Open and federated protocols and services should be our target. It is hard designing them, but if we could do that in the past, we should be able to do so today.
Open and federated protocols and services should be our target. It is hard designing them, but if we could do that in the past, we should be able to do so today.
TFA merely says: if you were gonna use PGP, use Signal instead. It’s a trade off. While we target these open and federated protocols, let’s not throw people who actually need encryption today under the bus.
So to the question of replacing email: unless all your email is currently PGP encrypted, you don’t need to drop your email just yet.
You don't need to drop email at all. If you trade protocol openness for encryption, you are acquiring technical debt. How long are going to do this dance of switching between instant messenger protocols? ICQ -> AIM -> MS Messenger -> Hangouts -> WhatsApp -> Signal -> ???.
Open protocols (open in specs and federated in access) are the only way to stop this madness.
(I think a lot of useful Signal properties are much harder to do with federation, but that’s a subtle enough problem that it warrants a long form post, not a HN comment. I agree that ceteris paribus federation is better than not—but c.p. is doing a lot of work there :))
Those who value the freedom of choice should push for Matrix before Signal becomes the de-facto standard and is acquired by one of the tech giants looking to lock down control of communication.
This is either misinformed or disingenuous: https://www.hello-matrix.net/public_servers.php
Synapse is much better with regards to resource usage these days, though. The RSS of my instance is 355M right now and the CPU usage is hovering around 0-10% (15-min server load ~0.5).
"[...]use the Services to store or transmit any inappropriate content, such as content that: (i) contains unlawful, defamatory, threatening, abusive, libelous or otherwise objectionable material of any kind or nature" [1]
(My emphasis)
1) we use it as a slack replacement 2) git integration 3) stellar Blockchain payments 4) encrypted file sharing 5) great system for key management
Do you seriously believe that ALL communication working through a single proprietary non-federated service would be a good thing? !
Let go of the idea of “good”, nothing is currently good. Everything is terrible. The only thing that’s “good” is a federated, open, and secure in practice protocol (I.e. not just for people who use it properly, but for people who is it full stop. Like HTTPS, for example.) Today, we don’t have that. Let’s work towards that. Let’s make it happen tomorrow.
But today: federated or secure, pick one. (See TFA)
Meanwhile , there are people , today, with a real need for encryption. (See TFA) A need that transcends our long term plans. These people look at what “techies” do and say, and they imitate it. That’s the way of the world.
It is currently PGP. That is not secure, in practice when used by those people (see TFA). Therefore, we need to stop using PGP, use Signal for now, until we have an actually good solution that is better than Signal and PGP.
That’s the summary of the article.
Nobody is talking about replacing all email. Nobody says the status quo is good. Heck, nobody is really arguing for Signal, as much as arguing against PGP, and signal winning by default. That’s all.
We’re all on the same side here, guys. It’s just a matter of temporary compromise.
I get that, and I actually agree with you on almost this whole comment. The problem of the temporary compromise on Signal is that I don't believe it is temporary. Signal is actually good enough to prevent the transition to the optimum. Being non-federated, Signal will always have a single point of failure, but this will get masked until it is eventually exploited.
There is not a federated messenger that provides the same security as Signal.
Your argument reduces to (for the user segment under question) “don’t use electronic because I value federation”.
I value it too but that seems incredibly selfish.
Actually, there are federated messengers that provide better security and privacy than Signal. Yes, XMPP ones. They might not have the same convenience yet, yes, because they are not tied to phone numbers, but don't even get me started by trying to say that tie to phone numbers is a plus.
Actually, this phone number thing is the main reason why I find it hard to suggest using Signal to anyone who's life is on the line.
As far as I can tell, sealed sender leaks less metadata than omemo currently does, which makes tor etc. Mostly irrelevant. Plus, I'm not going to fuck up signal, while I will misuse Tor.
This is an important question, because cryptographic repudiation and secured metadata prevent most of the dangers that I can think of, but I might be missing some.
One example (from the article) is other people accidentally replying to your encrypted messages in plain text, including the entire reply history.
This is what TFA is about. PGP is not safe for people who actually need encryption.
> Purchase a modern android or iOS device and install Signal. Your communications are now secure.
Given the security provided by signal, why do I need to understand the message authentication schemes, private key management, keyservers, versions, etc.
> The simplicity and strength of PGP is hard to beat. Riseup.net has an entire section mostly about OpenPGP:
Given that, in practice, basically no one's use of PGP provides security or privacy beyond what I get when using Gmail or Outlook, I beg to disagree.
How in god's name can you claim that a 6 page article describing the ~20-30 steps to correctly set up a keyring (oh and then keep up your opsec for the life of your communication because pgp doesn't provide forward secrecy and the protocol makes it possible to transfer plaintexts unencrypted) is simpler than "Install signal, and send messages"?
And yeah, Signal will detect that and inform the other side that "security number has changed". At which point they'll promptly confirm the new one, because they don't understand its purpose anymore so than private key management etc - because they simply installed the app from the store, and expect it to "just work".
Specifically, it will say "Your safety number has changed...This could either mean that someone is trying to intercept your communication, or that <other party> reinstalled signal."
Even for a layperson, if they have reason to be concerned about a powerful attacker that's reason enough to stop.
Something like Signal is OK for most people, particularly if they trust the Signal company. But when things get serious you have to:
1. Know what you are doing.
2. Keep the device that is doing the encrypting as separated from the rest of the world as possible.
If this is the kind of thing you're resorting to claiming, we're well beyond reasonable forms of argument, and so I think it's safe to say that you agree that signal is better.
No communication protocol works on an air gapped system, and a modern Android or iOS device is going to be secure enough that you really don't need to use a special device for your messaging.
The riseup article doesn't mention anything about using a special device for your secure messaging, so I'm not sure why you think it's so important all of a sudden.
The article mentions Magic Wormhole, age, and Signal, IIRC.
I don't think it impacts ergonomics.
What federation does is:
a) Remove the single point of failure present in Signal;
b) Promote competition between service providers.
None of these can be argued against.
Note that I'm not defending we stick with email. I'm defending we shouldn't move to a non-federated protocol. That fixes one thing and breaks another. Choose xmpp, matrix, design a better messaging protocol, ... Just don't take a step forward when facing the abyss on the merits of taking forward steps.
It's helpful to compare secure messaging to medical software. If we were talking about the software that controls the radiotherapy machine, no rational person would would have any priority other than safety. But of course almost nobody interacts with radiotherapy software, and everyone interacts with messaging software, so it's hard to see the connection. But it is there.
Just keep in mind this principle is personal, not shared with you by everyone. For example, I distrust security by central organizations, like Signal.org. They're an amazing target for bad actors.