware on your phone could exfiltrate your key but not all of your messages because that would somehow be more suspicious/noticeable, like if you were on a metered mobile data connection. But if the attacker is a government or has otherwise compromised telco infrastructure, the attacker might already have copies of your old encrypted traffic -- which, without forward secrecy, it could use. I think the context of the claim in the article is pretty much only for the "government physically seizes your phone and examines its contents" scenario: but even for that scenario, a user might choose to selectively delete specific messages without deleting all of them (e.g. Signal allows you to delete an entire "conversation" with a specific person). So in this threat model, either way, we also need to look into whether Signal successfully overwrites the content and metadata of the messages it deletes on the mobile device storage, because the government attacker would use forensic tools to try to undelete that data. I don't know the answer to that.
- ghthor 6y agoSSD storage makes it pretty much impossible to overwrite data on the disk from the OS. Because writing is all handled internally and is copy on write you cant just write to disk sectors. The internal firmware will route the write to different parts of the disk.
- schoen 6y agoI've been aware of that in the past, but it slipped my mind when I was asking this question. (So thanks.) Has anyone investigated the wear leveling of mobile device storage to see how bad/tractable this situation is at the moment?
- albntomat0 6y agoAuto-deleting messages by default seems like a clear violation of "the principle of least astonishment/surprise," with no clear way of designing around it. My personal view is that such a tradeoff comes down to the threat model of the individual user, and they should not be surprised by auto-deleting messages by default.
- lmm 6y agoFor an email-like system you expect to keep all messages forever. For a messenger-like system it's not particularly surprising if your messages expire after a fairly long period (e.g. 30 days or 180 days), IMO. E.g. I genuinely don't know (or care) whether my WhatsApp history is available or not past a month or two back.
- godelski 6y agoI mean a lot of us grew up when you could only save 500 text messages. AIM didn't originally preserve things either. I'm seriously curious why people want to save everything. It seems odd to me, and honestly a bit creepy. But maybe there is a use case I don't understand.
- deleted 6y ago[deleted]
- JoshTriplett 6y agoPeople suggest, often, that Signal is the usable successor to encrypted email. If it loses data by default, it isn't a viable replacement.
- thaumasiotes 6y ago> The user has to somehow know that they have to do this to get the benefit of forward secrecy. I mean, this is basically true of every feature in every product.
- tmp538394722 6y agoYes, it’s good to periodically delete your old content, but calling it “useless” is a stretch. Consider the context in which Signal came of age - post Snowden mass surveillance. Signal has always prioritized fighting mass surveillance. Getting individual devices hacked to recover its content is already outside of what I’d consider “mass surveillance”. That is, even if you don’t use disappearing messages, you’re much less likely to have your conversations slurped up into some PRISM aggregator type machine by using an e2e communication channel like Signal, in part due to its forward secrecy capabilities. That said - no harm in fighting targeted surveillance as well. Wether it be from a 3 letter agency, a phone thief, or an overzealous personal relationship.
- humbleMouse 6y agoI don’t understand why people use signal over wickr. Signal accounts are tied to an actual phone number, which is a public identifier. Wickr accounts are tied to nothing. And if you loose your phone you can just login again on any other phone to continue communicating.
- tptacek 6y agoIf you can lose a phone, get a new phone, log in again, and retain your contact list, you should think carefully about the metadata your messenger is keeping about you.
- humbleMouse 6y agoI’d rather it keep some metadata than have a login tied to my actual phone number.
- tptacek 6y agoYou shouldn't be so sanguine about that, because the metadata is often 80% of what your adversaries are looking for, especially if your adversaries are government-backed.
- ViViDboarder 6y agoDepends on your goal. Do you care about people knowing you’re on Signal? Or do you want to keep who you’re messaging private? Signal has features make it so that even if someone knows you’re using Signal, if you use sealed sender, they won’t know who you’re messaging with. For me, I’d rather an account tied to me for discovery, but to keep plain text metadata off their servers. That said, Signal plans to release non-phone identifiers, which I’m sure many are eagerly awaiting. I’m looking forward to it too, actually so I can use it to have my server message me instead of via Slack.
- haloboy777 6y agoEnd to end encryption is not beneficial to any big tech other than some marketing. Then why are they implementing it? Has anyone figured out any reason behind it?
- eganist 6y agoMarketing. Sometimes it matters. Also, it doesn't always have to be some malicious thing. Could just be that there's a visionary executive with altruistic intents who convinced a higher-up that it's the right move. But in the case of Signal, remember that it's a nonprofit. And in the case of whatsapp, it's looking more and more like the case above.
- tgsovlerkhgsel 6y agoDoesn't even have to be a visionary executive. This is one of the decisions where a senior engineer writing the design doc one way or the other can easily make the difference in how the final product looks like. Also, besides marketing, reduced compliance costs. Once police etc. realize that you can't provide useful data, they stop asking.
- shaftway 6y agoWhen the Snowden leaks came out it was a surprise to Google that the government had tapped the data center to data center connections, as these were private and not thought to be tapped. Eventually all traffic between data centers was encrypted to prevent eavesdropping. Internally there was a lot of animosity towards the three letter agencies for tapping our lines, so part of the rational was sticking it to them. Also, once you hire a security engineer for one thing they tend to be pretty vocal about other security issues. They can often stir up enough trouble that it's easier just to add the extra encryption. Adding this encryption to Google's messenger was probably a couple person-years of effort. So, like, 0.00001% of the budget?
- jMyles 6y ago> When the Snowden leaks came out it was a surprise to Google that the government had tapped the data center to data center connections I guess I haven't been keeping up, but I did not know this. Can you point me to a short documentary or document where I can learn more about what Google says it didn't know?
- baby 6y agoFor anyone curious, I spent a lot of time describing the protocol in intuitive ways[2] in the book Real-World Cryptography[1]. Having spent a lot of time reviewing Signal and secure messaging applications as part of my job, I wanted to be able to explain how the protocol worked in the most educative way possible. feedback is welcomed :D [1]: https://www.manning.com/books/real-world-cryptography?a_aid=Realworldcrypto&a_bid=ad500e09 https://www.manning.com/books/real-world-cryptography?a_aid=... [2]: https://livebook.manning.com/book/real-world-cryptography/chapter-10/v-10/ https://livebook.manning.com/book/real-world-cryptography/ch...
- schoen 6y agoYour book looks really cool! It says it's officially coming out in the spring?
- dessant 6y agoHi! Some of my peers have enabled Signal PINs when the feature was introduced, and they have used weak PIN codes that they could remember on the spot, because intially the app would not let them view their messages until the Signal PIN was configured, which was later fixed in an app update. What is the real-world impact of a weak Signal PIN code? Can a compromised Intel SGX process or the Signal server intercept our messages, if the PIN code is known?
- tptacek 6y ago
- adrianpike 6y agoOther than the UX for trust on first use, are there other things that make Signal's protocol better than OpenPGP?
- captn3m0 6y agoYour permanent key in PGP can be used to decrypt any intercepted communications down the line? Key compromise has drastic consequences in a sense?
- rpdillon 6y agoUsability and perfect forward secrecy. Usability is observable empirically: I was able to easily onboard everyone I text with to Signal, but getting them to use PGP has been completely intractable for years, even with tools like mailvelope.
- blueplanet200 6y agoWell, people tend to actually use it in real life. edit: Signal protocol also has message deniability, future and forward secrecy. OpenPGP lacks these properties.
- tptacek 6y agoThey're barely even comparable. Signal Protocol has: * A "double ratcheting" forward secrecy system, where message round-trips establish new DH keys, and message transmissions establish new symmetric keys. * An authenticated key exchange --- "Triple Diffie Hellman" --- that provides deniability without having to publish spent keys, and works without needing a signature algorithm. * A cryptosystem locked exclusively into modern misuse-resistant curves and AEAD cryptography. By contrast, OpenPGP: * Provides no forward secrecy (applications built on OpenPGP have to invent their own forward secrecy designs, which in practice nobody does). * Relies on long-term keys. * Uses a hodgepodge of algorithms, including outmoded cryptography from the 1990s; moreover, the compatible subset of PGP implementations depends on its nightmarish "MDC" hack, which was an attempt to retrofit message authentication into the standard. Some of PGP's problems are due to the fact that Signal was designed at a time when we had far better understanding of cryptography, and, frankly, designed by better subject matter experts. But more of the problems are simply due to the fact that PGP isn't purpose-built for messaging; it's a general-purpose encryption tool, the "Awk" of cryptography, and one thing we're rapidly forming a consensus on is that you don't want Awk-like tools in cryptography engineering.
- tmp538394722 6y agoThe buried lead is that RCS’s encryption will be based on Signal protocol. That seems huge! I wonder if iMessage will feel compelled to up their game. They were early to the e2e game, for which they have my respect (they had their issues, I know), but will they put work into evolving their system? Or will they be happy being “second best” for default messaging privacy capabilities when privacy is so intricate to their marketing?
- bjoli 6y agoI have been thinking the same thing since the news dropped. Apple has a pretty solid reputation for protecting iPhone users. Will they add RCS support to iMessage, even if it means protecting a competitor's users as well? Anyway. This means moxie actually did a large part of what he set out to do. 2 billion users will use the signal protocol by default. No extra app install necessary. I have probably been the loudest "federate signal" whiner out there, but I feel rather stupid now.
- tmp538394722 6y agoIsn’t “_perfect_” forward secrecy a misnomer in this context? One of the big innovations of the signal protocol, (called axolotl at the time) was that perfect forward secrecy, requires a handshake between participants before _each_ message, which is not compatible with the nature of async messaging, where the recipient might be (probably is) offline at the time of sending. Instead Signal protocol does an eventual key ratcheting as soon as messages are round tripped between participants by essentially attaching half a handshake to each outgoing message.
- unhammer 6y agoThis is still just for the transport, right? I'm guessing messages are still synced to Google's servers, otherwise what happens when you drop your phone in your cereal, are they gone forever? (Or does Google have magical unbreakable SGX'es storing your messages?)