5 ms·
"And second, the numbers themselves aren’t stored there in plain text, but rather in the form of a hash code." Very strange. There is no additional security by
by AtNightWeCode 4y ago
"And second, the numbers themselves aren’t stored there in plain text, but rather in the form of a hash code."
Very strange. There is no additional security by hashing phone numbers. Not that I trust anything form this source but anyway.
- permo-w 4y agoit seems like there very obviously is additional security in that
- dotancohen 4y agoNot at all. The numeral-only search space is too small, the rainbow table fits on an inexpensive thumb drive.
- permo-w 4y agoit’s still useful if you use a private hashing algorithm
- AtNightWeCode 4y ago> However the data is stored, first, in special storages called secure enclaves, which even Signal developers can’t access. And second, the numbers themselves aren’t stored there in plain text, but rather in the form of a hash code. I was out of context. You can use salt, pepper or both but if these attacks are done buy Signal developers it would most likely be easy to crack the hashes. In the case of a data leak it can help depending on how difficult it is to figure out how the hashing works.
- palata 4y agoWrong. That's exactly the point of the secure enclave.
- AtNightWeCode 4y agoExplain. It is generally not possible to use hashing securely on finite sets like phone numbers.
- palata 4y agoThe secure enclave guarantees cryptographically that you are running the code you say you are running. That code (private contact discovery) is open source and authenticated by your client using remote attestation. It's not just a hash, it's an SGX enclave.
- palata 4y agoThe Signal server knows your phone number. Not your contact list, just your phone number (hashed or not, I don't really care). Your contact list is only ever shared with the secure enclave, which cryptographically ensures that nobody else can read it, and the code being run in the enclave is open source and authenticated (so you can verify that the enclave is not sending your contact list to the Signal developers). If you trust the secure enclave, then your contact list is not shared with the server.
- orangepurple 4y agohttps://arstechnica.com/information-technology/2022/08/architectural-bug-in-some-intel-cpus-is-more-bad-news-for-sgx-users/ https://arstechnica.com/information-technology/2022/08/archi... Actually secure enclaves exist?!
- palata 4y agoDo actually secure smartphones exist? Ever heard of Pegasus?
- orangepurple 4y agoPinephone because nobody has targeted it yet! (lol)