3 ms·
I don't know much about security. I'm asking from a purely theoretical perspective, so you could imagine a worst case scenario - for example, Alice wants to us
by cardosof 5y ago
I don't know much about security. I'm asking from a purely theoretical perspective, so you could imagine a worst case scenario - for example, Alice wants to use her phone to securely chat with Bob about resisting the dictatorship they're living in or something like that. Or they need to trade industry secrets that are in their phones.
- junon 5y agoSo disclaiming this with the warning that I haven't really kept myself too up to date the last year or two with the latest in private communications so please correct me if I'm wrong or outdated about any of this. Also remember that privacy and security are never a silver bullet, and anyone claiming that something is, is probably not being genuine about their intentions. Privacy and security are about making things harder, not impossible - how difficult is entirely based on what you're trying to protect, and from who or whom you're trying to protect it. There are no perfect systems or completely safe platforms/locations/etc. Right, with that out of the way. In this case, tapping is less of a concern with anything E2EE encrypted and using proper cryptography suites - which is usually a given these days with most privacy-focused applications. Signal, Matrix, and Briar come to mind. But "censorship resistance" being the key term here, means that the infrastructure used to actually send the messages cannot be tampered with or otherwise taken offline. You want to make sure that automatic updates can't be pushed to the app by a third party. App signing helps but making sure that automatic updates are off and that you update frequently enough and ensuring that each release is properly released by the author is important. There are other modes where this still isn't bulletproof (system OTA update with a backdoor, app author is compromised, etc.) but these are typically not within your model. Open source projects tend to be the defacto if you really care about good intentions since it allows everyone (including you, but more importantly, independent auditors and people who are experts at looking at this stuff) to look at the code and assess that it works as described. Telegram is not censorship resistant[0], and while it's E2EE in secret chats, it's not E2EE by default. This is a common misconception by a lot of people. Signal by design isn't censorship resistant but they do a lot of work to make it effectively so (e.g. [1]) - when they're not fighting amongst themselves[2]. Signal is also quite aggressive when it comes to antiestablishment sentiments historically, which depending on where you are can work against you or be in conflict with your goals[3]. Matrix is a decent enough protocol at a higher level, though admittedly I'm not super acquainted with its internals. I do use it quite a bit, however, and generally like it, but it's very unapproachable to all but the savvier tech enthusiasts, and has a pretty young ecosystem when it comes to clients, phones, etc. It's also wildly underused compared to other platforms. I myself am a long time IRC user and get very confused with Matrix at times. Finally there's Briar[4], which I've not used but it was mentioned not too long ago here on HN. It can use other means of communication on phones to send messages securely. As always, Tor can be a great way to obfuscate your internet usage and in some cases even bypass state-enacted blockages of certain sites, but it's not foolproof and can actually make things worse[5] if you don't understand how it works and when not to use it. Make sure to research first. By the way, threat modeling[6] can be fun and is applicable to a lot of situations, including your own personal safety. The five functions[7] are a fun place to start. Read up on it if you want! Hope this is a decent enough overview! [0] https://en.wikipedia.org/wiki/Government_censorship_of_Telegram_Messenger https://en.wikipedia.org/wiki/Government_censorship_of_Teleg... [1] https://reclaimthenet.org/signal-offers-workarounds-for-iranian-users-blocked-from-using-the-app/ https://reclaimthenet.org/signal-offers-workarounds-for-iran... [2] https://github.com/net4people/bbs/issues/63 https://github.com/net4people/bbs/issues/63 [3] https://cyberlaw.stanford.edu/blog/2021/05/i-have-lot-say-about-signal%E2%80%99s-cellebrite-hack https://cyberlaw.stanford.edu/blog/2021/05/i-have-lot-say-ab... [4] https://briarproject.org/how-it-works/ https://briarproject.org/how-it-works/ [5] https://support.torproject.org/faq/staying-anonymous/ https://support.torproject.org/faq/staying-anonymous/ [6] https://en.wikipedia.org/wiki/Threat_model https://en.wikipedia.org/wiki/Threat_model [7] https://www.nist.gov/cyberframework/online-learning/five-functions https://www.nist.gov/cyberframework/online-learning/five-fun...