TechLife Australia

Private messaging

HOW TO CHAT WITHOUT BIG BROTHER LISTENING IN.

-

RECOMMENDE­D APP: SIGNAL PRIVATE MESSENGER

Last year, with bipartisan support, new metadata collection laws were introduced to Australia. e laws required that ISPs and telecommun­ications providers kept a record of pretty much all communicat­ions crossing their networks for a period of at least two years from the date of said communicat­ion. e captured informatio­n would include all metadata relating to the communicat­ions, including: e date, time and duration of a phone call e name, address and billing informatio­n of the user e IP addresses and email addresses of the senders and recipients e type of service in use (phone, SMS, social media and so on) e physical location of the telecommun­ications device (which mobile tower, for example) Essentiall­y any time you send a message to another person, it’s recorded and kept on le.

While the metadata laws don’t require that the ISPs and telcos record the actual contents of the messages, we do know from the Snowden leaks and other sources that wide-ranging intercepti­on and monitoring of content is happening. Service providers like Microso /Skype, Facebook and Google have had standing relationsh­ips with signal intelligen­ce agencies to record and deliver captured messages on legal request, while large-scale monitoring of internatio­nal internet links is essentiall­y standard practice for signal intelligen­ce agencies.

If you want to avoid such government monitoring — or are simply uncomforta­ble with providers like Skype having a complete record of everything you ever said on it — then you need a messaging service that supports two things: Strong end-to-end encryption No metadata collection End-to-end encryption means that the only people who can read the message are the

WHILE THE METADATA LAWS DON’T REQUIRE THAT THE ISPS AND TELCOS RECORD THE ACTUAL CONTENTS OF THE MESSAGES, WE DO KNOW FROM THE SNOWDEN LEAKS AND OTHER SOURCES THAT WIDE RANGING INTERCEPTI­ON AND MONITORING OF CONTENT IS HAPPENING.

sender and the receiver — they are the only people that have the keys to encrypt and decrypt the messages. To everybody else in between, it’s just unusable gibberish. Not even the service provider can read the message. No metadata collection is trickier, since it relies on trust in the app provider’s word with respect to metadata. ere are some purely peer-to-peer comms services for which there is no metadata, but they tend to be highly technical. All of which bring us to Signal Private Messenger ( whispersys­tems. org), our current pick for private communicat­ions. It’s easy to use and ticks both of those boxes. It supports end-end-end encryption with manual authentica­tion to prevent man-in-the-middle attacks. It uses servers that could technicall­y collect metadata, but Open Whisper Systems says no metadata is collected by it, and there are no records kept of communicat­ions between clients. Using Signal is very easy once it’s set up, since it integrates into your phone’s contacts. It works a bit di erently, depending on whether you’re using Android or iOS, since Android allows for deeper integratio­n. Essentiall­y, it works with your SMS and phone system on Android; on iOS, it’s a separate app independen­t from SMS and phone. In both cases, however, it uses your regular contacts list and automatica­lly detects if anyone on it also has Signal, so you don’t need to set up an independen­t contact list. To use it, just follow these steps: Grab the app from the iTunes App Store or Google Play (there’s also a PC version that’s in beta, but it still requires an Android device to act as a relay).

e rst thing that will happen is that you’ll be asked to verify your mobile number. Enter you mobile number in the eld provided, then tap ‘Verify this device’.

If you’re on iPhone, you’ll receive a veri cation code via SMS that you’ll need to enter into the app. If you’re on Android, you can skip this step; it can read your SMSs and extract the number automatica­lly. On iPhone, Signal will also ask you to grant it permission to access your contacts. Tap ‘OK’. You may also be asked if you want to allow Signal to send noti cations.

Once you’ve done that, tap on the compose button on the top right (iPhone) or bottom right (Android). A list of all the people on your contact list who also have Signal will appear. If there are none, you can tap on ‘invite contact’, which will send an SMS to a person on in your contacts with a link to Signal.

Tap on a name to send them a text message. If you’d like to make a phone call, tap on the phone icon next to their name. On iOS, you’ll only be able to message/call people with Signal from within the app. On Android, you can message anybody in your contact list, but if the recipient doesn’t have Signal (the presence of which is indicated by a closed lock icon), then it will use normal unencrypte­d SMS or phone calling to communicat­e.

You can also create groups and start a group chat by tapping on the group chat icon in the top right.

When you’re making a call, two words will appear on screen. Verify that the person you’re speaking to is seeing the same two words (just ask them). is is a protection against man-in-the-middle attacks. If you’re seeing di erent words, then somebody is potentiall­y listening in.

 ??  ?? Verify your phone number (iOS). Click on the compose button to start (iOS). On Android, a closed lock icon indicates that a person has Signal and that messages are secured.
Verify your phone number (iOS). Click on the compose button to start (iOS). On Android, a closed lock icon indicates that a person has Signal and that messages are secured.
 ??  ??
 ??  ?? You’ll see a pair of (probably) nonsense words appear on screen. You and the person you’re speaking to should see the same words.
You’ll see a pair of (probably) nonsense words appear on screen. You and the person you’re speaking to should see the same words.
 ??  ??

Newspapers in English

Newspapers from Australia