14 ms·
Signal Protocol and Post-Quantum Ratchets
- bilal4hmed 1y agoIm feeling pretty dumb even after reading the tldr. Can anyone who is well versed in this explain how this is better or safer? I read about the time, will it now be slower to send messages?
- jerknextdoor 1y agoFrom the article: > "What does this mean for you as a Signal user? First, when it comes to your experience using the app, nothing changes. Second, because of how we’re rolling this out and mixing it in with our existing encryption, eventually all of your conversations will move to this new protocol without you needing to take any action. Third, and most importantly, this protects your communications both now and in the event that cryptographically relevant quantum computers eventually become a reality, and it allows us to maintain our existing security guarantees of forward secrecy and post-compromise security as we proactively prepare for that new world."
- upofadown 1y agoTheir existing post quantum encryption didn't do post compromise security (PCS) against quantum attackers. This new one does. I am excited to finally know what they mean by PCS after reading this article. It means that the session keys from their key agreement scheme (n ratchet) are generated new so an attacker doesn't get them again after a fairly specific sort of compromise. So from that I get that the off the record (OTR) protocol also has PCS. Which is a bit disappointing, I thought that they had come up with some new concept. This key agreement doesn't happen that often. So a user isn't going to notice any slowness even if it was significantly slower.
- bilal4hmed 1y agothank you for the explanation
- tptacek 1y agoSure. In the standard practical analysis of quantum threats to cryptography, your adversary is "harvesting and then decrypting". Everybody agrees that no adversary can perform quantum cryptography today, but we agree (to agree) that they'll plausibly be able to at some point in the future. If you assume Signal is carrying messages that have to be kept secret many years into the future, you have to assume your adversary is just stockpiling Signal ciphertexts in a warehouse somewhere waiting so that 15 or 20 years from now they can decrypt them. That's why you want PQ key agreement today: to protect against a future capability targeting a record of the past. (It's also why you don't care as much about PQ signatures, because we agree no adversary can time travel back and MITM, say, a TLS signature verification). To understand the importance of a PQ ratchet, add one more capability to the adversary. In addition to holding on to ciphertexts for 15-20 years, assume they will eventually compromise a device, or find an implementation-specific flaw in cryptography code that they can exploit to extract key material. This is a very realistic threat model; in fact, it's of much more practical importance than the collapse of an entire cryptographic primitive. You defend against that threat model with "forward secrecy" and "post-compromise security". You continually update your key, so the compromise of any one key doesn't allow an attacker to retrospectively decrypt, or to encrypt future messages. For those defenses to hold against a "harvest and decrypt" attacker, the "ratchet" mechanism you use to keep re-keying your session also needs to be PQ secure. If it isn't, attackers will target the ratchet instead of the messages, and your system will lose its forward and post-compromise secrecy.
- ls612 1y agoWhat is the state of PQ symmetric crypto? My layman's understanding is that 128 bit AES is known to be broken by a quantum computer and that 256 AES may be OK but that isn't certain? Is this an additional vector for the "harvest and wait" strategy in the future?
- twiggers 1y ago128-bit AES is fine. To run Grover’s algorithm against it you’d need to cover the moon with qubits.
- twiggers 1y ago[dead]
- briandw 1y agoI can't believe that they named their protocol SPQR. It's the Latin abbreviation for Senatus Populusque Romanus. https://en.wikipedia.org/wiki/SPQR https://en.wikipedia.org/wiki/SPQR Love it :)
- saurik 1y agoOr, maybe, it just sounds like "speaker", because they are a chat app? ;P... not everything has to be framed as a Roman conspiracy.
- drdaeman 1y agoIt’s not a conspiracy, it’s a pop culture reference. Very unlikely it’s unintentional, given that Thinking About Roman Empire was a fairly notable meme of ‘23/‘24 (https://knowyourmeme.com/memes/how-often-do-you-think-about-the-roman-empire https://knowyourmeme.com/memes/how-often-do-you-think-about-...). Could be not a primary cause for the naming - only authors can tell - but I doubt they missed the reference entirely. It’s just way too obvious.
- dmesg 1y agoCaesar cipher anyone? Romans knew (bad) cryptography.
- saurik 1y agoI am struggling to believe that the Roman Empire reference for this acronym is "so obvious". I do know about the meme: in fact, what struck me so hard about this is how, for a protocol where you'd almost expect it to be hard for them to avoid the acronym "SPQR" (as, even if it were not Sparse, it is made by Signal; I could even see them having started with Signal and decided to remove their brand from the acronym), there are not one but two top-level posts on Hacker News where "speaker" seems to have wooshed over their head and somehow this extremely niche acronym from the Roman Empire is clearly the reason why this is called SPQR. Is the tech community on Hacker News really this stereotypical?
- 1y ago
- darwinwhy 1y agoSparse Post-Quantum Ratchet, or SPQR. Someone at Signal is a Roman history enjoyer.
- saurik 1y agoOr, just maybe, they are merely an enjoyer of chat apps (SPQR -> "speaker").
- lo_zamoyski 1y agoHow often do you think about the Roman Empire?
- throw0101d 1y agoNot very. But the Roman Republic…
- ziofill 1y agoOr Asterix
- untrimmed 1y agoDoes this mean we're any closer to getting editable messages?
- Trasmatta 1y agoSignal already has editable messages
- stavros 1y agoWe're about minus five months away.
- Night_Thastus 1y agoI remember editing messages a couple of years ago. Am I missing something?
- longitudinal93 1y ago10 edits in 24 hours. Been that way for ages.
- WolfeReader 1y agoUpdate your app please
- ihm 1y agoThis is really impressive, especially the way they've used formal verification. Great work.
- lyu07282 1y agoIts interesting to imagine that somebody [1] is already now capturing encrypted internet traffic and storing it all long-term, to then hypothetically in 40-50 years or something decrypt it and draw value from that information. I suppose to blackmail future politicians, learn military secrets, whatever. [1] NSA
- palmotea 1y ago> Its interesting to imagine that somebody [1] is already now capturing encrypted internet traffic and storing it all long-term, to then hypothetically in 40-50 years or something decrypt it and draw value from that information. I suppose to blackmail future politicians, learn military secrets, whatever. You don't have to imagine, there's literally a NSA datacenter in Utah for doing just that. https://en.wikipedia.org/wiki/Utah_Data_Center https://en.wikipedia.org/wiki/Utah_Data_Center
- lyu07282 1y agoThat's exactly what I was thinking about too, but I was to lazy to find the link, thanks ;)
- N19PEDL2 1y ago> to blackmail future politicians This seems to me the most valid reason. Any other secret is useless after 30 years.
- skybrian 1y agoIt's hard to tell as someone not in the field, but quantum computing seems to be moving faster than that? I'm not sure I believe two years, but: Harvard physicists working to develop game-changing tech demonstrate 3,000 quantum-bit system capable of continuous operation https://news.harvard.edu/gazette/story/2025/09/clearing-significant-hurdle-to-quantum-computing/ https://news.harvard.edu/gazette/story/2025/09/clearing-sign... PsiQuantum Raises $1 Billion, Says Its Computer Will Be Ready in Two Years https://archive.is/AEuan https://archive.is/AEuan
- 1y ago
- catapart 1y agoFantastic news! Awesome that the Signal team was able to deliver another first-class security feature.
- devmor 1y agoWow, this is one of the most well written cryptography articles I've ever seen. I consider myself a fairly experienced software engineer with a moderate amount of professional experience in private sector encryption, so I'm not completely out of my element, but many articles along this vein have my eyes glazing over halfway through the breakdown. This one was actually easy for me to follow the entire time for once, despite explaining something I'm not familiar with.
- elvisloops 1y agoStrange that they are posting about the "signal ratchet" when they just removed it by launching cloud backups that use a static key? Since those cloud backups include disappearing messages, that feature completely undoes all of the forward secrecy in this protocol.
- uv-depression 1y agoThat backup system presumably uses symmetric encryption, which is not nearly as vulnerable to quantum-accelerated attacks.
- elvisloops 1y agoYes, but you don't need a complicated ratcheting protocol if you've eliminated forward secrecy in other ways. This post is about "post compromise security," but there is already no post-compromise security after the cloud backups feature
- gruez 1y ago>but there is already no post-compromise security after the cloud backups feature The feature is opt in, so I really don't see the issue here.
- uv-depression 1y agoDo you also think it's "strange" that they're introducing that (optional!) feature while also storing all the messages on your device? The cloud backup is strictly more secure than that on-device database. Their blog post on the subject also explicitly says it won't include disappearing messages that disappear within 24 hours.
- elvisloops 1y agoIt's not optional because you don't know whether the people you are communicating with have it enabled. One person in a group chat with the feature enabled undoes the forward secrecy for everyone in the group chat. A cloud backup eliminates any forward secrecy. It used to be that in Signal, when you have a message on your device and it is deleted (or a disappearing message disappears), then it is truly gone and can never be recovered. Now with backups, since the key that was used to encrypt it to the cloud remains on your device, it can be recovered even after the message is deleted or disappears. The only way to "truly" opt-out is to, as you say, set a disappearing message timer for <24 hours.
- ysnp 1y agoCan anyone comment on where this puts Signal now in relation to iMessage with PQ3[1]? As an aside, can anyone comment on earlier (fast/rushed/sound?) attempts at quantum-resistant encrypted messaging in Cyph[2] and Simplex[3] in comparison? [1] https://security.apple.com/blog/imessage-pq3/ https://security.apple.com/blog/imessage-pq3/ [2] https://www.cyph.com/castle https://www.cyph.com/castle [3] https://simplex.chat/blog/20240314-simplex-chat-v5-6-quantum-resistance-signal-double-ratchet-algorithm.html#adding-quantum-resistance-to-signal-double-ratchet-algorithm https://simplex.chat/blog/20240314-simplex-chat-v5-6-quantum...
- thadt 1y agoMy read is that Signal now ratchets with ML-KEM in a similar way to iMessages's PQ3, with key delivery being one of the main differentiating features. Everyone is worried about the fact that ML-KEM keys are so chonky, so PQ3 sends them out only occasionally while Signal chunks them up and sends them in pieces along with all normal messages. Signal's argument is that a huge re-keying message could be detected and blocked, and chunking them is both safer and smoother on bandwidth. Erasure coding will likely wind up costing a bit more overall bandwidth, but each message will be more consistently sized. Given the wide range of Signal's deployment posture, that is probably a wise tradeoff to make. I would expect that Apple has a bit more control over their networks and are in a better position to deal with adversaries attempting to actively block their re-key updates.
- jorvi 1y agoIs iMessage even relevant since the vast majority of Apple users have iCloud backups turned on without E2E? E2E backups are opt-in because Apple can't help you recover your data if you turn it on. Given that, Apple can already decrypt messages of users, if so requested by law enforcement and intelligence agencies. No fancy quantum breaches needed.
- deleted 1y ago[deleted]
- jchw 1y agoI would really like to see some modern comparisons of the Signal protocol to Matrix, MLS, etc. since it's hard to keep up with everything but it seems like things are still moving.
- Arathorn 1y agoAt high level, and off the top of my head: “Signal Protocol” is a somewhat fuzzy description of whatever Signal does at a given point in time. Historically, this meant Double Ratchet, which is O(N) with the number of devices in a conversation. This uses elliptic curve cryptography to exchange keys (X25519); it was then extended to be PQ via PQXDH by adding Kyber512 to the initial key exchange, and has now also been extended to be PQ for subsequent ratcheting by mixing in the SQPR ratchet. Signal itself is obviously centralised; 3rd party implementations are forbidden; the implementation is AGPL+CLA. It has good metadata protection thanks to hiding group membership from the sender and “sealed sender” to hide the sender from the server too. Matrix is an open standard communication protocol. It supports pluggable E2EE, although the only protocol in production right now is Olm+Megolm. Olm is an implementation of the Double Ratchet, and Megolm is a per-sender ratchet used to share keys with the group. The current implementation of Olm from the Matrix Fdn is an Apache-licensed project called vodozemac. This sprouted experimental PQXDH support in Jan 2024 (https://github.com/matrix-org/vodozemac/pull/120 https://github.com/matrix-org/vodozemac/pull/120). Matrix is decentralised; anyone can run a server; multiple heterogeneous implementations are heavily encouraged. More metadata is exposed to the server than Signal - for instance the server can see the group membership, and key-value data is not encrypted (although we’re working on that right now: https://element.io/blog/hiding-room-metadata-from-servers/ https://element.io/blog/hiding-room-metadata-from-servers/). Also, group membership is controlled by the server; clients warn when if unexpected users/devices are added, but the protocol does not forbid it. We’re also working on fixing that, but it is a huge change. Finally, MLS (RFC 9420) is effectively a key exchange and group membership protocol. You can use it to add E2EE to messaging systems as an alternative to the Double Ratchet, while also using it to control group membership. By default it uses classical elliptic curve encryption, but there are proposals to make it PQ. It’s more performant than the double ratchet in that calculating new ratchets is O(log N). However, joining groups is still O(N). It’s much less mature than the Double Ratchet, more complicated, but benefits from significant cryptanalysis and formal verification thanks to being an IETF standard. It also seems to get significant hype just by being an IETF standard. It requires a centralised component to sequence MLS group operations, so to use it in systems like Matrix you have to extend it to be decentralised (see arewemlsyet.com). It doesn’t hide metadata from the server. It also doesn’t provide cryptographic deniability (unlike the double ratchet). It is not that widely deployed yet, although Google apparently uses it for RCS (presumably thanks to it being IETF and avoids any possible IPR questions over the double ratchet), which means it should be huge. Discord and Webex also use it for VoIP conferences.
- jdironman 1y agoMaybe my reading comprehension is failing me, but what does this mean for existing messages? I guess nothing of the have already been 'siphoned' to a 3rd party. As it couldn't retroactively apply to data not under Signals control of course..but what about existing messages already within their control?
- blindriver 1y agoIs it true that Signal was funded by the CIA or is that disinformation to try to get people to mistrust it?
- jmakov 1y agoWell, for some reason they're not worried about metadata. And the agencies mostly collect metadata...
- codethief 1y agoThis is not true, though? https://signal.org/blog/sealed-sender/ https://signal.org/blog/sealed-sender/ (Yes, I am aware Sealed Sender is not perfect and still susceptible to statistical attacks.)
- OutOfHere 1y agoSignal is lacking a crucial safety feature. To cover some background, it is necessary to set "Who can see my number" and "Who can find me by number" both to "Nobody", as this lowers the chances of spam messages and attempted hacks. Once these are set, the only way for someone to start a conversation with you is if they know your Signal username or QR link, both of which you can set in your Profile. The issue is that your link can be saved unsafely by your Contacts, and can be used multiple times, also by others, leaking it to hackers who can then send you unsolicited messages to compromise your device. The safety feature that would be good to have is to allow someone to contact me only via a one-time use link that cannot be reused by anyone.
- some_furry 1y agoThis sounds like an excellent feature request that would shore up their anti-abuse endeavors more than them "lacking a very basic crucial safety feature". Which of the so-called Signal competitors have implemented something like this already today?
- viktorcode 1y agoSo far the biggest weakness of Signal is identification via a phone number. It's not only hackers who can spoof the numbers, but an authoritarian governments too may take ownership of a number at any moment. Addressing future threats is good, but priorities should be different.
- exo762 1y agoYou can set a password in Signal, preventing movement of your account in case of SIM hijacking. Feature is called "Registration lock".
- array_key_first 1y agoIts a difficult problem because you, ideally, want to curb spam. Requiring phone numbers is a somewhat easy and somewhat reliable way to do that.
- jadbox 1y agoSort of. There are now immense warehouses filled with racks of used cell phones to generate spam. Limiting by phone number helps, but it's FAR from being an adequate cure.
- meowface 1y agoIf no one knows your user ID besides you and the people you share it with, why would spam be a big issue? If it's a random string, I don't know how anyone could get it, unless you share it publicly or with someone untrustworthy who shares it publicly. And even if it's a username users choose, as long as there's no directory it still shouldn't be a big problem. That is - even if someone makes 1000 bot Signal accounts, what can they really do with that if they don't have a good way of enumerating other Signal users?
- pelzatessa 1y agoThis is actually disturbing, as the article suggests that all previous messages sent using Signal are decryptable with quantum computers. If there are people with, for example, selfhosted mailservers sending PGP encrypted emails to each other, then, while they have to worry about them not leaking out from the server either by someone hacking to it or someone sniffing the traffic with the encrypted messages beforehand, they know for sure that their messages are safe. Meanwhile Signal users have been sending messages onto signal servers for years now, as far as I know they aren't sent directly through some p2p protocol. I don't know what their policy is about storing messages, and I believe that they have a lot of other countermeasures, but it still points to the problem with Signals centralized nature.
- ale42 1y agoAs far as they say, messages are deleted once delivered, or retained up to 45 days if not: Devices are always retrieving messages from their mailbox when they are online, and as soon as the device confirms they’ve gotten a message, it is deleted from the Signal servers. If a device has been offline for a while, it may have a lot of messages waiting in its mailbox when it returns. Today, Signal will hold a message in a device’s mailbox for up to 45 days, giving an idle device a chance to wake up and fetch it. (source: https://signal.org/blog/a-synchronized-start-for-linked-devices/ https://signal.org/blog/a-synchronized-start-for-linked-devi..., dated Jan. 2025)
- pelzatessa 1y agoIt is possible for them to say that they deleted the messages without actually deleting them though. One has to trust a pretty big company in order to not worry about the messages actually not being stored anywhere. I'm not aware of all techniques that Signal uses to somehow make the message anonymous even when if the encryption would have been broken, but sealed sender seems to be one of them: https://signal.org/blog/sealed-sender/ https://signal.org/blog/sealed-sender/ So at least there's that. Unless the encrypted sealed sender messages aren't somehow being fingerprinted by the IP address of client and the timestamps of connections. Signal probably also says that they don't log these, but with self hosted mailserver I wouldn't have to trust them on that too.
- ericfr11 1y agoSono pazzi, questi Romani
- 7bit 1y agoDie spinnen, die Römer!
- ericfr11 1y agoAt first, I thought the article was published on an April Fools day...
- Jenny858 1y ago[dead]
- romantomjak 1y agoSignal keeps cranking out brilliant crypto papers, but from a product perspective, it feels like they're throwing stuff at the wall to see what sticks. We've got post-quantum handshakes, stories and money transfer experiments, but still no SDK, no APIs, no bots. The official libsignal library is undocumented and incomplete. Large parts of functionality are still buried on clients. Don't get me started on "but they have published all protocol specs on their website, go on and roll your own library"! That's not how you run a product. It's borderline negligent for a platform used by millions. Every other major messaging app exposes something to developers, but Signal is allergic to the idea. Makes me wonder if they even have a head of product because whatever they're doing now is a far cry from a coherent product strategy. Signal is basically a pile of hot cryptography duct-taped to a messenger that's more hostile than any product in Apple's walled garden. And that's from a day one user who's been advocating for them the whole way. </rant> thanks to everyone involved in building the product <3
- JumpCrisscross 1y agoI'm surprised a semi-auditable Signal for Enterprise or Government hasn't surfaced. Every chat is mandatorily a group chat including the company.
- milkey_mouse 1y agoTeleMessage is a prominent, infamous such product: https://micahflee.com/tm-sgnl-the-obscure-unofficial-signal-app-mike-waltz-uses-to-text-with-trump-officials/ https://micahflee.com/tm-sgnl-the-obscure-unofficial-signal-...
- attila-lendvai 1y agolet alone this that drives me nuts: they are playing the ringing sound for the caller without the callee's phone actually ringing. and it's a deliberate choice that they are defending for seceral years now, ever since they removed the submarine sound.
- climb_stealth 1y ago
- RustyRussell 1y agoI want signal to act as a transport bus. In particular, I want to give certain contacts permission to ask my phone for its location, so I can give my wife that ability without sharing it with Google. Signal has solved the identity part, now encourage others to build apps on it. (2fa via Signal would be better than SMS, too, though I know this may be controversial!)
- mustache_kimono 1y ago> Signal has solved the identity part, now encourage others to build apps on it. Doesn't the fact that nobody has built apps on it indicate the license (AGPL 3) is a real issue for its ecosystem?
- ZeWaka 1y agoIsn't the lack of an SDK the problem, not the LICENSE?
- komali2 1y agoI'm not seeing how you could draw that conclusion. The more likely explanation is that they are telling people not to build apps around it (and I assume thus the apis aren't well designed for adoption by other apps). > This repository is used by the Signal client apps (Android, iOS, and Desktop) as well as server-side. Use outside of Signal is unsupported. https://github.com/signalapp/libsignal https://github.com/signalapp/libsignal
- Sporktacular 1y agoPost-quantum ratchets - cool. Now if they could solve notifications not consistently appearing between iOS and android devices...
- vayup 1y agoThis is a good time to remind everyone the technically sound choice of hybrid crypto is discouraged by NSA. I wish they didn't. PQ is a major overhaul to crypto systems. Setting aside the risk of yet-to-be-discovered algorithmic vulnerabilities, there is a huge risk of implementation mistakes leading to compromise. Mature classical crypto should be used as a backstop by deploying PQ in hybrid mode along classical crypto.
- bangaladore 1y agoIsn't the point of hybrid crypto due to the possibility that this fancy new quantum resistant algorithms have a fatal flaw? If so, I could understand why NSA has that stance (if you don't trust the crypto its useless), but realistically it's a good idea.
- vayup 1y agoThat's not how we approach security. We don't think in terms of 'Trust' in algorithm. We think in terms of risk management. It's not uncommon for new algorithms and approaches to have algorithmic or implementation flaws. That is a risk. One of the mitigations we often consider is adding another layer of defense.
- bangaladore 1y agoWhose is "we", because for example, the DoD doesn't agree with you. It's very much either crypto is "trusted" or useless. See NIST with the whole FIPS-142/3 debacle where they outright state that "non-certified" crypto is no better than plaintext.
- indolering 1y agoSource for the NSA's stance?
- vayup 1y agoCNSA 2.0 FAQ: https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI...
- 1vuio0pswjnm7 1y agoCan users write their own clients Can users self-host servers
- pluto_modadic 1y agoI think they could use better moderation features.
- buckle8017 1y agoWhat does that even mean.
- pluto_modadic 1y agouser posts inappropriate thing in group chat. group admins cannot delete it for everyone.
- buckle8017 1y agoThere's no moderation because signal groups aren't 1:n they're 1:1. The protocol doesn't even guarantee everybody in the group sees the same message.
- pluto_modadic 1y agopeople can see reactions :p they can also see when a mod adds or demotes a member
- palata 1y agoThis is wrong. The group admin knows the list of messages, so they could send a message to all the participants saying "remove this message". The fact that they are 1:1 means that the server does not know about the group, but quite obviously the group knows about the group.
- buckle8017 1y agoYour just like wrong man. Nothing even says the admin has to get the offending message.
- queenss90 1y ago[flagged]
- goldsteinq 1y agoI’m still not sure how do you even compromise a key without also compromising message history. The keys are stored on-device, along with associated history. If attacker has access to the keys, they also have access to all the previous messages stored on the same device. Unless you’re using auto-delete with short period on all your messaging, which I would think is not common, it would seem that you gain nothing by ratcheting.
- kogasa240p 1y agoI thought signal used some form of XMPP?
- cristoperb 1y agoNo, it has always used its own protocol. But apparently there is an XMPP extension that implements the Double Ratchet algorithm that Signal is based on: https://en.wikipedia.org/wiki/OMEMO https://en.wikipedia.org/wiki/OMEMO
- Night_Thastus 1y agoIronically I can't access the web page, browser marks it as 'Not Secure'.