9 ms·
The article mentions WhatsApp multiple times as a service that successfully made the transition to end-to-end encryption, but it always seemed to me that this c
by dromenkoning 10y ago
The article mentions WhatsApp multiple times as a service that successfully made the transition to end-to-end encryption, but it always seemed to me that this claim is rather meaningless when we don't have the possibility of auditing their source code.
- xapata 10y agoHow can you personally verify that any 3rd party service is doing what it claims? Unless you're a security expert with plenty of time to comb through someone else's code, you're still relying on others to be truthful and competent. Even then you're relying on layers upon layers of software and hardware. Far too much for an individual to verify.
- holri 10y agoYou rely on a net of diverse independent reviewers instead of a single entity with a particular interest. A peer reviewed distributed trust net is much more trustworthy.
- homakov 10y agoThere's no such net, nobody is signing the binaries.
- xapata 10y agoThat single entity consists of many diverse individuals with differing ethics. As much as the law might try to pretend, companies are not people. Uh, except in the sense that they are compromised of people. So, they literally are people, people combined with capital.
- holri 10y agoPeople in a single entity are by definition not independent.
- xapata 10y agoIn that sense, no one is independent. We've all got friends and family, or at least people we know. By definition, if you've heard of someone else's software, that person had a social network by which they distributed the software to you.
- holri 10y agoSocial dependency is not binary. Developers in a company a much more dependent from each other and the boss, than reviewers of free software.
- xapata 10y agoVery true. Maybe I misread your previous comment as being more binary than you intended. Keep in mind that reviewers of free software are also often employees and may have some agenda beyond pure altruism, even if the software isn't copyright of the employer. Open source is big business these days.
- holri 10y agoMaybe Open Source is big business, but not free software.
- 10y ago
- colordrops 10y agoIt seems that most people are completely in the dark when it comes to security, including myself, but there are some principles that should be unwavering that regularly get ignored again with every new iteration of "secure" software: * If there is a weak layer in the stack, from the physical layer to to UI, then the system is not secure. Even if your messaging app is secure, your messages are not secure if your OS is not secure * If the source code is not available for review, the software is not secure * If you or someone you trust has not done a full and thorough review of all components of the stack you are using, the software is not secure * Even if the source code is available, the runtime activity must be audited, as it could download binaries or take unsavory actions or connections. * On the same note, if you do not have a mechanism for verifying the authenticity of the entire stack, the software is not secure. * If any part of the stack has ever been compromised, including leaving your device unlocked for five minutes in a public place, the software is not secure. I could go on, and I'm FAR from a security expert. People compromise way too much on security, and make all kinds of wrong assumptions when some new organization comes out and claims that their software is the "secure" option. We see this with apps like Telegram and Signal, where everyone thinks they are secure, but if you really dig down, most people believe they are secure for the wrong reasons: * The dev team seems like honest and capable people * Someone I trust or some famous person said this software is secure * They have a home page full of buzzwords and crypto jargon * They threw some code up on github * I heard they are secure in half a dozen tweets and media channels
- espeed 10y agoThe Signal protocol (https://en.wikipedia.org/wiki/Signal_Protocol https://en.wikipedia.org/wiki/Signal_Protocol) has been vetted, and the code is online available to be audited: - Signal code: https://github.com/whispersystems/ https://github.com/whispersystems/ Telegram has had known flaws, which have been discussed in part here: - Telegram protocol defeated. Authors are going to modify crypto-algorithm https://news.ycombinator.com/item?id=6948742 https://news.ycombinator.com/item?id=6948742 - A Crypto Challenge For The Telegram Developers https://news.ycombinator.com/item?id=6936539 https://news.ycombinator.com/item?id=6936539 - Telegram (initial discussion) https://news.ycombinator.com/item?id=6913456 https://news.ycombinator.com/item?id=6913456 https://hn.algolia.com/?query=telegram&sort=byPopularity&prefix=false&page=0&dateRange=all&type=story https://hn.algolia.com/?query=telegram&sort=byPopularity&pre...
- mjg59 10y agoIt's not hard to demonstrate that apps are performing end-to-end encryption even if you don't have access to the source code. Reverse engineering this stuff is really pretty straightforward.
- dingaling 10y agoIt's not just that they're performing encryption, but also assurance that (1) they're using the keys they declare and (2) they aren't sending other data over unannounced side-channels. You can't just insert yourself in the message stream since the client and server use pinned, mutual certificate authentication. So you have to start from first-principles and step through decompiled code.
- mjg59 10y ago> they're using the keys they declare I'm not sure what you mean here. It's easy to identify where the key comes from and whether the ciphertext is what you'd expect it to be in that case. > they aren't sending other data over unannounced side-channels. It's not straightforward to determine that even if you do have the source - you could imagine an implementation that deliberately leaks information through timing details without that being obvious from the code. At some point you have to trust that authors aren't doing something awful. > So you have to start from first-principles and step through decompiled code. Well no, because the first thing you can do there is just disable certificate pinning. But really, the difficulty of stepping through decompiled code is vastly overrated.
- fidget 10y agoUnannounced side channels seems like by far the easiest thing to deal with there; send a 2mb file, observe network patterns, raise an eyebrow if 2mb gets sent over a channel that you didn't expect. As for using the correct key, dismantle the signal message envelope until you get your blob of encrypted message. Then see if the same blob appears on the target device. Multiple keys? I imagine either correlating message size and network traffic (encrypting stuff twice could well show up), or going at it with a debugger. Which is really the answer to all of these questions instead of any network shenanigans. You root your phone and attach a debugger, then step through what signal is doing. Not a security researcher, never reverse engineered anything for security reasons in my life.
- oculusthrift 10y agoif the cia has to bypass it by hacking users phones it seems to apply the encryption itself is solid.
- mirimir 10y agoThere are no secure smartphones (devever.net) https://news.ycombinator.com/item?id=10905643 https://news.ycombinator.com/item?id=10905643
- uladzislau 10y agoPuff and bluff. Assume that they are trying to save their asses only.
- benevol 10y ago> this claim is rather meaningless when we don't have the possibility of auditing their source code Open source is required not just for apps, but also for: - operating systems - drivers - firmware Then we can start to talk about privacy.
- imaginenore 10y agoYou forgot - hardware
- astrange 10y agoHave you tried learning assembly? It's not hard or anything.
- icantdrive55 10y agoFrom vault 7, "These techniques permit the CIA to bypass the encryption of WhatsApp, Signal, Telegram, Wiebo, Confide and Cloackman by hacking the "smart" phones that they run on and collecting audio and message traffic before encryption is applied." 1. O.k.--they are having a tough time with encryption--now. If they are intercepting information before the encryption, what's the point of encryption? (Yes--encryption is great, and we need it. It's just it doesn't seem like the CIA cares about it too much? We will need it for our everyday business.) 2. With the billions these Founders will make; how long will it be until they cave into threats by the CIA, NSA, IRS, etc., and just help the powers at be? "Here's the keys, or this is your backdoor. "I just don't want my meticulous life complicated." A poor man doesn't have anything to lose, so they might be the most trustworthy? (And don't tell me about morals. The successful founders have all bent the rules, or did something shady. You just need to dig. Yes--I'm stereotyping, and prove me wrong.) 3. An app, or hardware with real privacy will be hard to obtain. 4. A lot was redacted by Wikileaks. He redacted 10,000 spies. How do we know if he didn't redact information that would affect a IPO? 5. It used to be, "Don't trust a person with nothing to lose? For my seat, it's revered now, "Don't trust a 1 percenter who has a lot to lose." The government could make a Mennointe lose sleep at night with their shinagigans. 6. Yes--this is my dig at the "man". I don't believe 99.9% of them really care about their customers privacy. It's just grand standing. They care about money, and their lives, and maybe a few pet projects. 7. Assange has a lot of power at his fingertips. The only reason he hasen't been killed is they are scared. 8. Maybe the CIA shouldn't have computers at this point in history?
- Certhas 10y agoWhy do you think it is completely meaningless? I agree that it's weakened but I think it's still meaningful. If someone is choosing between WhatsApp and Allo the former is more likely to be properly encrypted. After all, even though we can't verify it WhatsApp has strong incentives to implement it properly, and OWS has strong incentives to only endorse WhatsApps use of their protocol if they are convinced that it's done properly. I really think "completely meaningless" is dangerously misleading hyperbole.
- CiPHPerCoder 10y agoWe don't need to audit the source code. Just grab the binary, reverse engineer it, and study that. There's an entire industry dedicated to reverse engineering software and studying its security properties. We call it the security industry. (Not every gig is white-box!)