8 ms·
This is why signal’s encrypted phone number lookup system is so cool. The server uses a bitwise xor when querying for numbers using hardware encrypted ram. The
by josh2600 10mo ago
This is why signal’s encrypted phone number lookup system is so cool. The server uses a bitwise xor when querying for numbers using hardware encrypted ram. The result is that even if you’re examining the machine at the most basic levels you can’t tell the difference between a negative or positive hit for the phone number unless you’re the phone requesting the api.
Obviously ratelimiting is a separate and important issue in api management.
The thing about building secure systems is that there are a lot of edges to cover.
- ronsor 10mo ago> The server uses a bitwise xor when querying for numbers using hardware encrypted ram. The result is that even if you’re examining the machine at the most basic levels you can’t tell the difference between a negative or positive hit for the phone number unless you’re the phone requesting the api. Do you have further reading on this?
- tapoxi 10mo agohttps://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/
- LunaSea 10mo agoI believe that the search term you can look for is constant time equality.
- dathinab 10mo agoThis article https://signal.org/blog/building-faster-oram/ https://signal.org/blog/building-faster-oram/ has some details but is more focused on improving their solution other blogs from the are "we want to build this soon" kind of blogs. It seems that most articles about this topic either have too little content to be of interest or are technology previews/"we maybe will do that" articles about things Signal wants to implement, where it's unclear if they did do that or something similar. To cut it short they use Intel SGX to create a "trusted environment" (trusted by the app/user) in which the run the contact discovery. In that trusted environment you then run algorithms similar to other messengers (i.e. you still need to rate limit them as it's possible to iterate _all_ phone numbers which exist). If working as intended, this is better then what alternatives provide as it doesn't just protect phone numbers from 3rd parties but also from the data center operator and to some degree even signal itself. But it's not perfect. You can use side channel attacks against Intel SGX and Signal most likely can sneak in ways for them to access things by changing the code, sure people might find this but it's still viable. In the end what matters is driving up the cost of attacks to a point where they aren't worth in all cases (as in either not worth in general or in there being easier attack vectors e.g. against your phone which also gives them what they want, either way it should be suited for systematic mass surveillance of everyone or even just sub groups like politicians, journalists and similar).
- rajnathani 10mo agoCan someone please clarify: For the phone number to reach the enclave for use during search via XOR, won't it need to come in as regular RAM via the backend's API call?
- m4rtink 10mo agoDo we relly know the server actually does this when you can't run your own Signal server instances you have compiled yourself from source code ?
- master-lincoln 10mo agoI thought you could compile from source and run Signal server instances, but there is no federation, so you would need a client that points to your server and you could only talk to other people using that client. https://github.com/signalapp/Signal-Server https://github.com/signalapp/Signal-Server
- GranPC 10mo agoThey use remote attestation based on SGX. So, assuming SGX can be trusted, yes. See https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/
- dathinab 10mo agoand assuming you have a practical way to - verify the attestation - make sure it means the code they have published is the attested code - make sure the published code does what it should - and catch any divergence to this *fast enough* to not cause much damage .... it's without question better then doing nothing but it's fundamentally not a perfect solution but it's very unclear if there even is a perfect solution, I would guess due to the characteristics of phone numbers there isn't a perfect solution
- mjg59 10mo agoWell, no - as long as someone you trust is able to do that verification, that's good enough.
- maqp 10mo agoShort answer is no. Signal provides content-privacy by design with E2EE. Signal provide metadata-privacy by policy, i.e. they choose to not collect data or mine information from it. If you need metadata-privacy by design, you're better off with purpose-built tools like Cwtch, Ricochet Refresh, OnionShare, or perhaps Briar.
- jazzyjackson 10mo agoStill lame that they require phone number at all, it took them a long time to add usernames so you don't have to expose your phone number to a new contact. Still skeeves me out that the account is associated with a SIM at all.
- HNisCIS 10mo agoWe need an established secure anonymous/subpoena-resistant chat app at this point. Signal is great for a minimal threat model but we're kinda past that now given everything going on. Simplex was a decent option but they're going down the crypto rabbit hole and their project lead is...not someone who should be trusted by anyone in the crosshairs right now.
- integralid 10mo agoCan you explain more about simplex? I remember reading about it a while ago and being really impressed. Sad to hear the project is going downhill.
- maqp 10mo agoSimpleX front page lied by omission about it having no identifiers. The fine print threat model did not mention the server has access to your IP addresses, and the mitigation to create "decentralized" system of users talking via separate servers ran into the problem of there being two VPS companies hosting the entire public server infrastructure. These issues were major as SimpleX advertised itself as an improvement over Cwtch, which should've meant superset of metadata had been protected. But that obviously wasn't the case. The CEO vanished from the discussion (again) so my proposals to improve ease of use of Tor never reached them. You can catch up on the discussion at https://discuss.privacyguides.net/t/simplex-vs-cwtch-who-is-right/19256 https://discuss.privacyguides.net/t/simplex-vs-cwtch-who-is-...
- miroljub 10mo agoWhat do you use now? Catch? Briar? Tox? I liked the SimpleX concept, but would prefer its relay server were replaced by Tor or i2p network. And if they used Signal instead of NIH protocol. Actually, the only unique SimpleX feature I really like is that it uses separate ids for every connection and group.
- codedokode 10mo agoDoes Signal protect from the scheme when the government sends discovery requests for all existing phone numbers (< 1B) and gets a full mapping between user id and phone number? While slightly unrelated, I thought, how we can fix this for truly secure and privacy-aware, non-commercial communication platforms like Matrix? Make it impossible to build such mapping. The core idea is that you should be able to find the user by number only if you are in their contact list - strangers not welcome. So every user, who wishes to be discovered, uploads hash(A, B) for every contact - a hash of user's phone number (A) and contact's phone number (B), swapped if B < A. Let's say user A uploaded hashes h(A,B) and h(A,C). Now, user B wishes to discover contacts and uploads hashes h(A, B) and h(B, D). The server sees matching hashes between A and B and lets them discover each other without knowing their numbers. The advantages: - as we hash a pair of 9-digit numbers, the hash function domain space is larger and it is more difficult to reverse the hashes (hash of a single phone number is reversed easily) - each user can decide who may discover them Disadvantages: - a patient attacker can create hashes of A with all existing numbers and discover who are the contacts of A. Basically, extract anyone's phone book via discovery API. One way to protect against this would be to verify A's phone number before using discovery, but the government, probably, can intercept SMS codes and pass the verification anyway. However, the government can also see all the phone calls, so they know who is in whose phone book anyway. - if the hash is reversed, you get pairs of phone numbers instead of just one number
- wizzwizz4 10mo agoAnd it's trivial to reverse a hash in such a scenario. This scheme is completely broken.
- Arathorn 10mo agoThere's some really interesting stuff we've been looking into on the Matrix side to solve this - e.g. https://github.com/asonnino/arke https://github.com/asonnino/arke aka https://eprint.iacr.org/2023/1218 https://eprint.iacr.org/2023/1218 or https://martin.kleppmann.com/2024/07/05/pudding-user-discovery-anonymity-networks.html https://martin.kleppmann.com/2024/07/05/pudding-user-discove.... Meanwhile, Matrix for now does support hashed contact lookup, although few clients implement it given the privacy considerations at https://spec.matrix.org/unstable/identity-service-api/#security-considerations https://spec.matrix.org/unstable/identity-service-api/#secur...
- heavyset_go 10mo agoI don't think it's cool at all, a secure messaging app should not require personal/tracking identifiers like phone numbers in the first place.
- overfeed 10mo agoSecurity and usability are frequently at odds. The ease with which users can discover and exchange messages with their contacts is a major usability issue. Phone number as a proxy for identity mostly works, at the cost of some privacy risks.
- soulofmischief 10mo agoThis made sense when Signal/TextSecure allowed users to send regular SMS, making it easy to convince others to set it as their default messenger. Now that this crucial adoption feature has been removed, it makes zero sense for Signal to continue to rely on phone numbers. Since that feature has been removed, the utility of Signal has been lost anyway and many in my groups returned to regular SMS. So the system is already compromised from that perspective. At least forks such as Session tried to solve this (too bad Session removed forward secrecy and became useless)
- K0balt 10mo agoI agree, but since a messaging apps utility is some fraction of the square of the # of users on the platform, a facile way to propagate virally is a de facto requirement for an app targeting wide spread adoption / discovery rather than targeted cells of individuals focused around a pre shared idea. It’s a compromise meant to propagate the network, and it has a high degree of utility to most users. There are also plenty of apps that are de-facto anonymous and private. Signal is de facto non-anonymous but private, though using a personally identifiable token is not a hard requirement and is trivial to avoid. (A phone number of some kind is needed once for registration only)
- 0x1ch 10mo agoThere's no alternative to reduce spam and fake accounts, unless we collectively are fine with blocking Russia, India, China, and friends from the internet.
- theamk 10mo agoSuch a nice design on server-side.. and yet on the client side, it uses system address book - something that Google backs up on the server, and many carriers back up too, and many apps (like Whatsapp) save it too. "Hey, _we_ don't store your contacts, we are good! Instead you have to manage them yourself, and in process share your presumably "secure" Signal contact list with Apple, Google, Facebook phone carriers and everyone else. But it's not on our servers, so we don't care"