5 ms·
"..trusting the server to deliver your messages to the right client." This is where I feel a little unsure about Signal. It wants access to my contacts, and so
by FourthProtocol 6y ago
"..trusting the server to deliver your messages to the right client."
This is where I feel a little unsure about Signal. It wants access to my contacts, and so it is possible to poison my contacts to get a rogue recipient into Signal. I would like a Signal in which I have the option to manually add contacts. Ideally a hash or key exchange or something, maybe a la PGP...
- tptacek 6y agoPGP has one of the worst metadata stories in all of secure messaging.
- FourthProtocol 5y agoTrue but not quite my point.
- grep_name 5y agoCan you elaborate what you mean by this?
- FourthProtocol 5y agoHe means that key exchange is frought with trust issues online. An exchange in meat-space is (can be!) 100% reliable, but doesn't scale. PGP is a posterchild for the impracticality of public key crypto. The UK actually made it work in conjunction with identity federation through the Government Gateway, but then the Government Digital Service got hold of it and destroyed any chances of moving it forward. Having seen it work I believe PKI can be practical at scale. And this is why I'd hoped a chat app might break some ground here.
- tptacek 5y agoNo, this is not at all what I mean.
- FourthProtocol 5y agoThen pray tell good sir.
- tptacek 5y agoMetadata problems in messaging systems are about what data about the communication leaks.
- FourthProtocol 5y agoSorry, I suspect I'm missing something obvious. You specifically said PGP, which is an encryption program that provides cryptographic privacy and authentication for data communication. And above you're saying it's about meta data problems in messaging systems. What is PGP's bad meta data story you were referring to?
- tptacek 5y agoWe're into the weeds here on this thread but the search bar below will avail.
- akerl_ 5y agoA quick entry point might be found here: https://crypto.stackexchange.com/questions/42247/are-the-metadata-encrypted-by-pgp https://crypto.stackexchange.com/questions/42247/are-the-met... Essentially, for most PGP workflows, PGP encrypts the body of the message but the entirety of the metadata (things like sender, recipient, subject line, basically anything you’d think of as “metadata”) are fully unencrypted.
- FourthProtocol 5y agoThis is not a problem with PGP. This is a problem with an application of PGP.
- IncRnd 5y ago> Having seen it work I believe PKI can be practical at scale. And this is why I'd hoped a chat app might break some ground here. If you believe that this webpage was delivered securely to your computer, then PKI might be practical. Of course, there are a few implementation details with that PKI.