9 ms·
Soatok's Informal Guide to Threat Models
- evanprodromou 3mo agoWow, excellent guide! And I love the E2EE example.
- mapontosevenths 3mo agoThis is the best gay furry blog post about threat modeling I've seen all day!
- Lucasoato 3mo ago> Please remember that Dhole Moments is a furry blog before complaining about the furry art. It gets exhausting. Articles about cybersecurity gets 100% credibility when made by furries.
- phrotoma 3mo agoI wonder what the reaction would be if the folks beyond the HN crowd understood the extent to which the internet runs on queer / trans / catgirl / furry power?
- deleted 3mo ago[deleted]
- teravor 3mo ago> Hybrid PQ+ECDH is a hedged bet against an algorithm break before Q-Day, but is utterly fucking useless over Pure PQ once Q-Day occurs. there is also the likelihood that Q-Day never arrives, either because something we don't know prevents the construction of sufficiently large quantum computers (eg. quantum gravity) or because the entire field was a scam. in that scenario abandoning ECC would have been pretty stupid.
- some_furry 3mo agoHi, I'm the author of this blog post! > there is also the likelihood that Q-Day never arrives, either because something we don't know prevents the construction of sufficiently large quantum computers (eg. quantum gravity) That is possible, but given the recent 2029 timelines from large Internet providers, I think it's prudent to prepare for Q-Day even if it never arrives. > or because the entire field was a scam. The field is like... a magnet for scams, sure. But it, itself, isn't one. And, like, the Quantum Village at DEFCON has really failed to establish credibility in my eyes. https://soatok.blog/2022/08/18/burning-trust-at-the-quantum-village-at-defcon-30/ https://soatok.blog/2022/08/18/burning-trust-at-the-quantum-... https://soatok.blog/2023/08/20/defcon-quantum-village-2-electric-boogaloo/ https://soatok.blog/2023/08/20/defcon-quantum-village-2-elec... > in that scenario abandoning ECC would have been pretty stupid. Not really, no. See https://blog.trailofbits.com/2024/07/01/quantum-is-unimportant-to-post-quantum/ https://blog.trailofbits.com/2024/07/01/quantum-is-unimporta... for a counter-point.
- teravor 3mo ago> That is possible, but given the recent 2029 timelines from large Internet providers, I think it's prudent to prepare for Q-Day even if it never arrives. no one argues we shouldn't. you made the argument that we should abandon ECC by not doing hybrid, in my opinion it's an extremely weak argument because it assumes Q-Day will arrive. don't change goalposts. the article you linked supports my position. > the fear of the quantum doomsayers is based on a completely valid observation: the internet has put nearly all of its cryptographic eggs into the single basket of the hidden subgroup problem. > By the time the next phase of standardization is over, we can expect to have algorithms based on at least three or four different mathematical problems. If one of the selected problems were to fall to advances in quantum or classical algorithms, there are readily-available replacements that are highly unlikely to be affected by attacks on the fallen cryptosystems. in fact, it makes the argument (if not directly) for a concatenation of multiple schemes. I'm all for it, hybrid++.
- Cider9986 3mo agoThis was a fun read. My introduction to threat modeling was from this post: https://www.privacyguides.org/en/basics/threat-modeling/ https://www.privacyguides.org/en/basics/threat-modeling/ It's a bit shorter and focused for people interested in privacy.
- raychis 3mo agoReally enjoyed this framing of threat modelling as a way to make assumptions explicit and not just a compliance checklist. It was also quite amusing and sassy. Well done to the author, great piece! The point that secure is meaningless without defining the adversary and assets is especially important. One thing it doesn't tackle that I would like to know more about is how do teams keep these assumptions and threat models current as the system and its environment evolve? I think that is a massive challenge.
- ezst 3mo agoMaybe I shouldn't, but I stopped taking the author seriously for their lack of nuance/extremely biased views favouring Signal in every article about E2EE applied to IM. But I do agree that threat modeling is just a support to formalize and document the variables in the threat equation. It doesn't say anything about whether the threat is reasonable, legitimate and grounded in reality, so it's only knocking the subjectivity can a tad down the road.
- wizzwizz4 3mo agoDoes one have to be nuanced in everything one says? I'm not a fan of Signal's threat model, especially their historical threat models (e.g. acting like it's safe to link users to phone numbers, and then advertise which phone numbers are and aren't using Signal), but Signal's main protocol seems pretty solid, especially compared to some other systems.
- some_furry 3mo agoMaybe it's because I'm a bad writer, but I've heard from at least a half dozen people in recent years that they think I'm too pro-Signal when my actual stance wasn't "Signal is good" but rather "all these so-called alternatives suck ass when it comes to cryptography implementations". Signal pisses me off in a lot of ways. If someone joins a group chat and posts horrific content, the admins cannot clean it up. This extremely basic functionality doesn't meet the most basic bar for group moderation and safety tools. This means a troll posting a high-frequency flashing GIF to a group chat full of epileptic people is going to cause real harm. This means someone joining a chat and posting unsolicited CSAM will legally imperil everyone present and the admins are powerless to intervene at all. They seem really indifferent on fixing this. I would love for an alternative app to materialize that provided the same level of cryptographic excellence as Signal but without the enormous ego of their marketing teams or evangelists, which actually put a microgram of care into user experience and community safety. None of the alternatives people raise meet the bar, and I find it extremely disingenuous when people insist their privacy (which is a second-order property from their cryptographic implementations) is somehow "better than Signal". So when people do this, I tend to 0day their favored apps. https://soatok.blog/encrypted-messaging-apps/ https://soatok.blog/encrypted-messaging-apps/ We, collectively, as an industry, should be able to do better. That we haven't is depressing.