What happens if Twitter gets encrypted DMs?
getsession.org
getsession.org
I tried it, I was interested in it, I always like to try new encrypted messaging methods. I like blockchains, but I don't like when one is shoehorned in when it is unnecessary, and I'm especially wary when a project with very little original development includes blockchain stuff, scams abound.
https://safecurves.cr.yp.to/#:~:text=The%20following%20table...
In this case the blockchain is used to incentivise the people running the routers. If you force them to stake funds then you ensure you have enough good actors to prevent bad actors from spying on your messages
How does Session compare to Matrix? Why another encrypted chat app that doesn't federate?
My understanding for matrix is that a volunteer hosts a server which clients can connect to, and that server acts as router to other servers which will forward it onto the destination.
In sessions case the servers (Service nodes) are incentivised so they are not volunteers, and clients can connect to any of the service nodes. Messages get onion routed to a group of service nodes known as the users "swarm" and when a user wants to receive their messages they similarly request them from the swarm.
There are likely pros and cons of both implementations. Matrix you call federated where as session is decentralised, which is a fairly significant difference. Sessions infrastructure mitigates things like the federated servers knowing the IP address of the client, clients having to trust the first hop, and metadata leakage to the federated servers.
You do realise that Signal also has a blockchain / cryptocurrency project associated with it as well? [0] Which makes it no different to Session.
> I like blockchains, but I don't like when one is shoehorned in when it is unnecessary, and I'm especially wary when a project with very little original development includes blockchain stuff, scams abound.
Exactly. Just like how Signal is doing the same by also shoehorning another cryptocurrency called MobileCoin? [0] Which basically enables scammers, criminals and hitmen to encrypt and hide their payments and also use Signal for their illegal activities?
This is the road to hell with encrypted blockchains and private cryptocurrencies and what Signal is no different to Session.
[1] https://support.signal.org/hc/en-us/articles/360057625692-In...
I think session has some advantages over signal. Such as onion routing, not needing to interact with centralised servers, and not requiring a phone number.
It all depends on what the key material is protected with at that point. If it's something provided client side and is transmitted securely, and used blindly, then it would work. Anything short of that would probably trigger my curiosity.
Edit: This kind of statement also needs to b prepended with who you're trying to protect yourself from, because that entirely changes the game.
Edit: There's also key exchange (and derivation) that could happen and impact the effectiveness of this process.
At this point the same entity controls both key distribution and the messaging channel, so information-theoretically it may seem that encryption becomes pointless because it’s very easy to perform a mitm attack. However, since any user can check their keys (at least in theory), the service cannot mitm _every_ conversation. This prohibits mass surveillance which is good enough.
The goal as I imagine it is to go from "Hundreds of Twitter employees can definitely access my messages today and anything I've sent and received up until now" to "Twitter will likely need to perform a MITM attack to read my messages starting from the moment when the attack was performed. Maybe they have a secret backdoor, but it's probably too valuable to use on my cat photos".
It would only take a couple of people I'm key positions to accomplish it.
No prizes for guessing entities that fit this description.
Encryption is the least of the things, all that means is that two of my devices probably won't see the same conversations.
I value privacy & security personally, and want Signal to succeed, but any compromise to UX in the name of privacy & security is going to make it impossible for Signal to compete as a mainstream messaging platform where network effects are paramount.
My point here isn't that Signal is perfect, just that the implementations by Signal and others shows that support for e2ee DMs on multiple devices is solvable. Teams can decide what their users need and how much flexibility is worth supporting. A public company of Twitter's size is clearly capable of solving this for some broad set of use cases.
A significant % of Twitter usage is through the website (either twitter.com or tweetdeck), which means the decryption would all have to happen in javascript in an effectively untrusted context - it doesn't even have the moderate protections offered by a chrome app/extension, and there's no clean way to securely store encryption keys for a webpage (afaik) without the aid of something like a Yubikey or Windows Hello. Secure cryptography in the browser is still (generally speaking) adjacent to a joke, and the idea of doing it in Twitter.com - a very complex website with a huge attack surface that gets loaded into iframes/popups and targeted by various extensions - is probably exciting to people looking for easy ways to claim Twitter's bug bounties. There are lots of other factors that will make this difficult but as long as the core of your product is a webpage with a history of severe quality issues you're basically using encryption for branding, you're not going to protect messages from anyone except perhaps disgruntled customer service staff.
That's ignoring the UX issues as well - when Line rolled out E2E encryption for messaging, they had to coax every user into enabling encryption and authenticating all of their devices to have access to their personal keys, so you had a patchwork of encrypted and non-encrypted conversations. And now if I lose my primary device (the keyholder) there's a convoluted process to attach new encryption keys to my account and the only way to recover my DM history is from a backup.
Am I supposed to believe they'll convince every Twitter user to jump through all the hoops to enable e2e encryption for DMs and manage encryption keys securely? Absolutely not. They'll have to do a ton of work to provide a comfortable user experience, at which point it'll be trivial for an attacker to get their hands on the encryption keys if they already had access to DM content.
First, they already have all the metadata they could potentially want, the message contents itself is virtually nothing. I'm quite sure they're even logging keystrokes in their website for autocomplete/analytics/advertisement/whatever purposes.
Second, they control the entire platform, including the code you would be running to encrypt/decrypt the messages! What would prevent Twitter from sending a specific party a special version of their JS that sends an obfuscated unencrypted copy of your messages to the mothership?
All this conversation is just security theater..
I'm glad you asked.
This is exactly the same problem that WhatsApp have been trying to solve for their web app, and they came up a browser extension called meta-code-verify[0] which checks the hash of the code received against an external append-only log. The extension only supports the WhatsApp site so far, but should be flexible enough to support others that opt into it.
Of course ideally this approach would become popular enough that the technology would be integrated into the browser itself, so that users wouldn't need to install the extension at all. I also hope that ProtonMail push for this too, since they are subject to the same threat model and care about open source security.
meta-code-verify is itself vulnerable to the trust chain. You trust Mozilla/Chrome not to alter the version you install from their store. You trust that GitHub isn't going to pull a swifty on you, or Facebook. You trust that the server hosting the append only log hasn't been unknowingly compromised, or the interpreter, or your machine, etc. ad nauseum.
Indeed, you trust in your computer to display the right hash, and to compare them correctly.
What's more is that this browser extension is useless in the context of this thread, because, as the grandparent post points out:
> A significant % of Twitter usage is through the website (either twitter.com or tweetdeck), which means the decryption would all have to happen in javascript in an effectively untrusted context - it doesn't even have the moderate protections offered by a chrome app/extension, and there's no clean way to securely store encryption keys for a webpage (afaik) without the aid of something like a Yubikey or Windows Hello. Secure cryptography in the browser is still (generally speaking) adjacent to a joke, and the idea of doing it in Twitter.com - a very complex website with a huge attack surface that gets loaded into iframes/popups and targeted by various extensions - is probably exciting to people looking for easy ways to claim Twitter's bug bounties.
Are you saying "No one should ever use a computer or phone because it might be spying you"? Every time someone uses Twitter they are using technology to solve a social problem (e.g. "I want to know what people I care about are talking about").
You're right that ultimately some unavoidable trust decisions have to be made, but with open source software (and multiple reviewers with hard-earned long-standing reputations) those trust decisions become even easier to make than "Do I trust my government not to illegally wiretap my phone call?".
> Secure cryptography in the browser is still (generally speaking) adjacent to a joke ... probably exciting to people looking for easy ways to claim Twitter's bug bounties.
If you think that secure cryptography in the browser is a joke then feel free to earn $10,000 by hacking ProtonMail.[0] You'll be laughing all the way to the bank, and actually helping to improve the security of millions of people.
[0] https://protonmail.com/blog/protonmail-bug-bounty-program/
Direct this to OP, not me.
Also it's a bridge/bot friendly platform and Maubot is great.
Im a huge fan of matrix and use it daily. Just to make that clear upfront. If you read HN you should use it.
I don't think it's ready for non-technical people. The federation part still causes issues. Occassionally messages get stuck etc. I would not feel comfortable telling my mom to download element to text me.
Also since the protocol is http, a friend of mine lets his servers send him notifications about cronjobs by just curling an endpoint. Lots of things you can do with it.
I know such things are possible (it works for me) but many people get themselves in a horrible mess.
But yes the client validation and key exchange is something non technical users don't grok :( Even though they've clearly spent a lot of time making it as easy as possible.
(As I wrote the above phrase, I realized that I could have abbreviated it to "tech journalism." Sigh/ugh.)
https://www.pocket-lint.com/apps/news/apple/160548-eu-s-digi...
> (...) chat apps, such as WhatsApp, Facebook Messenger and iMessage, will have to be interoperable with each other and competitors.
The same NYT and WaPo writers who have been writing attack pieces on Elon Musk for the past month will write about how horrible it is that people can communicate in private and how horrible their communications might be. Maybe a few EU politicians will make some threatening noises about banning Twitter, as well.
https://www.reddit.com/r/privacy/comments/nl8sdb/im_suspect_...
(Also can we please have a standard for messaging, every app cooking up their own protocol and not working with anything else is getting embarrassing.)
If everyone in a democracy agrees that "governments would never allow" large companies to implement end-to-end encryption, then, as a result, governments never will.
Also, some large companies do offer it, notably Meta and Apple. Apple offers a backdoor in the form of unencrypted iCloud backups. And Meta may also offer a backdoor to the US government, but they also might not. And there are at least a few large governments they don't appear to offer a backdoor to, as evidenced by Meta executives getting arrested for contempt of court in e.g. Brazil.
Twitter encrypting DMs is definitely an improvement, just as Twitter adding SSL was an improvement.
Security and privacy ultimately depends on threat modeling. Any given improvement can make the difference between the suitability or unsuitability of a tool for a given threat model.
And since peoples' threat models are extremely diverse and always changing, adding e2ee to a service of this scale can have a big impact on the security, privacy, and safety of many Internet users.
So some power has clearly been given up. Not willingly. But still it has.
And in the Snowden leaks you see that even the NSA had problems with tools like Tor and Tails.
Granted that was a decade ago, but there's no reason to believe that work by privacy activists to promote adoption of practices like SSL and START-TLS, or tools like Signal, has not had some impact on the cost and availability of mass surveillance to governments.
Highly doubt Twitter can pull it off and that they would manage to capture that all-important Trust.
Our software changed it because https://getsession.org/blog was listed as the canonical URL.
At best, for secure messaging I would expect someone to use twitter DMs to arrange a switch-over to a platform like Whatsapp or Signal
At first, only a handful of sites implemented SSL for all their pages, but eventually a critical mass of sites did it, and at that point every major site had to do it.
To make e2ee as ubiquitous for messaging as SSL is for browsing, we'll need a similar dynamic where it becomes standard practice, and each major site that adds it is a big victory.
Also, Twitter might have a smaller userbase, but journalists and political figures are among its most active users, so the social impact (e.g. to the health of democratic governments) of protecting the privacy of Twitter users might be on the same order as that of protecting the privacy of WhatsApp users.
If some small open source communication tool that was important to Hacker News readers added end-to-end encryption we'd all be cheering, no? So why isn't it a big deal (in some sense at least) for Twitter to do it?