Egregoros

Signal feed

Timeline

Post

Remote status

Context

12

@pelle @xgranade

whatever #signal's reasons are for badgering users for a #PIN, it's clearly a design choice they made, because other secure messengers don't do this.

The choice is either:

  • Periodically ask people to enter their PIN, or
  • Deal with people complaining that they forgot their PIN and are locked out (or, ideally not possible):
  • Provide an insecure way of recovering an account after you are locked out.

The PIN entry UI looks nothing like an incoming message.

@xconde

> forward secrecy

Autocrypt v2 later this year includes it (and PQC fwiw) with a time-based ratcheting system but also:

Jesus christ this is such a meme. PFS is useless unless you ALWAYS USE DISAPPEARING MESSAGES otherwise there's a plaintext copy still sitting around for an attacker to read when they get control of your devices.

e.g., Signal's PFS was completely broken on iOS for years because the message contents leaked into the Notifications database and were able to be extracted from there. Right now it's broken on MacOS and possibly all desktops because they don't flush the SQLite WAL logs frequently enough so copies of your messages can be extracted from there.

But yes it will get PFS though it's practically useless in the real world because nobody's recording all network traffic and trying to decrypt it later after they recover a key. If they can recover a key, they got control of a device from one of the parties in the conversation. If they have the device, they have your entire chat history. Game Over.

> Also note that Delta chat is not suitable if you need anonymity.

Why? What metadata are you referring to?

Replies

1
@xconde it all depends on various factors.

If I'm in the USA and my relay is in the USA, the gov can seize the server / monitor it pretty easily. If they gain root access to the server than can see the client IP addresses associated with an email address.

If I choose a relay server outside the USA, the gov can't see as much other than my IP address connecting to the server.

If I have multiple relays on my profile, I can just flip between them at will

I can choose to delete/create new addresses on relays as often as I want. (I'm hoping this will be automated soon)

If myself and my peer are sharing the same relay server, whoever compromises that server can see the client IPs of both parties.

This is why it's important if you are sercurity conscious to make sure that

1) you use relays outside your legal jurisdiction

2) you regularly change your relay addresses

3) you and the party you communicate with intentionally choose different relays so a compromise of one relay doesn't expose client IPs of both parties


but that's not really a high bar for someone who is especially security conscious. It's pretty easy to do.