7 ms·
Keybase Exploding Messages
- cascom 8y agoanyone care to expand on the practical applications/implications/threat model where this makes sense?
- giancarlostoro 8y agoApparently those dank memes and corporate espionage according to the article are some of the uses.
- schuetze 8y agoIt works as long as no one takes a screenshot.
- tylersmith 8y agoOr even extract the text + signature before it "explodes". Keybase messages don't have repudiability so anybody who has received a sign message should be considered to always have that message.
- WorldMaker 8y agoThough the FAQ at the bottom of the article suggests some sort of minimal repudiation support is in the works.
- arkadiyt 8y agoIt's for when you trust someone but don't want to risk either your or their device being compromised in the future. For instance: - if your or their phone gets taken at a border crossing - if your or their phone gets taken by the FBI (which is how they recovered encrypted WhatsApp/Signal chats from Michael Cohen's phone) - etc
- cascom 8y agothank you - this is what i was looking for
- ProblemFactory 8y agoOr in a much simpler and common case: you trust someone right now to run a non-modified client and not to take screenshots, for example based on a corporate policy. Months later the relationship turns sour, and they are fired or denied a promotion. They can't then go through the archives any more to take the screenshots.
- kough 8y agoHeard about this last week from a friend on the keybase team, happy to see it launch on time :) congrats!
- e1ven 8y agoAs I understand, Keybase chat is open-source? (https://github.com/keybase/client https://github.com/keybase/client) I don't have time to read through the code right now, but I'd love to hear how they implemented exploding messages with untrustworthy clients. I've thought about it a few times before, and it seems one of the few places that closed software has an advantage - You can't easily force third-party clients to delete messages. If they've solved that, I'm really interested to learn how it works!!
- ohazi 8y agoIt is impossible to implement this feature "safely" even with trusted clients -- worst case I take a screenshot or even a photograph of the device displaying the message before it explodes. If you don't trust the person at the other end, this is never going to work. It's more useful for "we both agree that we don't want a paper trail" kind of thing.
- ggg9990 8y agoA dead simple way to thwart the “screenshot” attack is to release a tool for accurately falsifying a screenshot. I’ve never seen this employed in practice though.
- tedunangst 8y agoHow is any bitmap editor not such a tool?
- lozaning 8y agoI think they're talking more along the lines of those online meme editors. Yea i could download the lion king and clip the frame with simba and then pull it into photo shop and then add text and then upload it to imgur. Or I could go one of those online meme editors in click the photo and enter my text and then get a link to the meme I made. The whole point is to totally lower the bar for anyone to make a passable copy, thus removing all confidence that any screen shot is genuine.
- Sir_Cmpwn 8y agoThis very article shows you the problem with "features" like this. You see that video demonstrating the feature? Notice how you can read the content of the message which was supposedly deleted?
- tylersmith 8y agoIn theory not having the signatures means the messages could be falsified, but many people would trust a screen capture still. Regardless, the signatures themselves could be extracted before "exploding" so the feature really is promoting unsafe security assumptions
- oconnor663 8y agoThere is a section about repudiability near the bottom of the article.
- wazanator 8y agoIf you don't trust the receiver you should not be sending them anything sensitive to begin with. This feature just eliminates the messages in case something happens to the recipent or their device if either become compromised. Let's say I work IT and user Bob forgot their password again and needs a temporary reset. I can message him his temporary password that expires in 3 minutes so that they can login and set a new one.
- yarrel 8y agoI trust the receiver. I don't trust future bad actors who get hold of the device, including the receiver should they turn.
- tomp 8y agoclick on some text in the article, it "explodes" :)
- tylersmith 8y agoThat was pretty annoying. I tried to copy some text but didn't drag correctly so it was interpreted as just a click and everything went away.
- leddt 8y agoDid you see the hidden message? I'm not sure what it means. (Treasure at the root of esabyeK)
- deleted 8y ago[deleted]
- Kenji 8y agoExploding messages are a stupid gimmick that does not hold up to any nontrivial threat model. What's out there is out there. Clients programmed to throw away plain- and ciphertext can simply be modified to keep them. Is the intersection of the set of clueless fools and set of people who want to use strong encrypted chats really this large??
- tylersmith 8y agoYour languages is stronger than I'd use, but this feature really is irresponsibly promoted at best and maybe just flat out irresponsible altogether for a "security" product.
- pphysch 8y agoI think this is precisely the target demographic--rather than cluelessly keeping a log of sensitive messages, the end user can cluelessly "explode" their sensitive messages. Of course, the clueless user will probably forget to do this anyways and it should probably be a default feature for the clueless organization.
- 0xCMP 8y agoWhat non-trivial threat model? Requires one side to have already been compromised and for a new client to be written to not throw away the message. For any secure messaging scheme or encryption protocol how do you actually protect against that? Without authentication and keeping remote party secure NOTHING will protect you (besides the threat of violence I guess). <science-fiction> There is currently no way to encrypt a message using a secure DNA-based public-key encryption that makes it so only that person can read the message. </science-fiction> You have to show it to whoever is "authorized" at some point. We hope the keys are kept safe to assure us of that.
- loteck 8y agoNice, succinct response in the FAQ to those who don't care about privacy: "I have nothing to hide" Because no one is trying to hurt you
- nebulous1 8y agoThis is like snapchat, they're offering something that they can't actually guarantee. Of course keybase users are going to be generally more knowledgeable than snapchat users and most will understand the limitations.
- 21 8y agoIt's still better to delete the message than to leave it there "because you can't guarantee it 100% either way". Defense in depth.
- Someone1234 8y agoI quote this far too much on security but "Perfect is the enemy of good." Meaning, people often dismiss improvements because they're technically imperfect. And it isn't just random forum discussions, major technologies like secure DNS, secure email, etc were held back years because nobody could agree on compromises needed to make improvements.
- nebulous1 8y agoYeah, I agree. The fact still remains though. Snap chatters, through ignorance, were under the impression that it was impossible for their photos to be shared with others. This was due to snapchat's failure to inform their customers and the experience level of their customers. It's notable that the blog post doesn't mention this at all, but on the other hand I would think that the percentage of keybase users that don't immediately understand this is extremely small.
- 645645645 8y agoi found this two blogs http://mawazo.tk http://mawazo.tk and http//cnn.com
- SamuelAdams 8y agoConsider this: I send an exploding message, set for 1 day, to Bob. Bob checks his chat a week from now. Does Bob get the message? Or has it already exploded? I guess I'm asking when the actual explosion timer starts - when the message is sent, or when it is read? For group messages, do all parties need to read it before the timer starts?
- ohazi 8y agoFrom the FAQ: Does the timer begin when the message is sent or received? Sent. This seems like the only sensible answer for group chats. And we can't have a different answer for 1-on-1 chats and group chats. That would confuse people. Not the kind of person who reads an FAQ such as yourself, of course. So our answer is simple: you set a timer and the message is gone after that time.
- schoen 8y agoI believe Signal uses the other policy, that the timer starts when the message is read rather than when it's sent.
- 24gttghh 8y ago>And we can't have a different answer for 1-on-1 chats and group chats. What might be the reasoning here that Keybase won't do it yet Signal messenger does start the timer on the "receive" end?
- wazanator 8y agoIt narrows the attack window. It's not hard to imagine a scenario where something happens to the receiver and as the sender you didn't realize this until you sent a few messages but the third party who got the receiver won't be able to access the device for some time. Hopefully by the time they get in they have self destroyed.
- 24gttghh 8y agoA valid point! Thanks for postulating!
- 456546546 8y agohttp://bit.do/mawazo http://bit.do/mawazo
- 8868678 8y agoabsolutly https://news.ycombinator.com https://news.ycombinator.com and http://mawazo.tk http://mawazo.tk
- kenbp 8y agoAnyone want to code Please Kenbp49@gmail.com
- qweamu1234567 8y agonice https://news.ycombinator.com/from?site=mawazo.tk https://news.ycombinator.com/from?site=mawazo.tk
- malgorithms 8y agoAuthor here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post. There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent. This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you sent something (i.e., you trust them THEN) and (2) there's a whole different class of adversary who compromises your or your partners' devices in the future. SnapChat, as far as I know, has none of the cryptographic implementation of Keybase. And yet it has likely protected hundreds of thousands of kids from severe bullying. Consider the teen girl who sends the goofy sexy pic to her boyfriend. Before the advent of exploding messages, he might've iMessaged or emailed that to a friend, just one friend, his best friend, out of pride. And that friend sent it to a few more, and so on. Not out of malice, but suddenly the whole school has seen her pic of god knows what and she literally wants to die. But with Snapchat, taking a screenshot is knowingly violating a social agreement. It's also violating the trust of his current girlfriend - everyone knows it's not okay to screenshot that shit. And the number of people who would do that is much tinier. Second, consider the far worse scenario: she dumps him a month later and until then he has been NiceGuy. But then he becomes r/niceguy, the guy who will look through the old pictures and spread them around. Finally, let's not forget that your device can be compromised by loss, theft, or hackers, at any time. Exploding messages are gone when that happens. People can be tricked, compelled, coerced, blackmailed, and hacked. Or just turn evil. All in the future. Which is what a timed message protects against. This is why Keybase is doing this. Paired with encryption it's quite powerful.
- DanielBMarkham 8y agoI hate to use this adjective, but this feature is cute. I love the little bomb. I love the concept. I love how you've applied it to several types of things. And I love how you've taken something that could be complicated and made it simple. Keep up the good work, guys!
- lakechfoma 8y agoI'm not a Snapchat user but doesn't that app, at least on Android, alert senders when a receiver takes a screenshot? You can still take a picture with a second device and that functionality isn't totally portable, but interesting feature. Do you think that concept has any utility here?
- ericnyamuken 8y agovery nice blog https://tinyurl.com/ybsu2vdw https://tinyurl.com/ybsu2vdw
- gepeto42 8y agoOf course this is not to address the case where the recipient would take a screenshot. I still find disappearing messages useful to reduce attack surface if say, the phone gets taken away and unlocked by someone else, or a backup of it is found and restored on something else, or if the phone gets compromised at some point at least not all previous messages are exposed, etc. A useful feature, not meant to address scenarios or malicious recipients or previous compromised devices.
- eridius 8y agoIf you haven't done so already, try clicking on any of the text of the blog post.
- AlphaWeaver 8y agoNice touch.
- 456hdsaq234g 8y agoI used to be against this style of 'DRM' -- either analog hole (screenshot or physical camera) or client subversion (client logs all messages out of band forever); but I think I misunderstood the use case. This is about changing behaviours to be more ephemeral; An expectation that your messages are not there forever. In a world of "unlock your phone or arrest" these features are very important. Thanks for rolling this out KB
- kolbe 8y ago> corporate messages In this day and age, I do not advise this. Check with your company's compliance officer or corporate council before doing anything that is designed to remove evidence of communication.
- mholt 8y agoI had to stop using Keybase after this issue [1] cropped up: when you re-install your OS, you lose access to the "device" and have to provision a new one, even though the machine is the same, and even in possession of an uncompromised private key. Apparently this happens a lot [2-7... probably more]. Unfortunately, this renders Keybase unusable for me because, even though I still have my private key, I cannot access my laptop's Keybase when I install it. [1]: https://github.com/keybase/client/issues/3460#issuecomment-278486140 https://github.com/keybase/client/issues/3460#issuecomment-2... [2]: https://github.com/keybase/client/issues/3559 https://github.com/keybase/client/issues/3559 [3]: https://github.com/keybase/keybase-issues/issues/1952 https://github.com/keybase/keybase-issues/issues/1952 [4]: https://github.com/keybase/keybase-issues/issues/1985 https://github.com/keybase/keybase-issues/issues/1985 [5]: https://github.com/keybase/client/issues/4260 https://github.com/keybase/client/issues/4260 [6]: https://github.com/keybase/client/issues/2357 https://github.com/keybase/client/issues/2357 [7]: https://github.com/keybase/client/issues/2675 https://github.com/keybase/client/issues/2675
- nebulous1 8y agoI'm not entirely sure what your issue is here. Why not reprovision (either with a different provisioned device or your paper key) and give it a new name?
- mnutt 8y agoAs a security layperson my initial reaction was "how can cryptography help with expiring messages, once it's decrypted it's decrypted, that doesn't sound right", but I'm curious if I'm understanding correctly that this is actually two separate features: 1) clients voluntarily respecting "please delete this message at X time" and 2) forward secrecy. And Keybase has tied them together for UX reasons since people tend to not have an intuitive understanding of when they might want to use forward secrecy, but they always want it in the case of exploding messages.
- askmike 8y agoThis is not functionality meant to make sure the other party will not have access to the massage after X time anymore, it's just convenience opsec: If you don't want someone to know X after some time, you should never tell him in the first place (he doesn't need to hijack the keybase client, he can simply "remember" the message). Instead this makes it easy to limit paper trace using a nice UX.
- oconnor663 8y agoThis is a good summary. Keybase supports adding new devices to your account at any time, and for that reason people often don't want forward secrecy. (Their message history would be gone on their new phone.) But that isn't a problem with exploding messages.
- deleted 8y ago[deleted]
- amelius 8y agoI want all my data on the internet to explode after N days. I keep asking for this. Google, Facebook, where is that feature?
- throwaway3189 8y agoYou might be surprised, but for some people this feature can be life or death. My team has been actually waiting for Keybase to have this. We work in countries where some of us are regularly taken aside by the local police or armed forces and our phones are being checked to see if we have anything against the current government. We have to constantly make sure our communication has no traces. We'll be moving to Keybase very soon. Thank you for this!
- prepend 8y agoWhy don’t you just use a client that deletes messages? Why would you wait for keybase to implement this?
- throwaway3189 8y agoWe've been waiting for Keybase, it doesn't mean we've been waiting with no solution meanwhile. We want to use Keybase because many of its other features.
- deleted 8y ago[deleted]
- shruubi 8y agoSeriously, do we need a stupid animation and a silly-looking "ka-boom" image? It just comes across as trying too hard to be cute and ends up looking childish and stupid.
- tmalsburg2 8y agoMetaphors like this help people understand what's happening. If the message just vanishes that could be for any number of reasons. But with this animation it's clear that the message is being erased. Keep in kind not everyone is a hackernews-reading computer expert.
- zkascak 8y agoThough I am not personally a fan of cute stuff like that, if it helps in making secure messaging usable for everyone from IT experts to their grandmothers who have never touched a computer I am all for it.
- ejholmes 8y agoHow does this differ from the existing "Message deletion/retention" feature that was present before this? Did the existing feature delete messages, but not keys? Is the old feature and the new feature combined, or are they still separate?
- mherdeg 8y agoCan someone explain the FAQ item around "My team uses Telegram and I'm scared shitless."? I musta missed the joke
- yellowsir 8y agonow that their is a exploding feature, can i finally explode this annoying notification about not providing my full name and description.
- monique212 8y agoHi everyone..I am trying to recover from a deceitful relationship and also trying to help people figure out if their partners are cheating or not..I am friends with the head of team of a hacking team..His investigation services include surveillance of a cheating spouse, partner, wife, husband, boyfriend or girlfriend,hacks from destroying data and evidence against you,changing school and university grades,increasing credit score,expunging your driving and criminal records to someone who is trying to blackmail you,he does random bank wire transfers and etc..He helped me hacked into my ex phone and find out he was cheating on me..If it wasn't for him,I would be in the dark still...Here's >>>>enriquehackdemon11at) gee mail (dot) C o M )>>>>..Tell your friends,family and loved ones to get in touch with him..He offers affordable rates, fast service and is highly confidential….enriquehackdemon11(at) gee mail (dot) C o M )
- monique212 8y agohi