On Ghost Users and Messaging Backdoors
blog.cryptographyengineering.com
blog.cryptographyengineering.com
- Add "ghost" users/devices to existing chats
- Suppress notifications of these additions to users
This would perpetuate a currently known bug in secure communication protocols, effectively turning it into "feature" for law enforcement.
Fortunately, systems like Signal and Briar have already moved past this flaw.
Perhaps another user with stronger familiarity on the subject can expand on this (ELI5 would be great!).
Edit: also, this is a deliberate design choice not an arbitrary one.
However, a few points to consider:
1. The signal server can't "see" the group. Clients are just sending N messages to everyone in the group with some encrypted metadata that says it's a group message.
2. The client app is open source. You can go look for a ghost user or backdoor mechanism yourself.
3. The build is reproduceable. You can build it yourself and sideload your own APK, or compare it to the APK coming from the play store.
I don't think it's impossible to put a backdoor in, but I think it at least makes vigilance a good defense. Smart serious people are paying attention.
And of course for major apps, there are people doing so.
"Modern Intel chips support a feature called Software Guard Extensions (SGX). SGX allows applications to provision a “secure enclave” that is isolated from the host operating system and kernel, similar to technologies like ARM’s TrustZone. SGX enclaves also support a feature called remote attestation. Remote attestation provides a cryptographic guarantee of the code that is running in a remote enclave over a network.
Originally designed for DRM applications, most SGX examples imagine an SGX enclave running on a client. This would allow a server to stream media content to a client enclave with the assurance that the client software requesting the media is the “authentic” software that will play the media only once, instead of custom software that reverse engineered the network API call and will publish the media as a torrent instead.
However, we can invert the traditional SGX relationship to run a secure enclave on the server. An SGX enclave on the server-side would enable a service to perform computations on encrypted client data without learning the content of the data or the result of the computation."
https://signal.org/blog/private-contact-discovery/#trust-but...
I don't know if they've got that in production yet - and I don't know just how strong the "cryptographic guarantee" of the secure enclave code is, but the fact that they're trying it fills me with joy...
Have you tried this? Most people seems content that there is some source available and trust the binary. That may not be an option for everyone.
There's a non-zero number of people around the world who check the builds. Your security rests on the difficulty of feeding you a subverted APK without feeding any of them the same APK.
If the attacker can identify your devices 100% precisely, just one device, then the rest doesn't really matter. But if the attacker has incomplete information or a coarse attack vector, then others must be attacked along with you. For example, if the attack works by putting a subverted APK on one or more CDN nodes, then everyone else in your geographic area gets the APK along with you.
If there's one person who gets the subverted APK and checks it against the original, the attacker's attack is public. If there's one person who automatically uploads all new installed APKs to apkmirror.com, then the attacker's attack is public. See?
There is (AFAICT) no single list of people who would discover the attack, and who therefore must be avoided by the attacker.
Now, if the attacker is willing to have the attack revealed a day after it happens, this may be acceptable. But otherwise, the attacker has to find a way to target you and avoid any false positives who might do that checking.
https://github.com/signalapp/Signal-Android/wiki/Reproducibl... is a thorough recipe, but I didn't actually do all of that. I had the right build environment anyway.
It would be interesting to compare its implementation to how Signal does group messaging in TextSecure v2.
[0] https://keybase.io/blog/introducing-keybase-teams#anyway-tea...
At least $50 million, courtesy of a WhatsApp founder: https://www.wired.com/story/signal-foundation-whatsapp-brian...
Either the backdoor works and the system is bad. Or the backoor doesn't work and the system is illegal. At least if the law doesn't have a loophole.
So not sure why the article complains about the design whereas the intent and goal are the real issue. Seems like the design works as intended.
The main complaint seems to be that Over time what seems like a “modest proposal” could lead us to world where GCHQ becomes the ultimate architect of Apple and Facebook’s communication systems.
But that is of course inevitable if the proposal is to be successful. What other solution would the author propose?
Who do our tools serve? Is it just that they should be made to serve someone else, against us? Where, exactly, is the line on one side of which it's justified, but on the other it's abuse? How do you build a system that prevents abusive uses, but allows appropriate ones?
Decrying absolutist positions is all well and good, but it is a nigh-on tautology-level truth that a system with a flaw or backdoor, will be exploited — usually in multiple ways, and well beyond any potentially intended such.
Myself, I'm not quite so convinced as you seem to be of the harm of "absolutist" positions. Maybe the truth isn't always somewhere in the middle
Remember Nextel direct connect? It was known that those communications weren’t tappable initially, and for a time every street level drug salesman had them.
(Looks around the office and sees the Echo and Google Home, remembers how many friends have those and/or Samsung "Smart TVs" in their home, or who have their phones constantly listening for "OK Google" or "Hey Siri". Right. As you were...)
The state should be able to get a warrant to intercept communications for reasonable cause, and the accused should be able to litigate the validity of the search.
Pretending that technology is infallible is a defect equally as bad as NSL with respect to the rule of law.
Obviously no complex IT system is infallible, and now we have a situation that with no legal remedy, the police and intelligence services are compromising or allowing latent defects to remain in order to fulfill their missions.
You never hear about law enforcement concerns with respect to iMessage or Signal, so it is likely that whatever security you think you have from the state is not meaningfully there.
Governments are more powerful actors on this playing field, but they are far from the only ones on the field.
A warrant doesn't expose something your saying to the government, it exposes what you're saying to anyone who might be listening.
We're not talking the equivalent of handing some documents over to the police, we're saying the police are ordering us to stick the documents to the window of our house so that they can see them.
Even with a messaging app, imagine that you created a new one, and then found that for some reason 90% of your user base is hitmen communicating with their clients. Maybe that's not your fault, but I think you would be ethically obligated to shut it down, or significantly modify it to stop enabling hitmen.
Obviously these are contrived examples, and often in real life it's impossible to make a tool that can't be used for evil. But I don't think you're devoid of responsibility just because you didn't intend for your creation to be abused. If you accidentally created something dangerous, you have an obligation to take reasonable measures to mitigate the danger.
All that being said, I do agree that in some cases there is a definite ethical burden on a creator to consider the impact of his creation - I just think that in many cases the best solution is not to change the tool to avoid misuse but to figure out why the misuse occurs/would occur in the first place and try to solve that. I would conjecture that the misuse more often than not points to a deeper social issue that is for some reason not being properly dealt with but which is actually a really big deal that no one wants to confront. I can think of a few examples but I think that level of exploration may be better suited to a blog post than a comment.
Allowing governments access to IM history gives them way more power than they ever had. This is not just restoring lost powers. Never has to government been able to see your entire history of every conversation going back for years. I think most of us would be ok if it were actually possible to create a system where only the government after going through proper court process was able to intercept the messages from that time and forward but currently there is no good proposed solution and very dangerous laws like those in australia are being approved.
If you don't agree with the poster then engage in debate, don't just click the little arrow to try to grey it into oblivion.
We're all here to learn. Why not learn how to challenge this fairly widely-held view. Imagine you're talking with a 'normal' at a Christmas party and they say that; do you just stomp away singing LALALA?
I mean, yeah, sure it's something to consider. But it's not exactly like too much surveillance hasn't ever killed anyone.
People get killed by mobs in China[1] as well, a country which backdoors all major social networks (Weibo etc) + at network edge (great firewall).