11 ms·
Encrypted messengers: Riot, not Signal, is the future
- jdp23 10y agoAre there any plans to do a security audit on Riot? The useful report by NCC [1] looks at libolm (which implements the end-to-end encryption) but of course that's only part of the whole product. [1] https://matrix.org/blog/2016/11/21/matrixs-olm-end-to-end-encryption-security-assessment-released-and-implemented-cross-platform-on-riot-at-last/ https://matrix.org/blog/2016/11/21/matrixs-olm-end-to-end-en...
- buzzybee 10y agoNote that that report explains that the Double Ratchet E2E algorithm is used in Matrix, in large part because of the Open Whisper Systems implementation in Signal and subsequent licensing. So we're looking at an apples-to-apples comparison, at least with respect to this one piece.
- jdp23 10y agoYes, it seems like a good choice of algorithm. And it seems like the implementation is also decent - they looked at that as well. It's a useful report and kudos to Open Technology Fund for funding it and to Matrix for making it public! Still, this is only one piece of the overall security of Riot, so I'm still interested in knowing if there's any work going on looking at the bigger picture.
- Arathorn 10y agoYes. Once the E2E implementation is fully finished and out of beta, and once we have a non-beta homeserver (as Synapse is still technically in beta, albeit very late beta), we'll be going to NCC and working out how to do an audit of the whole enchilada (homeserver + olm + matrix-js-sdk + matrix-react-sdk + riot-{web,ios,android}). This may well end up being broken down into separate components, much as the Olm audit was limited to the Olm component. At the current rate this should happen at some point in 2017.
- jdp23 10y agoGreat to hear, thanks!
- rahrahrah 10y agoI have the impression that Signal by now has such a great brand name that mere technical objections won't affect its growth for a very long time.
- majewsky 10y agoI wonder if the name of Riot will be a hindrance for widespread adoption. Most people don't like riots.
- rahrahrah 10y agoYou might have a point there. "Signal" feels much smoother than "Riot".
- zeratax 10y agoOr the fact that searching for it usually results in the company riot behind league of legends.
- mundo 10y agoI actually just learned today that Riot (the IM app) is not related to Riot (makers of hugely popular video game League of Legends). I thought the occasional mentions I was seeing of "Riot chat" meant that LoL's mobile chat client was gaining traction among people who don't play the game.
- hkt 10y agoYeah, it's a bad name. Don't think I could get my parents or colleagues to use it.
- aftbit 10y agoVector.im was much better - I don't really get why they changed it.
- xkxx 10y agoHow about Discord? It's very popular among gamers despite its name.
- 10y ago
- rahrahrah 10y agoThe question I would ask is: given the list of capabilities presented in this post, is there even any difference between Riot and e-mail? Or are you reinventing the wheel?
- NoGravitas 10y agoEnd-to-end encryption. Even if you encrypt email with PGP, which no one has come up with a satisfactorily easy interface for, it leaks a lot of metadata. Riot gives essentially the same privacy guarantees as Signal, but with email-like federation.
- rahrahrah 10y agoPGP can be used to encrypt at the ends, in which case it is end-to-end encryption. So that's not a different feature. Care to share what you mean by PGP leaks a lot of metadata? You might be right, I'm just not aware of such details.
- NoGravitas 10y agoPGP encrypts the contents of the message, but not the headers.
- dublinben 10y agoNone of the email headers are protected in any way for a PGP-encrypted email. All the same metadata is that collected from plaintext email is still available on "encrypted" email. You literally can only protect the body of the email. In surveillance, that is often the least interesting or valuable piece of information.
- qznc 10y agoSignal does not solve the meta data problem either. Discovery is an open problem [0]. Signal messages leak the recipient, which is the most important meta data. You would have to use Tor/Onion routing, which is inefficient. [0] https://whispersystems.org/blog/contact-discovery/ https://whispersystems.org/blog/contact-discovery/
- RodericDay 10y ago> If OpenWhisperSystems adopts any policy that goes against users’ interests in the future, users cannot switch providers without losing all their contacts. Is this correct? I've never bothered looking it up, but Signal was connecting me with people in my phone's address-book.
- NoGravitas 10y agoIt's semi-correct? You don't lose your contacts, as they're still stored in your phone's address book. But all of your contacts will have to jump ship at the same time as you, to the same silo. And your old contacts will only still be usable if the new silo also uses phone numbers as userids. On Matrix/Riot, userids are federated in the same way as emails. So when you change providers, your userid changes, but your contacts' stay the same, and you can still connect with them from your new provider.
- tptacek 10y agoThis topic has been beaten to death on HN over the last year (other people can provide links to discussions, with Moxie participating). I think something worth keeping in mind is that almost everyone who works in secure messaging agrees on one thing: that electronic mail is not the future of secure communication. There's no fundamental reason why that should be the case. The store-and-forward model used by SMTP could be made to work for asynchronous secure group messaging. You can get forward and future security with it. It can interoperate with existing email addresses. All of that can be made to work. But it is the case. Email won't be a secure group communication system. The reason for that is that email is federated and thus permanently mired in the lowest common denominator of mainstream email clients. I think reasonable people can disagree about whether it's tractable to create a federated secure group messaging system with what we know right now. But I do not think it's reasonable to suggest that the concern (federation = lowest common denominator security) is invalid. And that's what this piece does.
- acqq 10y agoEspecially dishonest of Riot promoters is to even introduce it at this very moment to the "normal" users, because "Riot’s encryption is not yet fully stable and, more importantly, it is not yet enabled by default in chats (you have to enable it manually). This will be changed in the future, but makes it more likely for users to make mistakes until then." Users "make mistakes"? By using the defaults? I consider it a mistake to promote it to the users with such defaults. A "secure" product which "doesn't encrypt by default"? And "it's not stable"? What does that mean? The encryption either works or not. "Almost working" is still "not working." Then please don't write "An alternative to Signal is Riot." It is not. As far as I understand it just "could once be an alternative." But based on the responses I've received here to my questions about Riot, it's promising: according to them, I will be able to set up my own network of people (e.g. just my family) with which I'd like to communicate. Yay! (thanks to mxuribe and NoGravitas for the answers)
- vertex-four 10y agoRight now, in practice, Matrix is "a better IRC". It provides bouncer-like functionality by default, federation across the whole network so you only have one identity vs having to register with each server on which there's a community you want to talk to, file sharing, voice/video chat, proper message formatting, and more. Encryption currently works on Riot Web, iOS and Android, certain bugs excluded - but it's missing a lot of UX work. (Among other things, you have to manually verify each and every device the people you talk to use, there's no way for them to say "these are all my devices, if you trust me, you trust them" yet. You also lose chat history at present if you switch devices or log out.) If you're able to work around the UX, the underlying protocol is fine and has been audited, with certain tradeoffs discussed in the report.
- exstudent2 10y agoA question I've had about Signal is what is stopping Apple from modifying and rebuilding the source with a backdoor in it? Is this technically possible (seems like it would be since they control distribution of the binary to devices)? The article is correct in stating that web based chat is inherently insecure but it seems all iOS apps are also inherently insecure. I'm by no means an expert though so would love to hear from someone with more knowledge. EDIT: Thank you for the responses! It pretty much confirms what I thought; Apple _could_ access your communication (either through keylogging at the OS level or backdooring Signal) but this solution is better than everyone use plain text communication. I personally would not trust Apple with my life if I needed that level of protection but maybe that's not the main use case for Signal.
- Cyph0n 10y agoWith such a system, you must end up trusting a certain entity; it's turtles all the way down otherwise. No system is independently secure. Similar questions include: What if a CA is compromised? What if Apple/MS bundles unwanted certs with the OS? What if Intel/AMD biases the on-die hardware RNG or other hardware crypto primitives? What if Apple/MS bundles a backdoored compiler a la "Reflections on Trusting Trust"? What if MS/Apple backdoor the entire network stack, including the physical and data link layers? etc. etc.
- hkt 10y agoDoes Signal support reproducible builds, at least? Real question, I don't know.
- kuschku 10y agoPartially. They're moving towards it, but it obviously doesn't help that only half of the app is actually open source.
- temprature 10y agohttps://whispersystems.org/blog/reproducible-android/ https://whispersystems.org/blog/reproducible-android/
- acqq 10y ago> Riot is based on the so-called Matrix protocol which is a federated protocol > In addition, people are writing alternative clients to access the Matrix/Riot network, implementing their favorite features and workflows. As users can vote with their feet for their own interests and choose providers and apps of their liking Can I run my own network which is not part of other networks (i.e. not "federated")? Can I tell somebody "call with your Riot client 'acqq at server ip nnnnnn' and we can talk"?
- NoGravitas 10y agoI believe so, yes. If not with the standard homeserver (synapse), than with a custom homeserver.
- acqq 10y agoNote: my question is, with a plain client, downloadable from the app store, not with some special custom build of the client. Also, how puringpanda's question fits to your claim? https://news.ycombinator.com/item?id=13239925 https://news.ycombinator.com/item?id=13239925
- NoGravitas 10y agoYou can connect to any homeserver with the default client; it's not tied to the default homeserver. If I understand puringpanda's question, the idea is that your domain and your homeserver are seized, but you have contacts on other homeservers. At this point, it's just like losing your email server. You lose your existing ID, and probably your message history, but you can reach your contacts from a new ID you create someplace else.
- mxuribe 10y agoThere are 2 "ways" to do this: 1. You and your friend both use the riot (actually matrix.org) server/network and you both choose any matrix-relevant client (doesn't even have to be the riot client), but only make use of private rooms on that server. This avoids any system setup overhead whatsoever...But the private room(s) that you create would still on a server that is not controlled by you. 2. You can of course setup and run your own little private network; on your own domain name/IP address. This is what I do with my family; and only my wife, and daughter have access (I've even disabled registration). I have not yet connected my little network to the greater matrix network...For 2 reasons: I wanted to beta test this internally so I could leearn; Also, i wanted to be sure my family does not get exposed to any spam (if there is any that is). Good luck; cheers!
- mtgx 10y agoI support good alternatives to Signal that also have other goals in mind. Signal's goal is to become basically as mainstream as Whatsapp is, and to get there it needs to make a few compromises for usability's sake. Whatsapp has already backtracked on some major privacy promises, and who's to say it won't backtrack on the end-to-end encryption support eventually, after everyone is baited and switched to it? Or worse, it could start to decrypt E2E communications in secret for governments. So we need a "mainstream" alternative that's actually trustworthy and can at least protect the security of the communications, if not the relationships between users. However, I support applications that aim to offer even better privacy and security compared to Signal, that are aimed at more opsec-sensitive targets, such as journalists. Signal may be the best tool journalists have right now, but it's probably not the best one they could have, as it doesn't do a great job at protecting sources. Perhaps Ricochet or the Tor Messenger may be better for that. What I'm worried about though is that even if these apps offer better security/privacy features, the various federated applications that use an E2EE protocol may not have too much of a security mindset. For instance, sure, Riot may adopt a better protocol, but is Riot itself using all modern security best practices? Can we trust the Riot developers just as much as we do the OWS developers? etc Finally, I'd much rather see Signal become a P2P application than a federated one, if that would even be possible.
- sliken 10y agoTrick to p2p is that generally you have to accept incoming connections for it to work. In signals case that's the signal servers. Originally skype did this, skype users with a good network connection, good uptime, and who accepted incoming connections could self promote themselves to a supernode. This allowed async messaging for others, helped introduce peers who couldn't talk directly because of IP Masq/NAT etc. So it's possible that signal could write a small application that could be a supernode. Ideally it could run on a Raspberry Pi, Plug computer, or even any of the numerous opensource routers. What way your battery sensitive phone wouldn't get run down by participating in a DHT or similar, but your raspberry pi could act like your inbox and facilitate incoming and outgoing messages.
- PurgingPanda 10y agoDoes anyone know if they are planning to add a way to change home server. If they take your domain (With your Matrix server on it), you have no way of communicating with other people over riot anymore.
- uabstraction 10y agoThere are plans to support 3rd party identification (such as an E-Mail address or a phone number) and use that as a basis for looking up users across the network, but I don't think it is currently useable. Account migration was brought up recently in the chat room, but it is not defined anywhere in the spec or reference implementations AFAIK. I agree that these are both important features, but I wouldn't worry too much about them unless they are left out of the 1.0 spec. In the meantime, it's not like you can migrate your Signal, Telegram, iMessage, or even Gmail/Hotmail accounts. I think Matrix needs a few more client/server implementations before the spec can't truly be set in stone.
- Arathorn 10y agoEmail identifiers work fine today, actually. They don't solve the problem of migrating accounts, but at least they abstract the discovery process away, as you say. MSISDN (phone number) identifiers landed on the backend this afternoon; implementation in the Riot clients will be coming very shortly.
- NoGravitas 10y agoI believe you need to create a new account on another homeserver.
- Arathorn 10y agoAccount migration is Hard, and we deliberately descoped it from the original design of Matrix in a bid to ship stuff sooner than later. https://github.com/matrix-org/GSoC/blob/master/IDEAS.md#decentralised-accounts https://github.com/matrix-org/GSoC/blob/master/IDEAS.md#dece... is a quick description of the problem. There are broadly two ways of solving it: 1. have a naive implementation where users can configure their accounts to replicate between sets of servers, and clients have primary and fallback servers they can talk to if the primary isn't available. 2. switch to a p2p model where each device has its own server, and so account data is automatically replicated across multiple devices. This has a host of other advantages too (e.g. you can own your data without running your own server; you can adopt metadata-protecting federation transports; you can still use all the existing apps today as the client-server API remains the same; you can still bridge with the Matrix network of today). #2 is obviously way more work, and is effectively rewriting the federation side of Matrix. However, Matrix is designed to evolve and we're not ruling this out from happening at some point. Meanwhile #1 is more likely to land in the nearer future. We haven't got it scheduled in yet, but it's very much on our minds!
- buzzybee 10y agoI believe Riot is the future not because of its security(its attention to such is a great, great bonus) but because it's positioned itself so well as a credible successor to IRC.
- NoGravitas 10y agoAnd an open replacement for Slack.
- qznc 10y agoYes. I don't see Signal and Matrix in direct competition, just like WhatsApp and Slack are not in direct competition. The technology is very similar (main difference seems to be the size of chat rooms), but the use case and marketing is very different. Signal/WhatsApp is for casual mobile texting, while Matrix/Slack is for working.
- krick 10y agoIt might be the case, but I should would prefer being able to stick to just one messenger in the end. And I don't see why it wouldn't be Matrix as opposed to WhatsApp. (If we ignore the networking factor, of course.)
- Perceptes 10y agoI think Riot is a better comparison to Slack than Matrix is. Riot is essentially the Slack experience built on the Matrix protocol, but Matrix can certainly work just as well for clients that present a Signal/WhatsApp/iMessage/SMS-style interface.
- ifelsehow 10y ago> The most important concern is that Signal is a silo [...] you have to connect to OpenWhisperSystems servers to communicate with other users. You can run your own private Signal service with OpenWhisperSystems' tools [1]. It's also worth noting that Signal - as a protocol - could easily be federated. (As others have mentioned, Moxie has chimed in on why the app is centralized [2]). If confederated messaging is important, why not use the existing Signal protocol implementations, (including the X3DH key exchange, ratcheting protocol, etc), which is all F/LOSS, and has already been widely reviewed (as the article mentions)? [1] https://github.com/WhisperSystems/libsignal-service-java https://github.com/WhisperSystems/libsignal-service-java [2] https://whispersystems.org/blog/the-ecosystem-is-moving/ https://whispersystems.org/blog/the-ecosystem-is-moving/
- stonogo 10y ago> You can run your own private Signal service A distinction without a difference. I use Signal because people use Signal. People do not use 'the Signal service'. They use OWS's app and OWS's servers and moxie has explained he will not federate. The fact that OWS goes to all the effort of creating this excellent protocol, and then insists on only deploying it to insecure devices (with direct-memory-access baseband radios) baffles me, but I hope that things move in a saner direction with time. The biggest benefit I think OWS has provided is the ability for other platforms (e.g. Whatsapp) to use their protocols. I daydream about a day when all these competing messaging services realize they would stand to gain a lot by federating, but I know it won't happen in my lifetime.
- ajamesm 10y agoI'm not a fan of opaque baseband firmwares either, don't get me wrong, but what's the alternative? Not for the DoD, I mean for union organizers making $50k a year -- people who aren't going to get murdered by Mossad, but still need to authenticate and encrypt their communication channels. What device would you recommend?
- voltagex_ 10y ago
- evolve2k 10y agoThe permissions Signal asks for do seem excessive (both on iPhone and even more so on Android). Can anyone justify why they are necessary?
- Forbo 10y agoOWS already has: https://support.whispersystems.org/hc/en-us/articles/212535858-What-are-all-these-permissions- https://support.whispersystems.org/hc/en-us/articles/2125358...
- stephengillie 10y agoDevelopers who are unfamiliar with the Intents system? That's a common reason for applications requiring a laundry list of permissions. http://stackoverflow.com/questions/6578051/what-is-an-intent-in-android http://stackoverflow.com/questions/6578051/what-is-an-intent...
- Forbo 10y agoThe developers have feature justifications for every permission requested: https://support.whispersystems.org/hc/en-us/articles/212535858-What-are-all-these-permissions- https://support.whispersystems.org/hc/en-us/articles/2125358... Edit: Reading your link now, as I didn't see it before I made my comment. Was that added in as an edit?
- stephengillie 10y agoThese are the justifications of developers who are unfamiliar with the Intent system. Were I unaware of Intent, I would make the same design decisions.
- wybiral 10y agoI agree. Mostly because they're asking for all of those permissions prematurely. What if I never want to share my location, take pictures, or send files? And then some things, like calendar access, aren't even used right now.
- mxuribe 10y agoNothing against Signal, But I sure hope matrix-based platforms and clients (like riot.im) keeping growing. The folks who work on both matrix.org and riot.im have done so much work in such a short time...not just in developing the protocol/server/apps...but also in education. They really have helped people like me to setup our own little home servers (i.e. private networks)...which ultimately helps the entire federated network. Signal - while certainly can be setup/hosted by anyone else separate of OpenWhisper - leaves some to be desired in the actual self-implementation details; just not enough tutorials out there. (Or maybe its just me?)
- widforss 10y ago> Signal - while certainly can be setup/hosted by anyone else separate of OpenWhisper - leaves some to be desired in the actual self-implementation details; just not enough tutorials out there. That is the problem at hand, that Signal _does_not_federate_. You could modify your Signal app to connect to your own server, but then you would not be able to talk to anybody else. For the record I prefer usability and walled-garden-security instead of federation, even though it hurts to admit as a long time FOSS user.
- sliken 10y agoI think signal made the right decisions raising the bar for encryption while maintaining extreme ease of use. Random Joe can click on it on the app store and chat with anyone in his addressbook that runs signal within a minute or so, with no expertise whatsoever. However I see no reason why a similar p2p app couldn't manage similar without a central server. Trick is cell phones (at least on WAN) do not accept incoming connection. Additionally apple/android push aren't good for a p2p transport. However adding supernodes (like the original skype) that could run on raspberry pi's, opensource routers, and similar embedded devices might just bright the gap. After all the cpu, bandwidth, and memory needs for instant messaging are pretty modest, even for many people sharing a raspberry pi.
- rando444 10y agoThe idea of supernodes is what got everyone paranoid (with reason) that they were now able to be spied upon.
- hkt 10y agoHear hear. Down with silos. I just hope matrix ends up working better than xmpp.
- Perceptes 10y agoIt should be noted that Riot is just the first Matrix client to support end-to-end encryption, but there will be more in the future. The thing you want to bet on is the Matrix protocol, not necessarily Riot. (Although both are a safe bet since Riot is developed by the same team that built Matrix.) I'm not part of the Matrix or Riot teams, but I'm convinced enough that Matrix is a great way forward for modern messaging. I started my own Matrix homeserver (as well as other Matrix libraries, eventually to include a Matrix client) written in Rust. If you're interested in Matrix, Rust, or both, I encourage you to get involved! https://www.ruma.io/ https://www.ruma.io/
- upofadown 10y agoAfter a recent discussion of the issues with XMPP on mobile, some obvious questions: 1. How well does Riot deal with changing network connections? Does it have problems when a mobile device switches between, say, WiFi and 4G? How well does it deal with a complete loss of connectivity? 2. How well does Riot deal with power management on mobile devices? Can it spend time in the background while getting message alerts while not running down the battery?
- heavenlyhash 10y agoIt's really good. I'll vouch for it as someone who has been using the mobile apps on both platforms, and the web application(s) on the desktop for over a year now. They're great. Battery isn't a problem; messages NEVER get lost. I actually came to matrix after trying to write an XMPP client, believe it or not. The matrix protocol is WAY better equipped for the future than XMPP is: it simply has the core designs necessary to make it federate well and do message sync without losses. (XMPP doesn't. (Unless you count a half-dozen XEPs, none of which are reliably implemented in all clients. But we're getting increasingly parenthetical here; by comparison, matrix Just Works.))
- tacoman 10y agoI've been using Vector/Riot using the Android version in F-Droid on Blackberry 10 for 6-9 months, connecting to my own server on my DSL. I haven't noticed a single issue with battery or lost messages.
- upofadown 10y agoOK, I did a better search and found something relevant in the fricken Matrix FAQ: * https://matrix.org/docs/guides/faq.html#i-installed-riot-via-f-droid-why-is-it-draining-my-battery https://matrix.org/docs/guides/faq.html#i-installed-riot-via... >I installed Riot via F-Droid, why is it draining my battery? >The F-Droid release of Riot does not use Google Cloud Messaging. This allows users that do not have or want Google Services installed to use Riot. >The drawback is that Riot has to pull for new messages, which can drain your battery. To counter this, you can change the delay between polls in the settings. Higher delay means better battery life (but may delay receiving messages). You can also disable the background sync entirely (which means that you won’t get any notifications at all). >If you don’t mind using Google Services, you might be better off installing the Google Play store version.
- sliken 10y agoWow, riot has a ways to go. With signal you install it from the app store, it creates an icon, you click on it. Similar for the desktop client, go to the chrome app store, click on it, and it tells you to use your phone to scan a barcode. In both cases you can start chatting with any signal user in your address book in a minute or so, no expertise (other than using an app store) needed. Tracked down the http://riot.im http://riot.im, it has a "try now button", that just scrolls you to the top. Didn't see any way to actually try it. I tried the ubuntu app, they make you manually create your own /etc/apt/sources.list.d, from only the base URL. Then you have to know how to add the pgp key. Then apt-get update, apt-get install riot-web. Then... nothing. Nothing called riot or riot-web in the path. Thought maybe there would be a daemon running (it's called riot-web afterall). Can't find any processes running, nothing listening on a new socket. I track down /var/lib/dpkg/info/riot-web.list, look through the list and find they dropped a dir in /opt. So I run /opt/Riot/riot-web. It worked, not exactly the kind of thing I'd ask random friends/family/colleagues to do though.
- danjoc 10y agoRiot? Can we talk about the edgy names? Think about how much differently history might have been if Napster was named Library of Alexandria. "According to Galen, any books found on ships that came into port were taken to the library, and were listed as 'books of the ships'. Official scribes then copied these writings; the originals were kept in the library, and the copies delivered to the owners." https://en.wikipedia.org/wiki/Library_of_Alexandria https://en.wikipedia.org/wiki/Library_of_Alexandria Sounds like Napster, yes? Think about how much harder it would be for Congress to pass laws shutting down the digital equivalent to a library sharing the world's music. But no. We get names like Riot, and Felony (https://github.com/henryboldi/felony https://github.com/henryboldi/felony). Congress sends you a "Thank you" every time you put an edgy name on something disruptive.