https://nakedsecurity.sophos.com/2018/04/06/washington-dc-aw...
https://nakedsecurity.sophos.com/2018/04/06/washington-dc-aw...
Sure, if you're defining 'modern' as something other than what's actually used by the vast majority 2FA users. Even for people who use U2F or TOTP as their primary Gmail 2FA, what percentage do you think have actually correctly deleted their phone numbers from both their primary account and any recovery accounts? I have no idea, but I'm guessing less than 1%.
Apple didn't want to open iMessage to the world. EU/USA should enforce a common, secure method for sending text messages to mobiles.
No way do we want any regulation here! I will accept balkanization of messaging apps for the lack of government interference here. If a government messaging standard is introduced, it will absolutely be designed to consider lawful intercepts like US CALEA. It would be a key escrow system upon inception.
EDIT: downvoters, join the debate. Do you feel differently? If so, why?
There is a new standard to replace SMS in flight called RCS. Arguably, this makes the world better -- SMS sucks, RCS brings a lot of the iMessage features to standard carrier messaging. But therein lines the problem: it's carrier-controlled, and carriers want lawful intercept. So, the standard does not call for end-to-end encryption and it is not implemented.
I still think this is a better state of the world than SMS, but it's pretty depressing that it's 2019 and e2e encryption isn't the default. I understand why it isn't when there's government interests in play, but it's still depressing.
Then that is obviously not what the parent is asking for. The government could decide to enforce an insecure messaging standard at any time. What does that have to do with the people demanding them to enforce a secure one? Are you suggesting that if we demand a secure messaging standard, it will give them the idea of turning around and enforcing an insecure one instead, as though they haven't had that idea already?
Also, its simply false that the market has not produced good solutions and if there was a 'unified message solution' then people would cry 'monopoly' and demand government regulation as well.
The fact is that the standard tool for most people use for messaging in Europe is an incredibly secure protocol.
Has it really failed though?
iMessages supports CALEA (but is still end to end encrypted, as well as FaceTime), all US messaging products must support it (even Twilio supports it [1] [2]). You are unable to subvert nation state legal jurisdictions within fundamental telcom infrastructure. Signal can get away with it, Apple, Google, and cellular carriers cannot.
Can't have your cake (universal messaging) and eat it (end to end encryption with zero trust requirement) too. So can't we push from something better than SMS, using regulation if required? It must not be perfect, but simply extensible in the future (similar to SS7). In jurisdictions that are favorable to it, you support E2E encryption. In those that are not, you downgrade loudly. Compromises must occasionally be made.
[1] https://www.twilio.com/legal/law-enforcement-guidelines
[2] https://support.twilio.com/hc/en-us/articles/223136547-Submi...
So, the SMS solution is what these quasi-regulated entities gave you. Whereas iMessage, RCS, Signal, etc is what private industry gave you.
Happened exactly like that when Germany introduced their "official version" of e-mail, called "De-Mail".
When the Chaos Computer Club pointed out how their whole system is insecure, due to, amongst other issues, a lack of end-to-end encryption. The German government simply decided to declare the whole thing as "secure" trough legal definitions [0].
Which means that in practice the system is not secure, but the law considers it secure because it fulfills the arbitrary, political, definitions for "secure transmission", which also includes the capabilities for lawful interception.
[0] http://www.spiegel.de/netzwelt/netzpolitik/de-mail-bundestag...
That, and I’m fairly certain any government mandated standard would just be one more service to support.
lol I appreciate you offering an excellent counter-example to your own point within the sentence.
So, it’s incredibly disingenuous to reduce all alternatives to capitalism to murder when american capitalism is objectively morally broke.
As far as messaging apps, iMessage benefits me greatly. The premise that apps don’t benefit the user is flawed: if they didn’t benefit the user, nobody would use it — except government, we have no choice on using government or not. If the government meets 99 people’s needs, but doesn’t meet my needs, I’m stuck. I can’t switch to an alternative. If an app meets 99 people’s needs but not mine, I can switch to an alternative or build my own. Nothing is stopping you and your friends from building the most amazing messaging app ever. From someone who grew up remember Lada and Yugo, my faith in collectivism in product development is admittedly thin. Very few products from Soviet era factories were any good, I have no expectation that a government built Messaging service would be any better.
This is exactly the problem with this site: no good tools made anyone rich.
There’s a reason I am having this discussion on HN: People should separate the building of valuable things from the pursuit of riches. Those two are inherently contradictory, and we have nothing but closed mediocre technology making someone rich who barely worked at all.
I believe cooperatives, collectives, and trade unions should be discussed more here. Nothing about Yelp is hard to build, and yet it’s a piece of crap, but the only piece of crap we have. Capitalism is a future of absolute mediocrity, where your needs are considered proportional to your wealth.
I didn't write or receive any SMS for like 5 years now (except some confirmation codes) since encrypted messengers became so common and accessible.
I think it's obvious that SMS is outdated either way and I too think that encryption should be P2P on the "application layer" for many reasons. Encrypting the actual physical transport would add extra cost in terms of latency and hardware and could become a maintenance disaster over time if I'm not mistaking.
Fortunately as data plans get cheaper we have plenty of alternatives for encrypted messaging on smartphones.
Now consider a world where SMS is end-to-end encrypted. Nobody can intercept your 2FA codes, no matter how insecure the transport is.
Which I believe was parent's point. Attestation and authentication of network infrastructure (in a way that would preclude Stingray attacks) is equally important as anything you layer on top.
Otherwise, without some sort of global PKI you can consult out of band, you're just rolling the dice that the cellular station you're connecting to isn't rogue and performing a man in the middle attack.
Some sort of global PKI like what iMessage uses under the covers?
My point was that app-layer security magic doesn't mean much if your first network step is "connect to closest, highest power base station and implicitly trust it."
There are wonderful things we can do on top of lower layer protocols, but the lower layers are pretty damn important too.
I don’t understand what you mean when you say that app-level security doesn’t mean much if your first network step is compromised. TLS will protect you there, as will any other decently implemented end-to-end encrypted protocol.
I was trying to note the risks to PKI-less / web of trust participants, and should have called that out explicitly.
Mostly because I'd much rather live in an encrypted world where WoT is the dominant mode, vs corporate-controlled PKI. And the biggest risks there seems like the step no one can get around in ordinary use.
If all the user needs to verify is the infrastructure, then something like https's certificates could work, but it could be simpler because it would be managed entirely by one organization. So more concretely, your sim card could contain some root CAs that it trusts.
But it would only protect against passive attacks by your provider. It wouldn't protect against active attacks by your provider. Your provider could issue itself a new cert for you and your correspondent and then intercept the messages. It's certainly an improvement over what we have now though.
The insecurity of SMS needs to have way more awareness and vendors need to feel it in their pockets for this to improve. There are better alternatives like TOTP.