7 ms·
It's easier to understand this if you look at the onion protocol. Broadly, it introduces noise between all users on the network by constantly sending and receiv
by ayx 3y ago
It's easier to understand this if you look at the onion protocol. Broadly, it introduces noise between all users on the network by constantly sending and receiving random bytes to and from each node. This prevents external listeners from figuring out where the main server is. Originally designed to protect naval command ships, it was later used for the "dark web". If you don't know which node is the server, you can't shut it down, or read data off of it.
Simplex does something similar. A connects to B. B connects to C. And A and C connect. They all chat. but there is no way to know A, B, or C, because from the outside, it all looks like: X connects to Y, X connects to Y, X connects to Y. So who spoke to whom?
This is great. Even if "the authorities" demand access to chat logs, first, they won't know what to ask for. Chats between whom? Second, they still won't know who spoke to whom even if they have all the data. It's anonymized chats. They would have to sift through all of it.
It still won't prevent someone invading privacy if they have physical access to your device, since the identities are stored locally for your usage convenience.
- throwaway290 3y ago> It still won't prevent someone invading privacy if they have physical access to your device, since the identities are stored locally for your usage convenience. does it mean if a lot of Simplex users band together and sift through all their local identities they can connect the dots?
- ajani 3y agoLet's say the whole network is just 4 nodes. A, B, C, D. And A and B are connected. And C and D are connected. And I have physical access to all 4 devices. In phone A, you will have B's contact stored locally, let's say as "Dan". B, A, "Pedro" C, D, "Dan" (yes D is also named "Dan") D, C, "Olga" What do you look for?
- tyingq 3y agoIt's a little hard to grok the details, but it sounds like it's a collection of "dead drops". Like, if done in a physical way, imagine locations around a city where you can drop off scraps of paper with cipher encoded message on them. Encoded not just with sender/recipient keys, but a dead drop location specific key too. And an agreement that replies to a received message get dropped off at a different, randomly selected one. Everyone can see and read the cipher text on all the papers, but each of the 4 people can only decode the things meant for them. So, if that's how it works, you could certainly learn who was talking to who if you had access to all the devices. But access to one device only shows you what came and went to the device, but no data about which of the other three users were involved in those reads/writes. You would have to gain access to each device, in turn, to prove whether it was in contact with the first device.
- epoberezkin 3y agoThat's right. With the difference that you drop at one address, and another address has to be used for the pickup. Disclaimer: I'm the founder.
- deleted 3y ago[deleted]
- throwaway290 3y ago> But access to one device only I specifically said a lot of users. A lot is the opposite of one. Imagine a lot (>40% of total users) of impostor devices acting in accord to deanonymize some of the X and Y. Is it vulnerable to that. Like apparently Tor is.
- ajani 3y agoNo. It wouldn’t be vulnerable to that. You would at most be able to deanonymize a certain percentage within the impostor network itself. Kind of pointless. Physical access of devices is the only way to have some chance of deanonymizing some of the users (always less than number of devices you have access to). That’s my understanding, but the maker of this thing is here, and maybe can respond better?
- deleted 3y ago[deleted]
- account-5 3y agoThanks this made it clear for me how it works, and with the confirmation of the founder I'm happy I can understand it.
- deleted 3y ago[deleted]
- OJFord 3y agoThey really bury the detail IMO after the banner claim front and centre on the website (I guess because it's hard/awkward to explain without it sounding just like a difference in nomenclature). What makes it work afaict is the combination of: - there are still queue (inbox) IDs - key (and (just initial?) queue ID) exchange out of band https://github.com/simplex-chat/simplexmq/blob/stable/protocol/overview-tjr.md#simplex-messaging-protocol https://github.com/simplex-chat/simplexmq/blob/stable/protoc... So messages are still delivered to an identifier, it's just that every user has tonnes of identifiers (per contact/group), there's no server tracking and handling their exchange, and possibly they rotate via encrypted messages once established anyway. Exchanging out of band gets you the secrecy, and having one per-chat protects you from a contact turning out bad/leaking/compromised - it's fine that they have metadata about their own chat with you, because they have that & the plaintext anyway.
- ajani 3y agoYou are missing a crucial aspect of this. There is no identifier. Only a connection. An identifier is something that relates to more than one thing. A connection is its two endpoints. It is those ends. Who is at each end is unknown and cannot be known without resorting to grabbing all users devices.
- largbae 3y agoThat isn't what GP is saying. In order to effectively use the chat, you are going to tag that connection identifier with a name like Joe on your endpoint device, so that when a message comes in you remember this was the conversation with Joe. The server may not know that this is you and Joe, but you do.
- account-5 3y agoYeah, that was my take. The issue with end to end encryption is the ends. The ends are the weak link. I think though that simplex may be the best option in this regard though. The user has to know who they are speaking with, but here the user can choose not to tag the connection, and therefore take on the mental load of remembering which connection identifier referred to which person. Having not used this chat I don't know how easy thing might be but I do remember, before mobile phones were a thing, being able to remember at least 8 phone numbers that I used to call regularly. Certainly if it called for it you could do this with simplex?
- yamrzou 3y agoReminds me of Vuvuzela, a private messaging system that hides metadata. Discussed here: https://news.ycombinator.com/item?id=10668494 https://news.ycombinator.com/item?id=10668494 (2015)
- rowyourboat 3y agoThe solution to this is of course to simply outlaw the use of communication systems that cannot be monitored by law enforcement. India has it, the EU is working on it, and I'm sure the US will do something like that as well.
- FrenchDevRemote 3y agosolution to what exactly? to help hackers hack companies more efficiently?
- rowyourboat 3y agoTo being able to surveil a country's citizens. These super-anonymous communication technologies are touted time and again to solve the problem of a surveillance state, while they do nothing of the sort. You cannot solve a social problem with technology.
- tambourine_man 3y agoYou think being able to surveil a country's citizens is a feature?
- samtho 3y agoThe point that was trying to be made was that it doesn’t matter how secure and unbeatable something is if a sovereign state wishes to simply criminalize its use. It can then utilize its full power to enact violence upon any S̵u̵b̵j̵e̵c̵t̵ citizen, who is caught using it.
- tambourine_man 3y agoThanks for clearing that up. But if a tool can be devised that no trace of its use can be found, there’s nothing such state can charge you of. This tool clearly wants to be a step in that direction.
- 3y ago