5 ms·
On the contrary, they started out with phone numbers so that they could avoid storing user data on their servers. The whole plan to finally have usernames come
by sa1 5y ago
On the contrary, they started out with phone numbers so that they could avoid storing user data on their servers.
The whole plan to finally have usernames comes down to their use of Intel SGX.
- colordrops 5y agoWhat does being tied to a phone number have to do with avoiding storing data on their servers or SGX?
- sa1 5y agoWith a phone number, the contact graph can be on the phone. With usernames, the contact graph has to be stored on their servers. They were forced to store (encrypted) information on servers anyway, since client-side contact matching didn't end up scaling, which is why stuff like this and usernames are now being developed. Their new security strategy now relies on decryption being done by client-attested code on SGX enclaves, so that the server still doesn't have access to the plain-text contact graph. All of this took a huge amount of time to come up with, and you can see the progress if you read their blogs or forums.
- colordrops 5y ago> With usernames, the contact graph has to be stored on their servers. Are you suggesting that there isn't a contact graph on their servers? How exactly do they route from one user to another? It's certainly not P2P. If you are suggesting that we should trust them just because it could work without them storing who I've contacted, you are mistaken. The whole point of private messaging is to obviate the need for trust. The code should be auditable/open source, and everything on the server should be either transparent, or assumed to be compromised. They certainly do send your contact graph to their servers, and whether they say they discard it or not is irrelevant. In the context of privacy, you must assume your data is persisted once it is behind a curtain you have no visibility into.
- sa1 5y agoThey only started sending your contact graph after adopting SGX. Before that the matching used to happen client side through a bloom filter. They can theoretically rebuild a contact graph by finding everyone you’re talking to, but that’s a small subset of the contact graph created by contact matching. The code is open source and SGX literally means that the client attests that the code on the server matches what it’s expecting. Signal might be the most audited stuff out there.
- colordrops 5y agoI trust bloom filters more than SGX. I assume they stopped using bloom filters because of performance or reliability reasons? Also, aren't most mobile processors not Intel? How would SGX be used?
- sa1 5y agoHere you go: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/
- colordrops 5y agoThanks for being patient and providing links. How do we know the closed source version of signal on the app stores is using the same MRENCLAVE as the one from the open source server? Also, my understanding as to why a contact graph is needed at all is because signal wants to increase their virality. Couldn't we forgo this unnecessary feature? Signal could generate a long enough key locally, and if you want to add another signal user, the client could send it automatically to a contact through SMS. The client on the other side could automatically read the key through SMS and add the contact. Or the user could manually send the key through any mechanism they wanted. A third note, trusting SGX assumes that 1. it has no bugs, and 2. it has no backdoors, 3. Signal server code has no bugs, 4. Signal server code has no backdoors. The first two of these are not strong guarantees, especially considering that it's not open source, intel doesn't have a great track record, and nation state actors have been involved in weakening these sorts of features in the past. At least with the Signal server code you can audit it.