4 ms·
Jack Dorsey out, plaintext DMs in. Slow clap for Bluesky.
by facialwipe 2y ago
Jack Dorsey out, plaintext DMs in.
Slow clap for Bluesky.
- evbogue 2y agoMy offer still stands to help the Bluesky folks implement these types of things if they can't figure it out. Call me!
- KerrAvon 2y agoI don’t think they want a plan to get Dorsey back — he seems to be an idiot.
- Kye 2y agoFrom discussions with security professional friends and folks on E2E encryption of protocols: I don't think it's that they can't figure it out, it's that they know it's hard to get right and harder to fix later, so they're taking their time to do it right in the first place. They don't want to end up like Telegram or Matrix with furries doing unflattering writeups on their security.
- evbogue 2y agoI agree that the furry interpretation of privacy is intimidating, but at the very least I think Bluesky could start with generating a private key on each client device, and then using a simple box algorithm to encrypt messages towards the user they want to talk to. The PDS could store these messages encrypted, so the PDS owner cannot read the messages. I don't think https://tweetnacl.cr.yp.to/ https://tweetnacl.cr.yp.to/ is hard to mess up. Similar to the interior of a furry suit, you won't know what is going on in there.
- some_furry 2y ago> but at the very least I think Bluesky could start with generating a private key on each client device, and then using a simple box algorithm to encrypt messages towards the user they want to talk to. Furry cryptography nerd here. No. This is inadequate. > I don't think https://tweetnacl.cr.yp.to/ https://tweetnacl.cr.yp.to/ is hard to mess up. Yes it is! If you're doing to encrypt some things in a constrained use-case, sure, NaCl is better than hand-rolling it yourself. But it's not sufficient for end-to-end encryption. Here's a few things that TweetNaCl (and other NaCl variants) is, without further protocol design, inadequate to protect against: 1. Invisible Salamanders. NaCl uses xsalsa20poly1305, which is not key-committing. 2. Forward Secrecy. NaCl's crypto_box doesn't give you this at all. 3. Key Compromise Impersonation. See also, Toxcore, which built atop NaCl: https://github.com/TokTok/c-toxcore/issues/426 https://github.com/TokTok/c-toxcore/issues/426 4. How do you do group messaging? If you do it as just pairwise, do you use the same public key as your p2p messaging? There's a lot of ways that can subtly go wrong. There is a damn reason end-to-end encryption involves authenticated key exchanges and forward-secure double ratchets.
- evbogue 2y agoWell, exactly. My point is that in a constrained use-case NaCl would be sufficient. If you want to rotate keys, then simply delete your private key and since we trust Bluesky so much we can use the PDS to share new pubkeys once we rotate. In fact, this would work for signing keys too! Then the PDS wouldn't be able to write messages for you if it wanted to. For group messaging you simply encrypt the message to each recipient. If they want to upgrade to a Axolotl from this, great! But starting with plain text is not private messaging, it is group messaging with your PDS admins and whoever they want to share that data with.
- some_furry 2y agoI literally wrote an X3DH implementation atop libsodium once https://github.com/soatok/rawr-x3dh https://github.com/soatok/rawr-x3dh I'm telling you, TweetNaCl is not enough to build a secure messenger libsodium, maybe
- evbogue 2y agoI agree there are more layers you can add on top of TweetNaCl to improve security. I'm going to personally add you to the list of people Bluesky should hire to get this implemented without the consent of the Bluesky employees. If they choose to hire both of us perhaps we can figure out how to implement this for them. I will not commit to putting on a furry suit. But I've been known to try everything once. And bonus I live right next to the furry convention center and have always wondered what the heck is going on at the Hyatt while you guys are here.