Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> when dealing with data encryption susceptible to brute-force attacks

The "brute-force attacks" imagined here are a bad guy somehow controls Signal's systems, or else the US government seizes them and then decides to try to brute force them, right ?

But these are attacks where for various rival systems it was already game over. So your assumption is that Signal's casual users, people who maybe were also considering Whatsapp or iMessage or something, should be required to have a cryptographically strong passphrase so as to defeat this unlikely circumstance, as a minimum?

Moxie's whole deal is that this stuff only works when it's for everybody. If there are a five people in your country who use Signal, guess what, the Secret Police can round them up as suspected terrorists and execute them. Were they planning to bomb the President For Life? Or just organising a pizza party? Don't care, it's just good policy. But if there are five million people who use Signal that's a different matter.

Even if all five million are terrorists, that's numbers where you're going to have to tear up your "no negotiating with terrorists" policy, 'cos there are just too many of them.



I do think considering the average use case is paramount. That's why I think remote encrypted contacts storage should have never been implemented: most people won't choose strong passwords. Giving them the false notion that their sensitive stored data is cryptographically indecipherable is wrong.

As it stands now, people who create a Signal PIN aren't even warned about the security implications of using weak numeric PINs, which is among the worst of all possible worlds.

If this feature is critical, it should have been gated behind prominent passphrase entropy warnings, along with the data being put at risk [1], or it should have enforced actual strength requirements.

Signal is still better than most other messengers. I am mostly comparing it to its former self. And its former self worked flawlessly without needing to upload persisted contacts information.

1. https://github.com/signalapp/Signal-Android/blob/main/libsig...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: