4 ms·
‘World’s Most Secure’ Email Service Is Easily Hackable
- btschaegg 9y ago> A service that claims to be the only way to do email in a secure way [...] And that, kids, is what we call the Dunning–Kruger effect.
- geezerjay 9y agoMarketing ploys aren't exactly a sign of incompetence. Probably they made those claims expecting that no one would bother checking.
- btschaegg 9y agoFair point. Although that also only would implicate that maybe, there were competent people, it's just that no one bothered to ask them. I don't know if that's making the matter better or worse ;-)
- wand3r 9y agoI believe they "hacked" it by physically editing the SD card. If someone has unfettered access to your email server you're in bad shape. Iirc the payload required navigating to a link and downloading a malicious file...Each time the attacker wanted to run code.
- nickpsecurity 9y agoI've always said consider any product, even a security product, insecure by default until proven otherwise by careful inspection by people who know how to find flaws. This was the recommendation of those that invented information security. It was best approach then. It's still the best approach.
- bmh_ca 9y agoOr monetize the contrapositive. Eg bug bounties.
- nickpsecurity 9y agoBug bounties don't prove anything. They're actually popular among peddlers of insecure software. Only thing that proves something is someone who can find vulnerabilities in the system got enough access and time to find something if it's there. They might be paid or not. It's the level of review and who is reviewing that matters most.
- nyolfen 9y agoI would recommend changing this link to the linked writeup by Scott Helme: https://scotthelme.co.uk/nomx-the-worlds-most-secure-communications-protocol/ https://scotthelme.co.uk/nomx-the-worlds-most-secure-communi...
- detaro 9y agowhich also has been on HN a few days ago: https://news.ycombinator.com/item?id=14209874 https://news.ycombinator.com/item?id=14209874
- wand3r 9y agoThe nomx response was here yesterday. Apparently the guy flashed the SD card, rooted the device and used a payload written by a friend. According to their account none of this was reproduced w/ an off the shelf device rooted by nomx and placed on a network not 100% controlled by the attackers for the challenge