惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Cisco Talos Blog
Cisco Talos Blog
P
Privacy & Cybersecurity Law Blog
I
Intezer
Y
Y Combinator Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
N
Netflix TechBlog - Medium
The Hacker News
The Hacker News
AWS News Blog
AWS News Blog
aimingoo的专栏
aimingoo的专栏
A
About on SuperTechFans
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Stack Overflow Blog
Stack Overflow Blog
Hacker News: Ask HN
Hacker News: Ask HN
酷 壳 – CoolShell
酷 壳 – CoolShell
量子位
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
B
Blog
T
Tor Project blog
C
Cybersecurity and Infrastructure Security Agency CISA
云风的 BLOG
云风的 BLOG
博客园_首页
V2EX - 技术
V2EX - 技术
T
Threat Research - Cisco Blogs
腾讯CDC
宝玉的分享
宝玉的分享
博客园 - 叶小钗
罗磊的独立博客
S
Securelist
The Last Watchdog
The Last Watchdog
Google Online Security Blog
Google Online Security Blog
Scott Helme
Scott Helme
博客园 - 司徒正美
W
WeLiveSecurity
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Secure Thoughts
NISL@THU
NISL@THU
N
News and Events Feed by Topic
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
雷峰网
雷峰网
大猫的无限游戏
大猫的无限游戏
K
Kaspersky official blog
IT之家
IT之家

WIRED

‘Avatar: Aang, The Last Airbender’ Leaked Online. Some Fans Say Paramount Deserves the Fallout NASA Wants to Put Nuclear Reactors on the Moon AI Could Democratize One of Tech's Most Valuable Resources Microsoft Surface PCs Are Getting Big Price Hikes, and the Cheaper Models Are Going Away Why Amazon Is Buying Globalstar—and What It Means for Your iPhone The US Government Will Ask Data Centers How Much Power They Use MAGA Is Starting to Look Beyond Trump Allbirds Is Pivoting to AI Compute. Sure, Why Not Best Smart Smoke Detector (and Why You Still Need a Dumb One) 12 Best Standing Desks of 2026, Tested and Reviewed Best Wi-Fi Routers of 2026 for Working, Gaming, and Streaming Best GoPro Camera (2026): Compact, Budget, Accessories The Caves That Could Help Us Find, or Become, Aliens AI Slop Is Making the Internet Fake-Happy The Deepfake Nudes Crisis in Schools Is Much Worse Than You Thought In the Wake of Anthropic’s Mythos, OpenAI Has a New Cybersecurity Model—and Strategy Telegram Is Still Hosting a Sanctioned $21 Billion Crypto Scammer Black Market The FCC Has a Fast Lane for Complaints About Trump’s Media Critics Top iRestore Deals for Hair Growth and LED Therapy Devices Meta Is Warned That Facial Recognition Glasses Will Arm Sexual Predators You Should Be More Freaked Out by Shingles BYD’s Fastest-Charging Car in the World Is Astonishing—in Good and Bad Ways The 4 Best Water Filter Pitchers (2026): PFAS, Microplastics The Internet's Most Powerful Archiving Tool Is in Peril The Dumbest Hack of the Year Exposed a Very Real Problem AI Agents Are Coming for Your Dating Life ‘The Audacity’ Is the Broligarchy Takedown You Were Waiting For Why Is It So Hard to Fix an Electric Bike? (2026) Best 2-in-1 Laptops (2026): Microsoft, Lenovo, and the iPad There’s a Secret Ingredient to Making Luxury Ice at Home The Screen Time Legends Who Won't Put Down Their Phones Mammotion’s Spino E1 Is Affordable but Doesn’t Quite Deliver You Don’t Have to Drink Lukewarm Coffee Ever Again. Get a Warmer Zuvi ColorBox Review: Please Just Go to a Professional MacBook Neo vs. MacBook Air: Which One Should You Buy? Best Electric Cargo Bikes (2026): Urban Arrow, Lectric, Tern, and More ‘Crimson Desert’ Is a Cat Dad Simulator Your Push Notifications Aren’t Safe From the FBI Flight Path Data Shows How Mosquitoes Target Humans How the Internet Broke Everyone’s Bullshit Detectors The All-Clad Factory Seconds Sale Is Back—for Now (2026) Artemis II Astronauts Safely Return to Earth After Historic Flight Around the Moon Home Depot Spring Black Friday (2026): Best Tool and Grill Deals Motorola’s Souped-Up Folding Phone Is Almost Half Off Anthropic’s Mythos Will Force a Cybersecurity Reckoning—Just Not the One You Think The Future of the Artemis Program Is Riding on Reentry Suspect Arrested for Allegedly Throwing Molotov Cocktail at Sam Altman’s Home "Uncanny Valley": OpenAI and Musk Fight Again; DOJ Mishandles Voter Data; Artemis II Comes Home This Clever Bike Bell Can Even Be Heard by People Wearing Noise-Canceling Headphones This Startup Wants You to Pay Up to Talk With AI Versions of Human Experts I Did Not Catch Air on the Aventon Current Electric Mountain Bike, but I Could Have Best Smart Shades, Blinds, and Curtains (2026): Motorized, Tailor-Made, and More How 'Democracy Now!' Became the Blueprint for Indie Media AI Podcasters Really Want to Tell You How to Keep a Man Happy Irrigreen's New Smart Irrigation System Promises Smart Watering Without the Hassle—Almost No One Knows Where US Vaccine Policy Goes Next I Tried Asus' First Open Earbuds for Gamers Meta’s New AI Asked for My Raw Health Data—and Gave Me Terrible Advice How and When to Watch the Artemis II Mission’s Return to Earth Naturepedic Promo Codes and Deals: 20% Off Hungryroot Coupon Codes: 30% Off This April Govee Discount Codes and Deals: 30% Off We-Vibe Discount Codes and Deals: Up to 60% Off Sealy Promo Code: Save $200 on Mattresses This Month OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters China Is Cracking Down on Scams. Just Not the Ones Hitting Americans The 70-Person AI Image Startup Taking on Silicon Valley's Giants Save $20 on This Already Inexpensive Wireless Mic Set John Deere Is Paying Farmers $99 Million for Allegedly Monopolizing Repair The Iran War Is Tearing MAGA Influencers Apart The FBI Didn’t Answer Texts From Minnesota Investigators for Days After Renee Good’s Killing The Pro-Iran Meme Machine Trolling Trump With AI Lego Cartoons Ridge Wallet Review: A Beacon for the Overencumbered How Meta Cafeteria Workers Took on ICE—and Won Get Peace of Mind With This GPS and Activity Tracker for Pets I Asked Netflix’s Reality TV Boss Why So Many Men On Dating Shows Are Terrible I Tried TCL’s Samsung Frame Competitor and It Didn’t Compare Politicians Are Spending More Money on Security as They Increasingly Become Targets This AI Wearable From Ex-Apple Engineers Looks Like an iPod Shuffle Artemis II Astronauts Witnessed 6 Meteorites Colliding With the Moon Medicube Coupon Code: 40% Off for April 2026 Instacart Promo Code: $15 Off | June 2026 Vivid Seats Promo Codes and Deals: Get 10% Off Birdfy Discount Codes: 15% Off Sitewide Google Workspace Promo Codes: 14% Off for June Paramount+ Coupon Codes and Deals for June 2026 NZXT Discount Codes: 50% Off in June 2026 LG Promo Codes and Coupons for June 2026 AT&T Promo Codes: $50 Off This June 2026 TurboTax Full Service Coupons This June Top Peacock Promo Codes: 40% Off June 2026 Therabody Promo Codes: 15% Off June 2026 Surfshark Promo Codes: 87% Off | June 2026 Nomad Goods Promo Codes: Get 25% Off in June 2026 20% Off Sephora Promo Code | June 2026 30% Off Canon Promo Codes | June 2026 Factor Promo Code: 50% Off Off Meal Prep Top Dell Coupon Codes: 20% Off for June 2026 Walmart Promo Codes: Up to 65% Off for June 2026 What Is the Best Fitness Tracker in 2026? Garmin, Oura, More
Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps
Andy Greenberg · 2026-06-11 · via WIRED

The new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.

Image may contain Person and Adult

Photo-Illustration: WIRED Staff; Getty Images

End-to-end encryption, in which data is encoded so that only users on either “end” of a conversation can decrypt their communications—and not the server that relays that information or any other interloper—has become the standard for modern privacy on the internet. But its very name suggests a kind of simple pipe with two openings. The metaphor, and often the encryption technology that has enabled that model, doesn't fit neatly onto the world of Slack, Discord, Google Docs, and the other multiuser, complex, collaborative software where people now live and work.

So one group of cryptographers has built what they describe as the foundation for a new generation of end-to-end encrypted apps, with a new metaphor: Instead of a mere pipe, they want to create “spaces” where users can hold group conversations, host information on a server, collectively make changes to it, invite in new collaborators or kick them out, all while maintaining the same strong encryption protections that prevent the server or network eavesdroppers from accessing their data.

That cryptographer team, including contributors from Harvard, Microsoft Research, and former developers of the end-to-end encrypted messenger Signal, today release a “preview” of Encrypted Spaces, an early version of a set of open-source code libraries, which is part of an architecture they've designed to allow anyone to easily build a rigorously end-to-end encrypted app that nonetheless enables all of the complex collaboration features that users demand from software today.

The group says it saw an opportunity in the migration from single-user apps and one-to-one messengers to multiuser collaboration tools. The transition comes at the same time as the advent of new cryptographic tricks—namely, “zero-knowledge proofs”—that enable computers to manipulate and verify the integrity of encrypted data without seeing its contents. “These pieces kind of fall into place to leave us with a moment of technological shift where we can inject encryption and privacy,” says Nora Trapp, an engineer at Harvard’s Applied Social Media Lab who has also worked as a technical lead for Signal. “We want to provide the technological surface area for developers to build all these apps in a privacy-preserving way."

Among the cryptographers working on the project is Trevor Perrin, the cocreator of the Signal protocol, the open-source encrypted messaging system used not only in the hundred-million-plus phones with Signal installed but also in the billions of devices that use WhatsApp and Facebook Messenger.

Image may contain Computer Electronics Pc File Screen Computer Hardware Hardware and Monitor

A screenshot of a research prototype collaboration app built with Encrypted Spaces.

Courtesy of Encrypted Spaces

Encrypted Spaces is, in some sense, the next generation of the Signal protocol, but for more complex and fully featured tools that go beyond messaging and calls, says Matt Green, a cryptography-focused professor of computer science at Johns Hopkins. “They've built a system that's kind of an extension of what end-to-end encryption can be, where you have an actual architecture for doing end-to-end encrypted collaboration,” says Green, who reviewed a white paper outlining the Encrypted Spaces project and a prototype application. “You can think of it as the Signal protocol for collaboration apps.”

Unlike Signal, however, the code that the Encrypted Spaces group has released is, for now, not a single, ready-for-use application. Instead, it's a code repository that the group is inviting cryptography researchers and developers to review, with the goal of eventually allowing coders to build their own encrypted collaborative apps—but without needing any cryptography knowledge. “We want to make it so there's no reason a developer wouldn't want to make their application end-to-end encrypted, because it becomes so easy,” Trapp says.

Change Logs and Zero-Knowledge Roll-Ups

Encrypted Spaces aims to deal with a crucial limitation of end-to-end encrypted apps: Because the server can't decrypt users' data, any manipulation of that information has to take place on the users' devices. That works well enough when the app is a pipe connecting two users' phones, each of which holds a key to decrypt their conversation. But when the app is a collaborative platform with dozens or hundreds of users working together, that model of end-to-end encryption creates a severe constraint: The app can't simply store users' information on a server and manipulate it in that centralized location as it would for an unencrypted platform like Slack or Google Docs.

Encrypted Spaces offers a new model: An app built with it manages data from a centralized server and let users collectively make changes to that information while still keeping it encrypted. More specifically, Encrypted Spaces keeps a change log—a record of every change to encrypted data that the users make over time—that can be shared with the app on every user's phone or computer, so that the app can implement those changes locally and keep everyone's version of the information synched and up to date.

The server uses zero-knowledge proofs, a relatively new cryptographic technique, to prove to every user's device that no changes are missing and no rogue changes have been made, but without the server ever accessing the unencrypted data or the changes to it. (Hence “zero knowledge.”) In fact, Encrypted Spaces can use a kind of “roll-up” property of zero-knowledge proofs to ensure that every user has the latest version of their group's data without actually applying every change in the whole change log. “The server can roll up the changes into a succinct proof that this current state reflects the entire history,” says Perrin. “It can convince you it's applied the change log correctly without actually having to send it.”

The server also uses zero-knowledge proofs to oversee how people's devices manage the cryptographic keys that allow only authorized users to decrypt and alter the data, allows new users to be invited in, and can provably revoke their access if someone leaves the group. The space's users can also choose to share the full history of the app or to limit a new invitee to new messages or data added after they entered.

The Encrypted Spaces team showed WIRED a demo of a prototype application it calls Spaces, which it also released Thursday. (They recommend the software not be used in its current state but instead treated as a research prototype.) In the demo, the Spaces prototype appeared to be a fully functioning, end-to-end encrypted Slack- or Discord-type app with added group notes, calendar, and file-storage functions, but still lacked certain features like voice calling and search.

Plenty of collaboration tools already offer some sort of end-to-end encryption, to be fair, such as Proton's suite of cloud-based apps including file storage and document editing or similar suites from CryptPad or Nextcloud. Software including Matrix and Nextcloud also offer Slack- or Discord-like end-to-end encrypted group messaging platforms.

Encrypted Spaces, however, provides an open-source, credible foundation for a more rigorous and standardized approach to building those apps or whatever comes next, says Johns Hopkins’ Green—as well as an enormous head start for anyone who wants to securely code an encrypted tool. “I like the idea that we're going to have a standard library for this that a lot of people can review,” says Green. “And if you use this library, you inherit all the security for free.”

From Signal to Spaces

The effort behind Encrypted Spaces originated, at least in part, within the team that develops Signal. In 2019 and 2020, Signal's developers, including Trapp and Perrin, were working on upgrading Signal's group-chat feature to better preserve the privacy of group members, so that Signal's servers could manage who was included in a group but without keeping any unencrypted record of that member list. They ended up partnering with cryptographers at Microsoft Research to build a new “anonymous credentials” system that used zero-knowledge proofs to maintain that member list on the server without ever exposing it.

Image may contain Page Text Computer Hardware Electronics Hardware Monitor and Screen

A screenshot of a research prototype collaboration app built with Encrypted Spaces.

Courtesy of Encrypted Spaces

That server-side, encrypted, verified list of a group chat's participants represented a new security model for Signal, which had otherwise generally kept as much data as possible on users' devices and used servers only as simple pipes for relaying it. At some point, Perrin says, they began to wonder what other features that approach—using zero-knowledge proofs to allow for more manipulation of encrypted data stored on the server—could make possible. “If we're doing this encryption for the membership list in this very consistent, nice, provable way, why couldn't we just kind of do this for everything?” Perrin says. “Why couldn't we just kind of move all of the data into something like this?”

That thinking eventually led them to a more ambitious thought, as Microsoft Research’s Greg Zaverucha describes it: “Why can't we have end-to-end encryption in all the apps we use?”

Seven years of on-and-off work later, Encrypted Spaces has finally released its open-source code repository. Microsoft Research’s Mary Gray, an anthropologist and technologist with a focus on privacy, is also leading an effort to collaborate with Bay Area community and social services groups to develop Encrypted Spaces and build prototypes designed with their needs in mind.

If Encrypted Spaces succeeds in its goal of unleashing a new generation of end-to-end encrypted apps of all kinds, those apps will no doubt be used for less wholesome purposes, too. Mainstream messaging platforms already serve as a conduit for plenty of cybercriminal groups. Encrypted versions of those apps would no doubt stymy law enforcement's ability to surveil some people causing real harm.

But Trapp stresses that the familiar argument about a small minority of bad actors shouldn't stand in the way of creating platforms that better protect everyone's privacy by default, instead of unthinkingly inviting sensitive conversations and collaborations while leaving users vulnerable to surveillance. “We have a general expectation of privacy in our real lives in the physical world,” she says. “We should be afforded that same right in the digital world, instead of building an internet with surveillance as a built-in aspect of its design.”

After all, encryption is already arguably becoming the norm in other realms of the internet, now that practically every website uses HTTPS encryption and Signal has helped to end-to-end encrypt the text and voice conversations on billions of phones and laptops. Why, in the midst of that great migration toward encryption, should your Slack and Google Docs remain as exposed as a postcard?

“In the same way that Signal became the status quo in the messaging space, technologies like this can become the status quo across all of application development,” Trapp says. “I hope that this just becomes how all apps work: that we have end-to-end encryption on every app on our phone and that it's a sort of de facto standard, and it just helps reinforce that privacy is normal.”

Andy Greenberg is a senior writer for WIRED covering hacking, cybersecurity, and surveillance. He’s the author of the books Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency and Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers. His books ... Read More