Session be like
"We're metadata-resistant. Also, we recently passed the 1 million user milestone. Don't ask how we distinguish unique users!"
https://www.404media.co/email/9ee8f6a1-348a-4fb1-b1b3-30c8898d7581/?ref=daily-stories-newsletter
Session be like
"We're metadata-resistant. Also, we recently passed the 1 million user milestone. Don't ask how we distinguish unique users!"
https://www.404media.co/email/9ee8f6a1-348a-4fb1-b1b3-30c8898d7581/?ref=daily-stories-newsletter
@gsuberland just "yeah, we're forking a sophisticated e2e messaging protocol" is enough for the bells to ring, never mind the sting ops. :D @soatok
@jkmcnk @gsuberland Didn't Session also remove forward security?
@soatok having just watched that DEFCON talk by the 404media guy about the FBI running one of the biggest encrypted phone companies as a sting op, the words "Signal fork" are some of the loudest alarm bells ever.
@feld @gsuberland @jkmcnk Making things ephemeral eliminates so many attack vectors. Long-lived secrets are undesirable.
@feld @gsuberland @jkmcnk I think this is asking the wrong question
Building PFS into a protocol costs almost nothing and makes security proofs easier, simplifies analysis, and lets us focus on other areas of the attack surface.
PFS should be the default for any protocol designed after the 1990s, and any design that doesn't include it should justify their choice to exclude it, rather than the converse.
@feld @gsuberland @jkmcnk Because one-time-pads don't offer protection against chosen-ciphertext attack.
It is frustrating that Signal still insists on requiring a phone number for everyone who uses their app, though. At least they finally made usernames so you don't have to share your phone number with others, but I don't really want to share it with Signal either.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.