does it mean if a lot of Simplex users band together and sift through all their local identities they can connect the dots?
does it mean if a lot of Simplex users band together and sift through all their local identities they can connect the dots?
What makes it work afaict is the combination of:
- there are still queue (inbox) IDs
- key (and (just initial?) queue ID) exchange out of band
https://github.com/simplex-chat/simplexmq/blob/stable/protoc...
So messages are still delivered to an identifier, it's just that every user has tonnes of identifiers (per contact/group), there's no server tracking and handling their exchange, and possibly they rotate via encrypted messages once established anyway.
Exchanging out of band gets you the secrecy, and having one per-chat protects you from a contact turning out bad/leaking/compromised - it's fine that they have metadata about their own chat with you, because they have that & the plaintext anyway.
An identifier is something that relates to more than one thing. A connection is its two endpoints. It is those ends.
Who is at each end is unknown and cannot be known without resorting to grabbing all users devices.
Having not used this chat I don't know how easy thing might be but I do remember, before mobile phones were a thing, being able to remember at least 8 phone numbers that I used to call regularly. Certainly if it called for it you could do this with simplex?
In phone A, you will have B's contact stored locally, let's say as "Dan".
B, A, "Pedro"
C, D, "Dan" (yes D is also named "Dan")
D, C, "Olga"
What do you look for?
Everyone can see and read the cipher text on all the papers, but each of the 4 people can only decode the things meant for them.
So, if that's how it works, you could certainly learn who was talking to who if you had access to all the devices. But access to one device only shows you what came and went to the device, but no data about which of the other three users were involved in those reads/writes. You would have to gain access to each device, in turn, to prove whether it was in contact with the first device.
I specifically said a lot of users. A lot is the opposite of one. Imagine a lot (>40% of total users) of impostor devices acting in accord to deanonymize some of the X and Y. Is it vulnerable to that. Like apparently Tor is.
You would at most be able to deanonymize a certain percentage within the impostor network itself. Kind of pointless.
Physical access of devices is the only way to have some chance of deanonymizing some of the users (always less than number of devices you have access to).
That’s my understanding, but the maker of this thing is here, and maybe can respond better?