* In modern messaging protocols, they don't have to care about encryption. The protocols are designed to reliably encrypt messages without user intervention, and security isn't "opt-in".
* The people who most need encryption are not the ones who are most aware of the need. In fact, the Venn diagram of "need" and "want" for crypto has very little overlap.
Sounds good. Doesn't sound worth giving up decentralisation for. Doesn't even seem like something we'd need to give up OpenPGP to get - if client design were equal (and it isn't at the moment, but I see no reason it can't be) I'd far rather have that client experience but with the more established/tested protocol.
> The people who most need encryption are not the ones who are most aware of the need. In fact, the Venn diagram of "need" and "want" for crypto has very little overlap.
I think that's even more true for decentralization than it is for encryption.
Some people really manage to mess up styles and Open or LibreOffice used to make it much easier to clean up those docs. (I'd switch back to get page numbers right though :-/)
Also, given how PGP works I fail to see how you can claim that you can achieve comparable client design/ease of use/UX to Signal.
At the very least it appears evident to me that the problem is much much harder than Signal (and it should be, Signal was designed from the ground up with UX in mind, and made several important trade offs for it).
No single point at which to apply judicial- and/or rubber-hose cryptography is the big one.
I do agree that the problem-space of attempting to make a reasonable UI for GPG has been explored for a long time with no useful results. I'd love someone to prove me wrong, but it seems like that's a hopeless endeavor.
It is worth asking why, though. I'm not a UI person, so apply appropriate weighting to my opinion. I think this is one area - application of the Unix philosophy to task-driven security software - results in software that only the really invested will use. A combination email encryption/key distribution system with most nonessential options stripped out, targeting one mail client (at least at first) might be simple enough to achieve something closer to Signal-level usability. And the rounding-errors can continue to use the full GPG for our weird open-source rituals.
But who knows. Maybe the entire model is just too complicated for mere mortals.
Has it? Have we ever had even e.g. 2 reasonably skilled design professionals spend a year trying? That would, I suspect, be much less effort than has gone into Signal et al. But still beyond the resources of volunteer-only FOSS, unfortunately.
But PGP-over-SMTP would still leak important metadata, and you would still have problems with forward secrecy and key revocation.
Matrix looks like a much better decentralized solution to build a new email infrastructure on. But there are still metadata leakage issues with federation, and there need to be some standards and an example implementation for email-over-matrix.
I don't think a well-integrated PGP-over-SMTP client would leak any more metadata than the likes of Signal does? Build in a good subkey rotation config and you'd solve most of the forward secrecy issues, and good defaults for how to treat revocation (including better expiry defaults) would resolve that issue. No?
I do not know enough to be sure about your point about forward secrecy. You may be right.
Sure, so any intermediate server would see who was talking to who. But that's the case with Signal et al as well isn't it?
No.
”Because your phone will be connecting to Signal’s servers, your cellular carrier can determine whether or not you are using the service. However, your carrier cannot gather any information about the individuals or groups with whom you are communicating.”
Source: https://github.com/WhisperSystems/Signal-iOS/wiki/FAQ#what-a...
It's a lot harder to block. You can have anyone run a mail server on any port (SSLed if necessary), which means you can use it for secure communications inside any "great firewall" (like that of China or Kazakhstan), or even in a country/region that's been cut off from the Internet (which we've seen happen for various amounts of time in Syria, Crimea, Turkey...). WhatsApp/Signal have a very limited version of this by getting makers of popular HTTPS services to work with them, but those services are subject to their own commercial pressures (all the big names have been known to collaborate with e.g. the Chinese authorities in the past) and attackers always have the option of just blocking those services outright.
It rules out a whole class of attacks involving compromising the central servers and tricking the client into redoing an initial exchange. If the Signal client is implemented correctly this shouldn't be an issue, but it's an extra attack surface that simply doesn't exist for OpenPGP.
Also compared to Signal et al it's more practical (though still difficult) to use pseudonymously, because a pseudonymous email address is eaiser than a pseudonymous phone number. Signal advocates talk about having deniability because your messages aren't provably signed by you, but I don't think that advantage exists in any reasonable threat model - if we're worried about a state adversary hunting down everyone who corresponded with dissident x, they'll find it easier to track down a phone number than an email address, and once they've tracked down one of x's correspondents (i.e. someone who has a phone with a number that exchanged messages with x) they're not going to be bothered by the fact that they don't have signed mathematical proof that this is the same person who corresponded with x.
> Signal was designed from the ground up with UX in mind, and made several important trade offs for it
Such as? At the protocol level I mean.
One of the explicit protocol level trade offs is federation:
> One of the controversial things we did with Signal early on was to build it as an unfederated service. Nothing about any of the protocols we've developed requires centralization; it's entirely possible to build a federated Signal Protocol based messenger, but I no longer believe that it is possible to build a competitive federated messenger at all.
The reality is that, no matter how much I wanted xmpp (and google wave for that matter) to succeed, Signal (and if you are willing to trust the closed source client WhatsApp) are the only ones that did.
And that's even though XMPP preceded Signal by a decade. The argument that a good federated user experience is possible in principle starts to sound a lot like talk about "sufficiently smart compilers".
Let's grant it is true that we don't have sufficient resources to update a host of different clients to use all the extensions. So then it still seems that in a resource constrained environment federation is not feasible. Open Whisper Systems managed to get encryption on a billion devices with a team of three people. The idea that it only succeeded due to a resources advantage (rather than fundamentally different trade-offs) does not seem very plausible.
For how much of that decade did we even see "a couple of full-time developers" applied to XMPP though? Yet alone an actual UX designer.
Trade offs:
Onboarding is trivially more complex. You have to enter your JID and a password -- registration of a new JID adds one checkbox to that.
Contact discovery does not piggyback on phone numbers, so you will have to add JIDs to your address book if you want Conversations to pick them up.
Another new XMPP-based app, Zom (https://zom.im/) makes some of this easier by letting you automatically register on their hosted XMPP server, locking you into sane default settings, etc. Android app seems still a little buggy, though.
As long as the message silos aren't regulated as utilities, decentralised systems give us more of the freedoms.
It's pretty easy to run a separate dns system - you can even blend your own private "authorities" dns for new tlds with fall back to the centralised root servers.
if /BEGIN PGP SIGNED MESSAGE/.test(message) { greatFirewall.block(message); }
Note that this argument is even more problematic for OpenPGP-encrypted email, as such email sends all metadata and some message data in plaintext.
I ususally respect tptacek a lot but when it comes to Whatsapp I actively avoid it if at all possible, preferring Telegram even if the crypto is more than questionable. Same goes for mail: I prefer it - even unencrypted - over Whatsapp.
For some of us our treat model is more concerned about Facebook and less about major TLAs.
With Whatsapp I have to expect that all metadata about me - and my friends - are fed into Facebook and datamined from here to eternity and back again or until the end of the world as we know it.
I have little to hide but given the catastrophically bad ad targeting of Facebook (yes, I am still a happily married father, a Java developer, a Norwegian. I don't need ANY more ads for dating websites until I specifically change my profile to let you know, THANK YOU. I would be happy to learn about useful developer tools or underrated fast food restaurants though. I also appreciated the uber ad with bundled coupon in google maps a few weeks ago and tested uber for the first time.)
Given the same catastrophically bad targeting and given that it is the same owner who as far as I know hasn't yet apologised for his remarks about how trusting him was stupid it wouldn't surprise me if is more a WHEN than a IF that Facebook is going to sell everyones data to insurance companies, support scam call centers etc.
I am not trying to use a secure messenger. I am trying to use a good one without ratting on my friends to the worst (as in size x badness) company I am aware of. Ohh, and I don't want to be be part of their network effect either.)
Decentralization/Federalization + Standard Protocols. To really get the full potential, one needs both, since only then the network is truly free.
Nobody can tell you how to access the Network, what software to use, who you can communicate with, etc.
If you try using an unofficial WhatsApp client (eg. when you don't have you're phone), they can delete your account, and you can't do anything against that. This is IMO just too much control the central server has over the client.
It also encourages competition, since the user can switch to a different service, and not be penalized by network effects preventing them from communicating with other people.
I use MX records in my domain so that I can switch to any mail provider I want, and people will still be able to contact me with the same address.
How is this possible in a centralized system? If I switch from WhatsApp to Signal, I lose all my contacts. If I want to keep communicating with them, then I have to convince them to switch to a different app, or just never stop using whatsapp. The network effects dynamic here makes it very difficult to switch from one centralized encrypted chat provider to another. If you try to leave, you lose all your contacts.
The other thing I dislike is that they all seem to require a valid phone number. This puts you at the mercy of the phone company. If you change your phone number, then you have to get all your contacts to change their contact info for you. This is a huge step back, compared to email with own domain and MX records!
The other thing I dislike about these centralized encrypted chat providers is the lack of client choice. 1 company can only support so many platforms, fair enough. But that will likely mean I'll never see the company develop a Linux desktop client, or a terminal based client for their network. And because of centralization, no-one else will be allowed to develop one either. In contrast, there are many different tools I can use for sending and receiving email on the Linux desktop, cli based backup tools, etc.
And as far as the spam problem goes, I'm not sure how Signal/WhatsApp are better in this regard? If you have to give your signal address to out for people to communicate with you, or to do business with a company, then I don't see why companies can't just spam you. Signal can centrally filter all messages you receive to make sure they don't have spam in them and block spammers messages from going through (but this is no different than what many mail providers also do). You can block individual contacts, but that doesn't help if there are a very large number of different accounts sending spam. You can whitelist your contacts, but then noone you don't know that wants to talk to you can contact you.
It also doesn't stop known contacts from sending spam to you either because
- They are forwarding spam messages to you, like chain letters.
- They got a virus or some malware which sends spam to all their contacts
- It's a "legit" company you need to receive communication with, but sends spam mixed with vital communication: marketing lists you get auto-opted into (imagine if all the "give us your email to read the article" pop overs got replaced with "add us on signal to read the article"), amazon sale ads, facebook constantly trying to entice you to go back on the site, etc.
If signal replaced email, I don't see how it could remain spam free.
You don't understand the problem: if you rely on a service like this, two things can - and by the laws of probability, will - happen:
a, a centralized service goes down and suddenly no one can talk to nobody b, you're unable to send a message to someone and never realize it
Imagine if there was _one_ ISP. One single mobile provider. If it goes down, it goes down everywhere, for everyone. Not fun.
As for b, I can't remember, but there's a term when a provider let's you post but it won't get show to others. They can also alter messages - see the Whatapp signal implementation issues that certificates can be silently re-issued.
You are, unfortunately right though: very few of us realizes how important this is. Thankfully the smarter elders of the internet seem to do. https://www.decentralizedweb.net/
If you find that unthinkable, consider the bubble you might be living in. I appreciate that there are people that require a decentralized service for messaging and understand where they're coming from. I don't deny their existence. I simply think their numbers are much smaller than they appear on nerd message boards.
I highly doubt that's true. Email is pretty essential to the functionality of the internet, from signing up accounts to getting notifications, to just plain discussions with professionals. It's pretty much the only thing that does what it does.
To use non-nerd examples people in my life have done recently via email: contacting the school registrar's office, updating insurance information, discussing minor problems with a recent surgery with their doctor. Especially for people with anxiety issues who have problems on the phone, email is a life saver.
I lived off email when buying a house through a builder last year. Everyone went through email and nothing else was even offered in many cases. The builder, bankers, lawyers, electricians, everything was email.
* Email remains important for middle-class Americans because it's used for business. But that is a small subset of the whole population, including very large numbers of Americans.
* For almost all those users, email might as well be a Google, Yahoo, or Microsoft product.
* Every year, the number of people and businesses that rely on email gets smaller --- in the last 5 years or so, by something like 15%.
There's no trend we're looking at that suggests that email is becoming more relevant.
We should be happy about this, not freaking out. Even if you think the future is decentralized messaging protocols (I like decentralized too; I just think we should figure the nuts and bolts out before we decentralize), email is a boat anchor holding us back.
If that's true then where's that stat from and how are these businesses getting contacted online?
There's no decent replacement for email in that department at all to my knowledge.
I've done most of my non-B2B communication with businesses over the last year or so via FB messenger, Twitter or phone.
Bolting on decentralization works about as well as bolting on security.
Middle class Westerners (not only Americans by any mean) that are doing business are also pretty much the only ones that are willing to spend money on written communication. E-mail might not be on the rise, but I'd guess it grosses way more money than all IM platforms together.
* You have to use one that is not economically or legally dependent on a jurisdiction hostile to you.
* There can never be many different centralized messaging systems that are economically viable because that requires network effects.
As a result, there will always be a large number of people who will not be able to find a centralized system that protects them reliably.
What's considered reliance? What's the name of some place that stopped using email? I can see a drop in businesses that are running their own email, and that outsourcing maybe represents a big shift in terms of how they see it as "not critical and must be kept in house" but I don't know that they rely upon it much less.
How are these businesses messaging and communicating?
I still believe email will outlast all the current solutions though, but the crushing presence of a few big providers is not doing any good for the protocol.
https://i.imgur.com/Fp2LLCg.png
Annual per-capita mail delivery is down 50% in the US since Y2K.
I still receive all my most important communications through the mail box, including anything related to administration, voting, my landlord, invitations to major life events, bank details, etc.
Now if you hope to kill email, you gonna have to remember that.
> Every year, the number of people and businesses that rely on email gets smaller --- in the last 5 years or so, by something like 15%.
Are you sure that's not just the spam decreasing?
If he claims something, he should be able to back it up with something else than his so-called "authority".
Say Gmail goes down (forever), will people use another of their emails? Or register for a new one somewhere else? Or start using another medium of communication alltogether? I assume all of the above will occur to some extent, but if that system was centralized, only the third option would be available. And if that centralized system was so good that it had killed all competition, then suddenly no one would be able to communicate.
It's not about the amount of people who scream for decentralized solutions. It's about the alternatives available in case something does go down, and how easy those alternatives are for users to adopt.
What would happen if e-mail didn't exist, and a site like HN listed their WhatsApp contact information instead of an e-mail address? Suddenly, the Brazilian user base here would be unable to contact HN. They might be completely out of luck, or if the user base was large enough, HN could add an alternative contact method for users in restricted regions. "Contact us on WhatsApp. If you're in Brazil, you'll need to contact us on ABC messenger instead. If you're in China, and unable to access both, you'll need to send us a message on XYZ messenger."
Average Joe is perfectly fine with just "100% secure" label. Add some "military grade hurr durr" nonsense (okay, maybe it's a bit outdated buzzword) and Joe's even willing to pay for it. No need for any actual security.
And doesn't apply to IM systems, because it's just not possible for Whatsapp user to contact Signal user and invite Wire user in a group. IM app fatigue is a real problem. Or maybe it's just that nearly everyone in my bubble has load of apps just to contact all their peers.
Email yes, encrypted email, no. That's the whole point. A decentralized system, as nice as it is in theory requires participation to enable widespread change. You cannot just say "now we all encrypt email" and know that everyone does. But you can change the transport mechanism of a centralized system to something encrypted and know that it works for all participants, even for those that don't care or don't know how to do it themselves.
It's a trade-off. Again.
The "market share" of SMS is the entire world. SMS works with anything from a $15 Shenzen dumb-phone to a $1k iPhone 7+. Not to mention that unlike WhatsApp, which is forbidden to do business with countries like Iran (due to US export regulations), SMSing works with any country in the world except North Korea.
Not an argument for or against any privacy solution if you're citing people who don't care or make sacrifices. They're not the demand side for private messaging. The solution for such people is security professionals getting employed with or consulting those groups to embed strong security into their products with continuous monitoring for subversion at source or repo level. They mostly arent doing that.
So, the WhatsApp point is broken twice: its users dont care enough to use something better; best security people talking WhatsApp security arent there improving or maintaining it.
However I would not like it to transform into phone number harvesters for spam.