Daniel Fernandes
@dfern.eth
Signal has moved the ball on e2e for the masses, but it's centralized arch makes it a honeypot for metadata collection & timing correlation attacks. p2p networks w/ plausible deniability bloom filters like @waku & mixnets like @nymproject make attacks like this harder w/ the tradeoff of higher bandwidth & latency.
4 replies
2 recasts
10 reactions
Daniel Fernandes
@dfern.eth
also Quorum Messenger via @quilibrium can add cryptoeconomics into the mix by providing incentives to run decentralized messaging infra
0 reply
0 recast
2 reactions
Henry
@hlau
Feels like UX is usually the biggest trade off right? The fact that our industry runs on top of TG continues to baffle me but I’ve accepted the network effect
1 reply
0 recast
1 reaction
boscolo.eth
@boscolo.eth
Agree that Signal is awesome except for it's centralized arch. In addition to honeypot for metadata collection, Signal also doesn't have a cryptographically provable identity to verify initial messages sent to a new contact. A team of us are experimenting with adding Signal-like e2ee messaging to Bluesky which, like FC, has a DID that can bootstrap secure messaging.
0 reply
0 recast
1 reaction
boscolo.eth
@boscolo.eth
With this particular attack, I think the only thing that will help is a mixnet or a client that doesn't use a CDN in any way. It's a trade off between responsive UX and doxing your location.
0 reply
0 recast
1 reaction