The most backdoor-looking bug I’ve ever seen (2021)
words.filippo.io
words.filippo.io
I am moving my newsletter archives to my blog, and the issues must have hit the RSS feed, even if the pages are not well annotated yet.
The unfederatedness of Signal seems to be a HN phenomena. Though someone did make a feature request that could be something that's kinda middle ground and seems more in line with Signal's philosophy[0]. Personally I think Signal works so well because you don't have to worry about servers, domains, and whatever. It just works. Exactly like texting. It's for the masses, not us nerds. I want to see Matrix grow, but I don't see it being usable by the masses anytime soon.
[0] https://community.signalusers.org/t/signal-airdrop/37402/8
No, it's as huge issue. You cannot trust yet another walled garden. Especially when there's no way to verify the servers.
Signal is vulnerable to timing correlation. An observer on the servers or on network devices nearby can easily infer the social graph of users: at what time they communicate, with whom and how often.
This is not a minor issue. Quote from the former CIA director: 'We kill people based on metadata'.
Wrong. Do they all use the very same server? No, and therefore timing attacks are still there.
> it's very clear that Signal is the best game in house
Wrong. There are protocols designed to provide good security in the first place, like Briar.
> Timing attacks aren't solved by federation btw
Also wrong. Federation makes timing attacks very difficult, especially when servers are delocalized because it increases the amount of access required by any global observer.
I'm going to stop replying. You clearly are not familiar with the topic.
Just look at how much information they hand over to the feds:
https://signal.org/bigbrother/cd-california-grand-jury/
I'm not sure what you mean by walled garden, but I assume you mean that you can't setup your own servers and join the network? What's stopping a federated network from forming a cartel and blocking small players, or servers they deem morally objectionable?
I've never really understood the argument. Just because someone hasn't done something doesn't mean it is a walled garden.
That's not true, see the other reply.
Well, this is a good question. Telegram is an allround day-to-day messenger with channels, massive groups, broadcasts etc that also works as a login provider while Signal is a research project to create a secure messenger and also something about crypto coins ;-)
Yet, while Telegrams encryption scheme has left a lot to be wished for and their communication has been arrogant:
- Signal has had more than one really bad security problems like remotely exploitable XSS in desktop app and that rather long time span when Signal sometimes sent images to wrong recipients
- Meanwhile Telegram hasn't seen such problems since they were starting out
And WhatsApp? Why it is even mentioned in a discussion about secure messaging after all the blunders they've made I don't know:
- Sending deliberately unencrypted backups to Google with the intention that Google could datamine them.
- Lately there has also been talk about "filtering content on the edges". So much for E2E-encryption when the endpoints report your content through a separate channel.
I believe in Signal and E2E-encryption, but, as I have said a number of times and a number of ways before:
There is a lot more to security than just cool algorithms and buzzwords.
All the E2E-encryption in the world doesn't save you when the service provider gets away with the abuses WhatsApp have been caught red handed with and no algorithm saves you when you can get remotely exploited by receiving a message.
Some might think I am extremely pro Telegram. I have one place where I want a lot less of it:
It really scares me when I see police use it. For any kind of communication that needs to be super secure: stay far away!
You mentioned only unencrypted OS backups (which were a major issue, but also industry standard, affecting everything but Signal which takes a severe usability hit over it, and apparently fixed https://faq.whatsapp.com/general/chats/about-end-to-end-encr...). "Filtering content on the edges" is a whole debate but not something that ever materialized.
It sounds there's a list, what are the others?
They can't read message contents.
There is no point of even looking into Telegram's code - it is not encrypted. Why would researchers waste their time?
Encrypted one-to-one chats is not really a feature. It is rarely used since parties need to explicitly request such session. And even than it's clunky as hell.
WhatsApp is a Facebook product and obviously cannot to be fully trusted. However, I'm still really happy that nearly everyone in my country is using something this secure. There's no point in having the perfect system if nobody uses it.
[1] Brazil politicians' Telegram 'hack' of 2019
https://www.wired.com/story/brazil-hacker-bolsonaro-car-wash...
[2] Iran Telegram 'hack' of 2016
https://www.reuters.com/article/us-iran-cyber-telegram-exclu...
[3] Israeli cryptocurrency executives' 'hacked' on 2020 including their Telegram
https://www.haaretz.com/israel-news/tech-news/.premium-exclu...
[4] Moxie Marlinspike of Signal app on Telegram
https://twitter.com/moxie/status/1474067549574688768
Hack is in quotes because all involve SMS interception.
They're a russian-HQ'd and staffed company which alone makes them suspect, and the government seems to have no problem with them, which doubles the suspicion given it's a perfect tool for anti-government groups and terrorists and if the FSB couldn't read everything, they'd be harassing the company, its founders, etc.
I consider myself an Internet Archive power-user; I spend hours playing with CDX queries, t̶r̶o̶l̶l̶i̶n̶g̶ trawling the archive for interesting tidbits that have been lost to time. I have spent countless evenings building scripts based on the internetarchive (https://github.com/jjjake/internetarchive) and iamine (https://github.com/jjjake/iamine) tools (along with a host of others).
I am utterly ashamed I had never heard of the /diff/ feature between pages until I read your article. Thank you for bringing this to my attention! I am continuously impressed by the work they do at IA.
EDIT: As an aside, I didn't realize there's no strikethrough option for text on HN. For anyone else who wants to hide their shame without ninja editing, I found this site which does the same in unicode:
I think your subconscious did just fine.
I'd say it was intentional, but that'd be a bald-faced lie.
In my headcanon, trolling is a slower, less directed process. So I might idly troll for bugs to fix on a bug tracker, rather than a trawl which would aim to gather everything matching some criteria.
I assume the reason is that the recipient of the truncated hash can validate that they've derived the same key without exposing it. This makes it way more straightforward to reject invalid keys. Truncating the hash is pointless but I get why they'd do it - it doesn't "hurt" since ultimately decryption will (hopefully) fail with an invalid key and this is just a shortcut to commit to a specific key.
Otherwise, a really interesting example of thinking "I'll add a nonce here, that'll make things safer!" and getting the exact opposite result.
Anyway, Telegram MTProto backdoored; this never was a surprise to anyone I guess.
It would be very difficult to prove the difference between actual incompetence and deliberate ineptitude.
I think that normally A and B would compare whatever they were using for long term identity and not the shared key they got from a DH exchange. So that would be the fingerprint of some sort of public key from some signature scheme. There is a tendency to throw away the results of the DH exchange as part of a forward secrecy scheme and the users would not want to have to compare fingerprints constantly.
Does Telegram do something different?
Edit: Sort of answering my own question. Apparently each secret chat is self contained. You are supposed to verify your fingerprints when you start one. If you start another one you then would have to check the fingerprint again. This suggests that Telegram secret chats are indefinite and can stick around for a long time. I guess that is one way to simplify identity management. That also suggests that the forward secrecy is per secret chat session. It only kicks in when you end the secret chat.
Maybe I should explain the problem I'm thinking (and I'm honestly curious if there is a solution).
Within one app I want to be able to establish contact with multiple types of people without revealing to others those identities (i.e. anonymously). If I use a username then my friends and family that have my phone number can see my username (similar to Snapchat). This also allows for cross-site deanonymization as I can't use that same username on sites like Reddit or Hacker News where I may actually want to establish private or group communication with other users. The problem here is that usernames are persistent and so identities will be linked (even if multiple usernames are allowed). I want to be able to connect friends, family, internet friends, and others without revealing any PII or letting others knowing who I've established contact with.
As I see it, there needs to be some zero knowledge contact initialization. How do we establish a (persistent) communication channel through untrusted platforms that do not reveal PII? And more importantly, how do we do this in a manner that is usable by an average person?
If you're a normal person and don't have the knowledge or drive to set up an XMPP server, I would say Signal is probably one of the best secure chat clients at the moment.
A lot of girls on dating apps prefer snapchat because they can just block the person and there's far smaller chance of getting stalked or harassed.
Matrix does not expose your email address or phone number to people you connect with, so you're a lot safer.
"never attribute to malice that which is adequately explained by stupidity."
Around security you have to assume "malicious until proven otherwise", unlike in law.
If that wasn't the case, then please instead ask for clarification next time - people are generally fairly forthcoming as long as you're not dismissive or intimidating (although it can be hard to tell what random strangers on the internet will perceive as such).
As to the explanation: I don't think anyone can claim to be perfect, and we all have to go through various learning phases (in various learning dimensions) throughout life.
Increasingly that process is on record, for most of us -- as it is in the linked article here. It's risky and could stunt growth to call people out for their failures; especially on platforms that have a wide audience. There are often ways to find more constructive, positive and healthy personal development.
Who's to say, really? Is any other environment much different?
In conclusion: I'm not sure whether I understand my original comment, either. It probably says more about me than expected, and perhaps to boost my ego further, I should follow my own guidance and walk away from that :)