Delete.im: the forgetful messaging service
delete.im
delete.im
So I can't send this to people I dont trust and I have no way to guarantee that delete.im doesn't save my messages. What exactly do I gain from this over just clearing my local logs?
As as security person these 'forgetful' services really bother me because people tend to claim that they offer the world but there is no way to actually guarantee any of it. More importantly there _fundamentally_ isn't a way to prevent the other side from saving the message. Without end-to-end encryption there isn't a way to make any claims about what is stored by the service.
And before you recommend end-to-end encryption in a browser based service don't forget that we know exactly how those get MITM'd: When a warrant comes in you serve that person a different webpage with broken encryption/leaks.
This is the same rant I had about Snapchat, and the same rant I'll have about the next forgetful .* service. The only claim they have to actually being forgetful is a promise and you'll never see them stand behind any actual privacy claim because they cant and they know that.
tl;dr Please stop making 'forgetful' services or 'view only once' services.
I have an honest question for you HN: Do you not see these services as fundamentally broken? Would it be worth writing a long post somewhere breaking down exactly why these services are broken at best and bad in general? I'm deeply afraid that the public will start seeing these services as providing actual privacy and start using them as such.
Delete.im is not supposed to keep you safe from hackers or NSA. It's only to prevent sensitive data from lying around your chat history or emails. That's pretty much it. It's a completely different concept from snapchat and the others.
The point is that you don't actually offer me any more privacy than if I just used the 'Off The Record' feature of many chat programs or deleting my logs.
Are 'off the record' conversations deleted the second they fall off your chat history? I doubt it. Are delete.io messages deleted once the server started returning 'this message is unavailable'? I doubt that too. More importantly I can't verify if you delete them then or even at all.
Now my sensitive data is not lying around in my chat history or emails, it is lying around on your server. If my logs are only stored locally I can delete them. Likewise if I control my email server I can delete them.
How can I prevent sensitive data lying around on your server? Are you more trustworthy than my email? Why?
The comparison to Snapchat and friends comes from the 'limited number of views' or 'viewable only for a time' feature. These features are trivially broken at best and misleading to non-technical people. These are marketed as privacy features and they're a lie.
If you want to bill your service as a pastebin style service that removes files after a time then go right ahead, I will not have issues with that.
If you want to claim that those features are to protect sensitive data? Then I have a problem. Services built around working with sensitive data need to be held to a higher standard.
https://github.com/dokipen/crap.io http://crapio.doki-pen.org/
https://onetimesecret.com/ – also sends messages. Does not support images or view limits greater than 1, but does support requiring a password to view.
http://volafile.io/ – for sharing files. Create a private or public chatroom where you can upload files and they are deleted after 24 hours. See, for example, the Hacker News room: http://volafile.io/r/BCcsa6.
The developer also open sourced it so it can be integrated into an IT department's internal workflow if trusting him is too much. The command line tool is also a nice touch.
- open source, so you can (and should) host your own - encrypted on the client, only encrypted data is stored on the server. Key is "stored" in the fragment identifier [1] (ie after the #hash), so the server doesn't receive it, yet you can share the full url with who you want.
Obvious deficiency: the javascript to encrypt/decrypt is distributed by the server, so you have to trust it. Which is why you should install and use your own instance.
Side-effect of using client-side encryption: "burn after reading" is merely a convenience for the server admin so he can reclaim some disk space. You don't have to trust the server for this.
Oh, and it's only php, so installation is only unzipping.
[0] http://sebsauvage.net/wiki/doku.php?id=php:zerobin [1] https://en.wikipedia.org/wiki/Fragment_identifier
As the lovely named 'shittyanalogy' picks up on I think the use case here isn't for super secret messages or data you never want viewing. We've had people use it for coupon codes (first 100 get it) or your phone number so you don't have to post it publicy. We preach the mantra of 'don't upload things to the internet you don't want people to see'. This rule applies to snapchat, us & all the other services out there.
Not that it matters: pressing printscreen isn't exactly difficult.
https://delete.im/messages/retrieve/n0rLEeSsqX/
Edit: It says 'unique' views. I wonder if my incognito windows didn't fool it? Hopefully HN can make it disappear.
All of these "disappearing ink" apps are patently ridiculous, they all have demonstrated security flaws, and they completely ignore the analog gap problem.
What are people thinking when they decide to use this crap?
... "Oh cool, look at me, I am a spy... let me send you something sekret, tee-hee I am sure this other dude running this server is totally cool too so you can send me your sekrets back... tee-hee-hee... nobody will ever know"
So many god damned stupid fucking kids walking all over my fucking lawn these days!
I live with my girlfriend. My girlfriend's birthday is next week and I want to plan a surprise party. I send a message out on this thing instead of Facebook or email (where she might see it).
When the vast majority of people talk about not leaving a paper trail, they (rightfully) aren't concerned with third parties -- they're concerned about second parties. Snapchat didn't take off because people were trying to hide from governments, it took off because they were trying to hide from friends and parents.
Case 1: You delete my message once I read it Case 2: You simply report it as deleted once I read it(but keep it stored)
Is there any way for us to distinguish the two?
The more important part of my post was "What stops Delete.im from saving your messages?". What if you get an order from your government's legal apparatus to save my messages?
{
"success": true,
"seconds": 300000000,
"code": "20r5M5y3ec"
}[0] http://www.businessinsider.com/libor-instant-messages-from-i...
[1] http://dealbook.nytimes.com/2013/03/21/prosecutors-weigh-ins...
http://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_p...
This is useful for cases where you trust the person you are sending to (to not print screen, etc), and also don't care about third party knowing the message.
Security is a spectrum not an absolute measure.