Vuvuzela: Metadata-private messaging
vuvuzela.io
vuvuzela.io
> Vuvuzela can support 1 million users exchanging text messages (up to 240 bytes each) with an end-to-end latency of 37 seconds, achieving a throughput of 68,000 messages/sec.
Unfortunately, 37 seconds, even for a privacy-aware service, seems too slow to deliver instant messages.
I don't think all text messaging is equal. If you want a realtime conversation with someone, you probably want to just jump on a call with them anyway.
Furthermore, a system like this, with its extreme level of privacy (and the fact that you, at least at the moment, need a Go toolchain installed locally to even use it), seems to be tailored for a pretty specific kind of audience. That audience is the kind that values, and probably requires for their own personal safety, privacy above all else. 37 seconds of latency seems like a pretty reasonable trade off in that case.
How do you consider that in the threat model of the research paper?
How would you say your privacy + tech measure up against Signal and WhisperSystems? I love those folks and what they build and have been using Signal primarily for texting for a while now.
Also the messages are stored in plaintext:
https://github.com/signalapp/Signal-Desktop/issues/1017
They say it's a non-fix cause you can use full disk encryption, and honestly that's what I do anyway, so I'm not as bothered.
I ask because the 2M (concurrent?) users would be a very small limit in a hypothetical whatsapp/telegram/etc replacement.
So my question is not a critique, but an honest question. I imagine either this is purely research, or that 2M limitation is intended to be setup for communities, where you'll have many 2M instances running. Though, many 2M instances running seems prone to isolating one group of individuals.
Thoughts?
Pardon my ignorance here, so how is something like my IP hidden from the centralized server? I would assume "strong metadata privacy" would include the most obvious metadata, IP, and keep it from the server like Tor which they compare against.
Someone watching all traffic will know that you're using Vuvuzela, but won't be able to figure out who you're communicating with. In Tor, generally if someone can see all traffic they can rapidly trace communication links-- it's encrypted, but the fact that you send packets and induce a chain of a few other packets to the target is a dead giveaway.
Noise to thwart traffic analysis is wholly unrelated to endpoint obfuscation.
`Failed to generate new Alpenhorn client: fetching latest dialing config: config expired on <timestamp>`