feld, (edited )
@feld@bikeshed.party avatar

DC3 Technical Advisory Signal Chat App Decryption

https://content.govdelivery.com/accounts/USDODDC3/bulletins/2e03518

Never forget guys

meso,
@meso@netzsphaere.xyz avatar

@feld dude, all software is like this

feld,
@feld@bikeshed.party avatar

@meso Except PGP mail with a Smartcard

meso,
@meso@netzsphaere.xyz avatar

@feld smartcards are proprietary

feld,
@feld@bikeshed.party avatar
meso,
@meso@netzsphaere.xyz avatar

@feld link open source hardware for it

feld,
@feld@bikeshed.party avatar

@meso Here's an alternative: NitroKey's implementation and their hardware is open source too

https://github.com/Nitrokey/opcard-rs

sun,
@sun@shitposter.world avatar

@feld @meso I guess it would be too much trouble to make signal work with a yubikey

feld,
@feld@bikeshed.party avatar

@sun @meso I'm currently wondering if we can coerce @delta to support it. I wouldn't mind having an account that only works when I plug in my Yubikey

meso,
@meso@netzsphaere.xyz avatar

@feld @delta @sun delta is a meme

feld,
@feld@bikeshed.party avatar

@meso @delta @sun idk man, have you tried it recently? it's looking very promising

sun,
@sun@shitposter.world avatar

@meso @feld @delta using smtp in the background seems like literally the worst choice you could possibly make yet delta chat seems to work great so I guess I don't mind what's under the hood and they can carry on being good

feld,
@feld@bikeshed.party avatar

@sun @delta @meso it does solve some interesting problems for you, though.

Like with WhatsApp/Telegram/XMPP/iMessage any media attachments actually go to a webserver and the message contents reference a link the client downloads

with SMTP as the transport mechanism you just include the attachment in the message, and it will also be encrypted

It doesn't scale as well which is one reason why the others do it their way, but scaling is not a problem that needs to be solved right now

feld,
@feld@bikeshed.party avatar

@sun @delta @meso you're not gonna be able to do 2GB attachments like Telegram obviously

feld,
@feld@bikeshed.party avatar

@delta @meso @sun I'm cackling to myself at the idea of using NNTP for large file attachments, actually... it could work...

imagine if establishing a chat also established a private obfuscated newsgroup name between the parties and the encrypted payloads were pushed there. You'd have to be able to integrate somehow so the NNTP servers could be told which groups to subscribe to and which servers to peer with, but it would be possible to limit the scope so only the involved parties' groups get downloaded by the partipants' servers.

feld,
@feld@bikeshed.party avatar

@sun @delta @meso one of the issues with PGP mail is that there's too much metadata exposed plaintext but Delta side steps that a bit e.g., the Subject field isn't used for message data

adbenitez,
@adbenitez@mastodon.social avatar

@meso
"delta is a meme"

meanwhile me:

@feld @delta @sun

meso,
@meso@netzsphaere.xyz avatar

@feld @delta @sun >Yubikey
Proprietary alert :alert:

feld,
@feld@bikeshed.party avatar

@meso @delta @sun I hate to break it to you bud but most of your computer hardware is proprietary

meso,
@meso@netzsphaere.xyz avatar

@feld @delta @sun no it isn't

feld,
@feld@bikeshed.party avatar

@meso @delta @sun

your CPU is
all the important bits on your motherboard are
your NIC is
your WiFi and BT radios are
your GPU is
all the important bits in your monitor are
the guts of your keyboard and mouse most likely are
your USB/thunderbolt controller is

sun,
@sun@shitposter.world avatar

@meso @feld @delta okay, nitrokey

feld,
@feld@bikeshed.party avatar

@sun @delta @meso he's currently malfunctioning after I linked him the Nitrokey smartcard source code

feld,
@feld@bikeshed.party avatar

It's wildly irresponsible for Signal to not warn you that your contacts are using Signal Desktop

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • GTA5RPClips
  • JUstTest
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • provamag3
  • Leos
  • cisconetworking
  • megavids
  • lostlight
  • All magazines