Your Anonymous Posts to Secret Aren’t Anonymous After All
wired.com
wired.com
The app is being extensively used to bully people - non-authorized pics of naked people, messages with ofenses and etc. It was covered all over mainstream media and there is a consensus that it was a right decision (in this kind of press I mean).
Edit: here a TechCrunch about it: http://techcrunch.com/2014/08/20/brazil-court-issues-injunct... It was submitted to HN but got no comments or upvotes: https://news.ycombinator.com/item?id=8202444
When will these companies learn that "if you build it (the infrastructure for censorship/surveillance), they (the governments) will come"? It's inevitable, and they should know better by now.
Only if you somehow consider the app store and mobile infrastructure a public good, which is most certainly is not.
There are open source/decentralized options that you are free to use.
I guess by "mobile infrastructure" you can extend that to "every phone," in which case why not remotely remove programs from PCs as well? Why not just say outright that the coalition of your local government plus Apple/Microsoft own your computer, rather than you?
I can't tell if you're being sarcastic and advocating free software, or openly advocating for autocratic computer systems management.
(This is of course what RMS has been saying for literally decades, but for the people on HN who disagree with RMS, ... told you so.)
IANAL but it seems you have given permission:
Notwithstanding any other provision of this Agreement, Apple and its principals reserve the right to change, suspend, remove, or disable access to any App and Book Products, content, or other materials comprising a part of the App and Book Services at any time without notice. In no event will Apple be liable for making these changes.
http://www.apple.com/legal/internet-services/itunes/us/terms...1. Get a Nexus phone.
2. Flash to a custom ROM.
3. Don't flash Google Apps.
4. Sideload APKs or use an alternative store.
5. Enjoy.
The reason you can't have everything is that the app devs and most people prefer the store situation. If this is a particular problem for you, there will be sacrifices.
Stop letting game-riggers dictate your view of reality.
I am basically saying that the market can support both but is trending toward user acceptance of the latter. All those EULAs out there are the agreements that make all this possible. If people rejected those terms then we wouldn't be in this pickle.
Where does the article say that?
It's plausible that future iterations of smart phones will make progress on this "feature", should it become a more stringent requirement for shipping in Brazil.
This is been public knowledge for as long as the App Store has existed: http://www.macrumors.com/2008/08/11/30-million-in-app-store-...
Jailbreakers found it almost immediately: http://forums.macrumors.com/showthread.php?t=549203
http://fortune.com/2014/08/07/we-tested-secrets-anti-bullyin...
Sounds like ask.fm all over again. Afaik there were news stories about people getting bullied actually killing themselves on that site so I have no problem with apps being removed if they fail to moderate this stuff correctly.
There is also a Tumblr called "Os Melhores Secrets" (The Best Secrets) which publishes secrets (no NSFW pics on the blog). If anyone speaks Portuguese, you can get an idea of what kinds of things are being passed around, though certainly there are worse secrets (w/ pics) on the app's network.
I find the gossipy aspect of Secret entertaining, occasionally useful, and maybe 25-50% reliable. It serves its purpose. I don't post anything to Secret, though, and I would certainly never post any of my own secrets.
I share the concerns over cyberbullying, libel, and other potentially dangerous issues with any service of this nature. I don't think banning a class of apps altogether is the right solution. More likely, it's a flagging system, combined with a very active moderation policy on Secret's part. There will come a time -- maybe it's triggered by government regulation or banning in some regions; maybe it's triggered by lawsuits in others -- when Secret decides it needs to get serious about moderation. IANAL. But I can't imagine that, in a hypothetical libel suit, Secret can mount a strong defense right now.
In your Google example, Google is in no way responsible for the content of someone's blog post. Google is not the publisher of that content, and is debatably not even the distributor.
At least when US politicians try to ban something, they generally try to have a good bullshit excuse, like terrorism or "national security".
I had never heard of this app before, but reading the article, as soon as they got to describing how it works (you give it emails/phone numbers of your friends, you only see secrets from them), I correctly guessed what the attack would be.
Now, maybe it wouldn't have been obvious to me without the setup (there's been a successful attack, and now we're going to describe how Secret works like this, setting you up to understand the attack).
But if Secret has security engineers, intimately familiar with their system, and trying to identify possible attacks -- how could they have not identified this? It makes one think the bug bounty program IS their security program. Which is probably true of much software, but this is software focused on secrets!
On the other hand, maybe it just seems that obvious in retrospect? Apparently they have already given out 42 security bounties, and this one wasn't identified until now, so I dunno. It sure seems obvious though.
I installed the app once to check it out. The first thing it asked for in order to proceed was an E-mail or phone number. Again, THE FIRST SCREEN REQUIRES PERSONAL INFO. It should be plainly obvious to anyone who gets past the first screen that your use of the app is not anonymous.
It was a known attack, their defense against it is dummy account/bot detection systems, and they claim that they were broken somehow due to an infrastructure upgrade which is why it worked for this guy.
For example, remember that seriously hideous post to secret regarding a prominent GitHub employee?[1]. The post has since been removed, but a determined GitHub employee who could see that post could over time defeat the dummy detection with a method similar outlined in the post. Just continue to create new accounts on Secret and iterate on the friends in your contact list the way that git bisect works. Create an account with half your friends and see if the message pops up. If so, create a new account with half that list, and continue until you reach 7 and rotate in users you know aren't responsible. In the end the person who made that horrible post will be revealed.
[1] http://recode.net/2014/03/15/prominent-github-engineer-julie...
Secret don't stand a chance if that is the basis for their defense model.
Figuring out who is real or not is one of the current big problems with a huge opportunity. Were someone to figure it out, they'd do something in the ad industry and make billions before building an app like Secret.
Going back, it says.... they had automated attempts to identify bots like this in place, since May when Russian hackers attacked in the same way. The implication is not before then.
Yeah, this does not make me more confident in them having any sort of a security program whatsoever.
So people just have to feel 'safe and in control,' rather than making sure they are actually safe and/or in control? It sounds like an admission that the whole anonymity thing is just a marketing gimmick: as long as you have a name like "Secret" and make people feel like they're safe, they'll share whether or not they have strong security at all.
Post Snowden, there's an obvious market for "secure" and "anonymous" apps and startups, and the appearance of security is usually cheaper, quicker to implement and less annoying for end users than the real thing.
Having a bug bounty is nice and obviously security is hard even when you do try, but even that can be used to give the appearance about being aggressive about security while still making sure their network is just broken enough to return whatever value there is in being 'social' (which is usually antithetical to being secure or anonymous.)
But more seriously, if there are bugs that can reveal the poster's identify in the first place, then it's not anonymous. It's very easy to make your servers not record any identifying information along with the text or pic. It's also easily possible to strip any exif data from an image. Clearly for usefulness/monetary value, the identity of the poster is being recorded.
Before you even sign up it's quite clear that there can't be anything anonymous about this at all. It delivers plausible-deniability at best.
Their claims may be fuzzy. People may not be paying too much attention when they sign-up or use it. But they're quite clearly not trying to make an actually anonymous secret sharing site.
"Social Network A wants users to feel like they control their privacy settings."
"Online Store B believes shoppers should feel like their credit card information is secure."
"Cable Company C's service goal is for customers to feel like their support issues are being addressed."
mindblown.gif
As was pointed out when Secret launched by many, the model can never be secret. It has been interesting to watch the company feel their way around in the dark to a conclusion that anybody in infosec or who understands security/anonymity could have told them before they launched.
When you don't know that many people who would even ever be on Secret, which is true right now about anybody who doesn't work in Silicon Valley, then it becomes almost completely transparent just because you know who your friends are. The anonymity model is a joke outside of the tech bubble.
He could do it by snail-mail: http://postsecret.com/
Simply saying, "Use your brain and solve your problem." To a mental patient is very insulting and extremely marginalizing to their condition.
Following your logic, Secret is actually encouraging the very practice you called out as abhorrent.
If Secret staffed trained professionals to provide anonymous help, that would e different. They don't.
It's also sometimes the only help that people will ever get. Talking to people about their problems can't be declared as forbidden or irresponsible unless mediated by a doctor. That's both unrealistic and it implies an initial unqualified diagnosis over the internet by a stranger to decide that a statement constitutes mental illness rather than a simple sharing of internal states - making an absolute statement like the one you're making self-contradictory.
For example, I'm upset about a discussion that I had with my sister the other day. It makes me sad, and slightly worried. Should I continue to talk about it, or should I consult a doctor? If you answer that question, is it a diagnosis? Should all inter-human communications be routed through mental health professionals just in case?
If you're talking about serious mental illness, which was the entire point of this comment, then it needs to be handled by professionals or at least someone with basic training.
edit:
[I pick out one of the posts promoted to Secret’s homepage, and read it to Byttow over the phone: “At work I’m being given more and more responsibility. Silently I’m struggling with mental illness.” Does Secret provide enough anonymity for that user?
He turns the question back on me. If there was no Secret, or an app like it, where would this anonymous poster go for catharsis? Where would he share his struggle with mental illness? Facebook? Don’t make him laugh.]
Clearly, the interviewer and CEO David Byttow are talking about mental illness. They are not talking about someone having a bad day or even suffering from mild, common depression. They are talking about mental illness, and I am reacting to their discussion of mental illness. My original point, short as it was, is that someone with an actual mental illness ought to seek actual treatment rather than the faceless world of something akin to Secret.
This isn't to say that talking on Secret (our a diary for that matter) is a terrible thing. However, the assertion by Byttow is that his service provides a legitimate outlet for someone who may need real help and may pose a danger to themselves or others.
Perhaps the meaning of "mental illness" is where we differ in the discussion? How about I reveal a "secret" which is quite true and we see where this goes...
I do not know you, nor do you know me. I do not know if you or people you know suffer from mental illness. You do not know if I or people I know suffer from mental illness. I do not know if you or people you know have injured themselves or others as a result of their illness. You do not know if I or others I know have done likewise. However, I will reveal to you, that I have indeed known more than one person who suffered from serious mental illness. Some of these people have injured themselves and others as a result of this situation. Of this group, some received professional help. Most did not. Those who did not chose instead to keep it to themselves or to talk to unqualified people who had lots of supporting words but had absolutely no idea what they were actually dealing with.
The results? In two cases, suicide. In one case, murder. Another particular person has conducted a lifelong campaign of mental and physical abuse against family members resulting in another person's suicide. In these four cases, could the issue have been resolved with proper assistance? I think so, at least in three of the cases. Would something like Secret help? Unlikely. These individuals needed real help.
So, when I say that it is dangerous, it's because I have witnessed first hand how dangerous mental illness can be. It is dangerous for professionals and lay persons alike. It is dangerous for the individual suffering from the affliction and for those around them. Is this always the case? Of course, not. Perhaps your experience is different. I certainly hope so because it is a horrible thing to witness a person you know suffer in this manner and then cause injury to themselves or others. I wouldn't wish it on anyone.
I guess that most people don't know what a mental illness can be.
Perversely, many of the people with conditions that hamper them from earning much are the most in need of care. Lacking an "official" means of support, people are forced to find new ways to seek out help.
[1] This isn't exactly true in the few states that haven't expanded Medicaid eligibility as provided for in the ACA, since in those states there is a gap.
I'll accept the downvotes for my ignorance, but I feel like underlying message is still true: there's undoubtedly a lot of people without coverage still and those people need to seek help elsewhere.
Or there's always 4chan.
Even in the app space Secret hasn't cornered the market, there's Whisper for example which doesn't ask for your email address and doesn't show you your friends' posts. It's ridiculous to claim that Secret is the only option for that person.
On the other hand, if we're talking about an adversary with a more limited capabilities - maybe he can access only 50% of the computers in the world and that cannot crack encryption at will - Than there are papers talking about theoretically sound systems that can give you anonymity with very high reliability.
On the other hand I guess the whole point is knowing your friends secrets, not just people secrets.
Everything sent over the wire to their apis is encrypted, but using an easily reversible fashion. The encryption key is a combination of a static salt and the user's session id. The session id is also sent to the api as an http header, so it's pretty easy to decrypt that anyway.
n.b. I wrote the windows phone app
To even approach feasibility you would need to give people the power to view and approve emails that are following them. Then social circles would naturally form within the app along with a form of self governance.
.@getsecret Un-veiler-service:
1) Empty contacts
2) Re-add incrementally
3) Identify "secret" posters
4) ??
5) Profit
Seems way too obvious.
You need at least 7 contacts that use Secret, but approximately half (or 1/3 or 1/4, whatever gives the best experience) of your messages will come from people NOT on your contact list. That is, most of the posts will be from people you don't know. But enough will be from your contacts to keep it personal...
So that would kind of defeat the purpose of the "friends" stream entirely.
What they could do instead is only share secrets if you have N contacts in common. This solves the bot problem - the target will not add the bots.
You could also have some sort of threshold before showing secrets as well.
That said, I've never used Secret so this may or may not work. It'd be interesting to play with the Secret data to see how the social circles overlap and what kind of traffic patterns they see.
To put the attack in contexts, imagine all the epitaphs you've heard playing FPS games online, but much worse. Then imagine having those slipped under the door of your home, scrawled over a Polaroid of you sleeping in your bedroom. Now imagine that you have no safe place to complain about this invasion of your privacy, but that you have to keep it constantly bottled up in yourself. That's a mild version of what these developers are facing.