4 ms·
As someone who doesn't follow TextSecure or anything else, how does this work? How do my messages get encrypted, yet the people I'm texting don't need to insta
by ToastyMallows 12y ago
As someone who doesn't follow TextSecure or anything else, how does this work? How do my messages get encrypted, yet the people I'm texting don't need to install anything to read them? What am I missing here.
- Couto 12y agoBoth parties need to have SMSSecure installed, and a secure session started — a roundtrip of sms to exchange keys, or something (im not an expert so not sure if those are keys, or something else). Otherwise they will only see a garbage of letters/numbers.
- ToastyMallows 12y agoAh ok, I guess I read this wrong: > SMSSecure works like any other SMS application. There's nothing to sign up for and no new service your friends need to join. Made it sound like there's nothing to install. Kind of confusing.
- throwaway7767 12y agoThey mean that they use the SMS infrastructure of your telco and not their own servers. You still need to do key negotiation out of band.
- huehehue 12y agoThat seems like it would turn off some potential users due to the hassle of switching apps. I'm ignorant of the process, but is there no way to check that the user has installed SMSSecure first and, if not, fall back to sending unencrypted data? (perhaps that could be toggled via a fail open/closed option)
- Couto 12y agoYou can use SMSSecure as your default messaging app. That way you don't have to switch apps. You can even import your SMS from the default messaging app so that you don't loose your history. Bonus: you can then encrypt those SMS locally, but that's optional. You can toggle the option to send encrypted sms or not, per contact, so if your contact doesn't support SMSSecure, you just send a regular SMS. The ability to know who's using SMSSecure is interesting and not currently supported (that I know of)
- pR0Ps 12y agoActually, if you receive a message from someone using SMSSecure, you'll get a prompt asking if you want to upgrade to a secure session. But yes, there is no way to look someone up and check if they're using SMSSecure. The detection was actually inherited from TextSecure and works by "tagging" shorter messages with some detectable whitespace after the message contents. A bit of a hack, but it's a limitation of the transport. Relevant commit: https://github.com/SMSSecure/SMSSecure/commit/93d94f2b7a9fd60c5051e2e3845e40bb857cc5ef https://github.com/SMSSecure/SMSSecure/commit/93d94f2b7a9fd6...
- psykovsky 12y agoSo, that detection can be used by anyone who receives one of my texts to see if I use SMSSecure or not? Isn't that a metadata leak?
- pR0Ps 12y agoYes, anyone who analyzes the messages you send can assume that you are using SMSSecure. However, compared to the amount of metadata that's already being leaked over SMS[1], adding the fact that you could[2] be using a specific SMS client that has the ability to encrypt messages doesn't seem too bad. There was an option in a previous version of TextSecure to disable this tagging, but it was deemed unused and axed[3]. For the same reason, I'm loathe to add it back in, but having the option shoved under the "Advanced" menu may not be too bad. [1] This is something that TextSecure does much better with. SMS messages (even encrypted) still leak metadata on who you're messaging and when. [2] There's some element of deniability with whitespace tags (granted, not a lot). On the other hand, if you're registered with TextSecure (which can be checked simply by adding a user your contacts and opening the app), there's only one reason you would be there. [3] See https://github.com/WhisperSystems/TextSecure/commit/40eca5e0f600f0579c8e4001da74d19b8785e820 https://github.com/WhisperSystems/TextSecure/commit/40eca5e0...
- pR0Ps 12y agoSMSSecure's default mode is to send normal, unencrypted SMS messages so people using regular SMS clients can still receive them. If both users have SMSSecure, they can exchange keys and upgrade to an encrypted session. Also, there's some amount of autodetection going on. SMSSecure will automatically prompt the user to start a secure session if it detects the recipient is also using SMSSecure. But yes, if a user tries to start a secure session with someone who doesn't have SMSSecure installed, the recipient will just see a bunch of garbage (limitation of the transport).