Alec Muffett Profile picture
Jan 4, 2020 15 tweets 22 min read Read on X
I need help : from someone with a better legalese attention span than me, and with broad cryptography understanding, to explain to me how US Patent 10412063B1 is somehow NOT an attempt to patent the @signalapp #Signal Encryption Algorithm: patents.google.com/patent/US10412… ImageImage
@signalapp @matthew_d_green @SteveBellovin @tqbf @FiloSottile I am literally halfway down my first coffee, and it smells to me a bit like someone has taken #Signal, said "if we throw away the prekey mechanism then we have something novel", and then patented it; but then I am still skimming the document: Image
@signalapp @matthew_d_green @SteveBellovin @tqbf @FiloSottile I am not interested in armchair patent lawyers saying:

"Ho ho ho yes but they cannot enforce this patent in the bastion of privacy that is Germany!"

…because if your remit is that "everyone deserves good security", that includes America.
@signalapp @matthew_d_green @SteveBellovin @tqbf @FiloSottile But my 30 year career has been peppered with people attempting to either regulate or patent, chunks of cryptographic art, thereby retarding adoption.

With this, if I am right and if it is not thrown out, we risk innovation around Signal coming to a FUD-laden stop for 19 years. Image
@signalapp @matthew_d_green @SteveBellovin @tqbf @FiloSottile Perhaps @zaumka himself would like to chime in and tell us how this patent application:

1/ differs from @signalapp
2/ will not chill innovation in and around #e2ee

cs.nyu.edu/~dodis/
@signalapp @matthew_d_green @SteveBellovin @tqbf @FiloSottile @zaumka Again, I cannot shake the impression of "handwave away the Signal prekey mechanism, and then bolt-the-entirety-of-signal-protocol-to-that-and-patent-the-result".

What am I missing, @zaumka ? Image
@signalapp @matthew_d_green @SteveBellovin @tqbf @FiloSottile @zaumka Oh, oh, oh, it's not a daisychained series of hash functions which generate message keys, NOOOooo... it's a "random number generator with a seed" Image
@signalapp @matthew_d_green @SteveBellovin @tqbf @FiloSottile @zaumka NARRATOR: "that's basically the same thing"
@signalapp @matthew_d_green @SteveBellovin @tqbf @FiloSottile @zaumka The Claims: this is where we go back to "need someone with a better attention span than myself" ImageImageImageImage
@signalapp @matthew_d_green @SteveBellovin @tqbf @FiloSottile @zaumka To me, this reads a lot like the Double-Ratchet algorithm (eg: as described in Wikipedia) with maybe freedom to redefine the hash ratchet as some form of PKE?

If my fear is that this chills development of (say) group chat based on Signal, I don't yet feel that I'm wrong. ImageImageImageImage
Hacker News is Hacker News:
news.ycombinator.com/item?id=219540…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Alec Muffett

Alec Muffett Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @AlecMuffett

Nov 2, 2023
Hot on the heels of #ChatControl and in the name of “identity” and “consumer choice” the EU seeks the ability to undetectably spy on HTTPS communication; 300+ experts say “no” to #Article45 of #eIDAS #QWAC alecmuffett.com/article/108139
If you would like to see more discussion regarding:

Regulation: EU Digital Identity Framework — including #eIDAS and #QWAC

…here's a #ReadyMadeTwitterSearch with links & more information at: github.com/alecmuffett/re…
Read 8 tweets
Jul 20, 2023
When Signal and WhatsApp have fled the surveillance of the #OnlineSafetyBill, what app will still be around for politicans, journalists, and actual normal people to use, securely.

The answer might be this:

alecmuffett.com/article/85187
@JohnNaulty @matrixdotorg Let's be clear: we are talking about the evacuation of the entire Signal and WhatsApp userbase / niche, from the United Kingdom.

That's a lot of people.
WOW:

- No Signal
- No WhatsApp
- No iMessage
- No Facetime

@jamesrbuk called it #internexit; the UK will be extraordinarily isolated from the rest of the internet.

bbc.co.uk/news/technolog…
Read 15 tweets
Jul 21, 2022
All Watched Over By Filters Of Loving Grace: GCHQ's Holistic, Sociotechnical , "Thoughts on Child Safety on Commodity Platforms" #ghostProtocol #ghost #NCSC
alecmuffett.com/article/16236
THE NEW GHOST PROTOCOL PAPER'S UP!

tl;dr —

* @GCHQ like client-side filters

* …and ghost chat participants

* …and would like everyone else to buy into them defining what E2EE means

* …because they *don't* like simple definitions of E2EE

arxiv.org/abs/2207.09506
Read 17 tweets
Jul 20, 2022
I've been saying stuff like this for ages, maybe if @alexstamos says it too then people will listen? #DMA
Inevitably the response is something glib like "Use Matrix"
A big part of the the reason for the existence of that API was because the European Union wanted to enable people to access their data; so they created the problem, complained when the inevitable leaks happened, and are now reinventing it
Read 4 tweets
Jun 10, 2022
Could be the attached, but my suspicion is that this is going to be another CYBER! DARKWEB! CYB3R! SYBER! CAMBRIDGE ANALYTICA‼️BRAIN CONTORL! YOU SAW AN ADVERT AND SO A RUSSIAN ARTIFISHIAL INTELLIGENCE APP MADE YOU VOTE FOR UKIP! … thing.

READING BETWEEN THE LINES:

Plucky spooks in Cheltenham but dressed for speed-dating in 2015-era Shoreditch, battle "Russian influence operations" that Nadine Dorries will soon cite as rationale for the #OnlineSafetyBill.

Token American subplots help sell the series to the US.
Read 4 tweets
Jun 2, 2022
Back in 1991 I published an open-source password cracking tool which defined the state of the art for the next 5+ years, so much so that echoes of it can be found in all major password crackers of today.

Some folk criticised me for doing this, choosing words like these to do so: Image
I know that in general it's bad form to take a single quote out of context and use it to critique an entire essay (concerned.tech) — but I do feel that this time it's deserved.
The concerned-dot-tech essay has had extensive technical debunking, e.g.:

1/ prestonbyrne.com/2022/06/01/deb…

2/

…but that's not what bothers me.
Read 12 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(