27 ms·
TextSecure's Private Group Messaging
- kaeporan 12y agoThe fact that transcript consistency is waved aside, despite being an essential property of a messaging protocol especially in a group context, is problematic, from my perspective. Consider a group chat between Alice, Bob, and Carol. With this protocol, Alice can selectively send different messages to Bob and Carol with both of them thinking they got the same message. For example, Alice can tell Bob "The funds were transferred, thanks!" and tell Carol "Bob is stealing money." — and the protocol will ascribe integrity to the messages for both participants and label them as the same message. That said, I strongly respect Open Whisper Systems. They usually release very well thought-out material. Perhaps they should have paid more attention though to this particular issue.
- sigil 12y agoThey're not waving aside transcript consistency with their protocol, near as I can tell. ("We believe that it is possible to provide transcript consistency while preserving an asynchronous orientation.") mpOTR, on the other hand, only shows transcript consistency at the end of a group chat session. This does seem problematic.
- kaeporan 12y agoYes, per your quote, transcript consistency is discussed. But the discussion simply outlines problems with implementing it in their mobile use case — to my understanding the current version being offered to users doesn't have strong transcript consistency.
- tptacek 12y agoThis post says that TextSecure implements transcript consistency in the protocol, and in a fashion objectively superior to that of mpOTR: the TextSecure protocol can provide continuous consistency checks, while mpOTR can do so only when the session is torn down. What the TextSecure client does not yet do is provide a UI for that feature of the protocol. Further, it's hard to understand how transcript consistency could be a serious objection while lack of forward secrecy in the messages isn't, especially given the deniable messaging semantics of OTR. So, to address your concluding sentence directly: it seems to me like Moxie has paid more attention to this issue than you have.
- kaeporan 12y agoI'm quite certain that the current TextSecure chat allows my proposed scenario with Alice, Bob and Carol to go through without issue. This is the main problem here. So while transcript consistency is discussed in the blog post, it remains the case that Alice can send a different message to Bob and Carol without being detected.
- tptacek 12y agoThis is a comment you could have written without even reading my comment. You haven't responded to anything I just wrote. I'm not surprised; your function in TextSecure threads seems to be to pop out and complain about TextSecure without mentioning that you're the author of Cryptocat, a competing (and inferior) offering.
- kaeporan 12y agoI think TextSecure is an excellent and inspiring project. All I'm trying to do is identify an area of concern for me. I'm not sure why you're attacking me personally here. I think my initial point of concern stands and I hope the TextSecure developers will work on addressing it. And yes — I believe my work on Cryptocat does grant me some helpful perspective on the kind of issues faced in group chat. I'm more than happy try my best to offer some insight to other great open source projects. If I wanted to sneakily hide that I work on another encrypted messaging project (why would I? Open source projects discuss issues with one another all the time) it would have been simple for me to create another username.
- tptacek 12y agoI'm not attacking you personally. I object to the fact that you didn't lead with the fact that you compete with TextSecure. As for your tone regarding the TextSecure project, here are all your messages regarding TextSecure: https://hn.algolia.com/?q=author%3Akaeporan#!/comment/forever/0/author%3Akaeporan%20textsecure https://hn.algolia.com/?q=author%3Akaeporan#!/comment/foreve... I am, however, happy to attack your project, Cryptocat, which I believe to be incompetently interviewed, debugged into existence, and dangerous to its users. Finally, you still haven't responded to my comment upthread.
- sdevlin 12y ago> For example, Alice can tell Bob "The funds were transferred, thanks!" and tell Carol "Bob is stealing money." — and the protocol will ascribe integrity to the messages for both participants and label them as the same message. Isn't this trivially possible in Cryptocat for anyone who controls the server?
- kaeporan 12y agoI don't think it would be trivial (it's likely possible to some degree, but authentication and integrity checks might make it slightly more difficult), but the issue with this protocol is that you don't even need server control — any client with TextSecure installed can do this. Note: I don't mean to disparage TextSecure by saying this. By all means, TextSecure is a kickass app and you should use it. I'm just trying to point out something that could be fixed in a future update.
- sc00bz 12y ago> Isn't this trivially possible in Cryptocat for anyone who controls the server? Yes this is a known bug since August 2013. When I found it and reported it. This was "patched" but if Mallory controls the server it is still possible. There were three ways to do this: block (which just doesn't send messages to blocked users), silent drop when invalid MAC, and silent drop when invalid tag. Block was turned into ignore and these three cases now display a warning message stating something about integrity. I seem to not be able to find me or anyone stating that "if Mallory controls the server it is still possible". So I guess it was only said in person. Technically it's known but not publicly known :). P.S. This was a "clamp the artery until the mpOTR protocol is finished".
- seertaak 12y agoI've been using TextSecure for my private messaging and am a big fan. I can't wait for WhisperSystems to release the iPhone version of the app -- at that point, all my family's communications will go through TextSecure.
- pnathan 12y ago" ephemeral signing key pair along with K. ... hash-ratcheting K and including a signature in the transmitted ciphertext." Can someone knowledgable comment about the crypto protocol here and how this provides guarantees that ensure the server can't reverse the messages for multicast (am happy to read academic papers here too)?
- codelike 12y agoI'm a big fan of TextSecure and recommended it to all my friends, both those in IT and 'normal' people. Usually, I managed to convince them that the open source nature of TextSecure and the crypto experts behind it (e.g. Moxie) make it more secure than Threema/... . However, the more sceptical ones among my friends always asked two questions, which I didn't have a good answer for: 1. What is TextSecure's business model? Who pays for the server infrastructure? 2. Doesn't WhisperSystems belong to Twitter? Twitter is a US-company (and also part of the NSA stuff), so why should I use that kind of software? [Edit for clarification: I'm from Germany, where the US/Twitter affiliation is seen as a downside by some people]. It would be great if TextSecure/Open Whispersystems publicly addressed these points. I have seen that there's a reply from Moxie here: http://support.whispersystems.org/customer/portal/questions/5836104-how-is-openwhispersystems-paying-for-the-its-server-costs- http://support.whispersystems.org/customer/portal/questions/... but these two questions are so central that they deserve more attention than a reply in the support forum. From a technological point of view, TextSecure wins hands down. Now it's time to convince those who are still skeptical because of other reasons. Just to be clear: I want TextSecure to become successful. I'm a big fan. That's why I'm mentioning this: in order to help spread the word.
- phaer 12y agoAfaik TextSecures server infrastructure consists mainly of Google Play Services which comes at no financial costs for them but with the downside of depending on Google to temporary store encrypted text.
- makomk 12y agoYeah. The more substantial downside is that Google effectively has remote root access to every device which holds decryption keys for that text. That's not exactly ideal.
- xyzzy123 12y agoI would be interested in your thoughts on alternative platforms / firmware /ecosystems which get around this?
- davidroetzel 12y agoI would love to have a console or even web client for this. Or is anyone aware of a secure group chat application to replace IRC (or SILC for that matter)?
- phaer 12y agoAs far as I now, there is a in-browser client (a browser extension, iirc) in development. Your second question is harder. I don't know of a better solution than a self-hosted jabber-server with https.
- secfirstmd 12y agoAwesome, look forward to using it!
- zokier 12y agoI wished moxie would have discussed more the group management aspects. > Anyone can create a group, name it, give it an avatar icon, add members, and then everyone can chat together with a normal asynchronous experience. Does this mean that any group member can add more members? Are there any IRC-like moderation features (even planned?), eg. privileged members who can remove users from group? Is there support for persistent groups (ie IRC channel equivalents)?
- liliakai 12y agoTextSecure groups are fully egalitarian. Anyone may add members and no one may force an existing member to leave. There are no privileged members. A group conversation persists locally on your own device unless you delete it, just like a normal conversation. The server does not store any records representing the group, so there's nothing to persist beyond the clients. There is no plan to change these properties, afaik.
- scl_md 12y agowhich application should I use if I have an iphone? (and do not want to change the iphone) what program would you recommend? thank you very much
- dm2 12y agoI think TextSecure is coming to iPhone soon, so just wait.
- throwaway41597 12y agoThis is great! And I love TextSecure. But I wish it didn't send my contact list to its servers and store them in perpetuity [1]. Has it be considered to use: 1. text message history with a contact to derive a key between two contacts? 2. adding metadata to text messages to discover the sender uses TextSecure? By (1), I mean Alice and Bob may already have exchanged several messages. I believe there is a lot of entropy in text messages. That should be leveraged during the key exchange. In addition, you'd also use WhisperSystems's servers as another channel, so the mere possession of the text history doesn't allow an attacker to guess the key. (2) would only be useful when Alice sends her first text to Bob. She would for example hash(text_message + "I use TextSecure"), then append the encoded hash to the text and finally send it. The encoding could be white spaces for 0 and tabulations for 1. The size of the hash could be as small as 8 bits, because adding 8 trailing spaces/tabs to a text is so rare in real life. Once Bob receives the text, he can reasonably assume Alice uses TextSecure and then start the regular key exchange. [1]: https://whispersystems.org/blog/contact-discovery/ https://whispersystems.org/blog/contact-discovery/
- Canada 12y agoReference [1] doesn't describe what TextSecure actually does. The client sends a truncated hash of each contact to the server, and the server responds with the set of matches. The process does attempt to protect your privacy, however the "preimage space" is small, and the server will accept thousands of contacts per directory update so enumeration of TextSecure users is possible. The directory update process occurs every 12 hours. The TextSecure-Server does not store these hashes of your contacts. Of course, we can't know for sure what any particular instance does. It could be modified to log that info. Metadata is in fact added to text messages to discover other TextSecure users. You can exchange encrypted messages over SMS and MMS with users who are not registered on the server or with users who are registered on another server.
- throwaway41597 12y agoYes my reading of the blog led me to believe they use the naive solution because it only lists solutions which don't work and concludes that TextSecure is too big to use these. Do you mean that TextSecure may send encrypted messages to contacts who don't have it? You didn't address my bullet (1). If Alice has exchanged N texts with Bob prior to installing TextSecure, these messages could be used to make the preimage space huge. Texts have a lot of entropy. From an scrypt slide "Entropy estimated according to formula from NIST: 1st character has 4 bits of entropy; 2nd–8th characters have 2 bits of entropy each; 9th–20th characters have 1.5 bits of entropy each; 21st and later characters have 1 bit of entropy each". So a 140-character text has about 156 bits of entropy, excluding the date the text was sent which probably adds some 20 bits. It's too bad not to use that both during the discovery and the key exchange. Same thing for RedPhone, it could leverage the call log between Alice and Bob.
- a159482a 12y agoIf it were to be HIPPA compliant, like Medigram, then it potentially could be useful for health practitioners as well.
- fossuser 12y agoOn somewhat of a meta-HN note it seems strange to me that every one of kaeporan's comments has been heavily downvoted. Seems unnecessary - maybe the downvote karma threshold needs to be raised again? To 1000?