36C3 - What's left for private messaging?

Title:
36C3 - What's left for private messaging?
Description:

https://media.ccc.de/v/36c3-10565-what_s_left_for_private_messaging

It is easier to chat online securely today than it ever has been. Widespread adoption of signal, wire, and the private mode of WhatsApp have led a broader recognition of the importance of end-to-end encryption. There's still plenty of work to be done in finding new designs that balance privacy and usability in online communication.

This introduction to secure messaging will lay out the different risks that are present in communications, and talk about the projects and techniques under development to do better.

The talk will begin with a threat modeling exercise to be able to concretely talk about the different actors and potential risks that a secure messaging system can attempt to address. From there, we'll dive into end-to-end encryption, OTR and deniability, and then the axolotl construction used by Signal (and now the noise framework).

The bulk of the talk will focus on the rest of the problem which is more in-progress, and in particular consider the various metadata risks around communication. We'll survey the problems that can arise around contact discovery, network surveillance, and server compromise. In doing so, we'll look at the forays into communication systems that attempt to address these issues. Pond offered a novel design point for discovery and a global network adversary. Katzenpost adapts mixnets to limit the power of network adversaries and server compromise in a different way. Private Information Retrieval (PIR) trades off high server costs for a scheme that could more realistically work with mobile clients. Others, for instance Secure Scuttlebutt attempt to remove the need for infrastructural servers entirely with gossip and partial views of the network, a whole other set of tradeoffs.

Will Scott

https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10565.html

more » « less
Video Language:
English
Duration:
01:00:06
http://www.youtube.com/watch?v=ezA01rs7n3s
Format: Youtube
Primary
Added   by C3Subtitles
Format: Youtube
Primary
http://www.youtube.com/watch?v=zYTznwBv4dg
Format: Youtube
Original
Added   by C3Subtitles
Format: Youtube
Original
http://www.youtube.com/watch?v=IpZeeNbZM9M
Format: Youtube
Added   by C3Subtitles
Format: Youtube
http://www.youtube.com/watch?v=kQEoCp3D3r8
Format: Youtube
Added   by C3Subtitles
Format: Youtube
Format: HTML5
http://www.youtube.com/watch?v=d1js0d-I8w0
Format: Youtube
Added   by C3Subtitles
Format: Youtube
http://www.youtube.com/watch?v=BpFs_1Fw02A
Format: Youtube
Added   by C3Subtitles
Format: Youtube
http://www.youtube.com/watch?v=Bhttps
Format: Youtube
Added   by C3Subtitles
Format: Youtube
This video is part of Amara Public.

Subtitles download

Completed subtitles (1)