10 ms·
Darknet Messenger Briar Releases Beta, Passes Security Audit
- kobeya 9y agoFeedback: darknet has come to mean places where you go buy drugs online, not p2p applications generally.
- freshhawk 9y agoDoes it? I know it has that meaning on the evening news, but even on network television it means something like "the secret internet where crazy stuff is". I mostly hear it used to mean what it is supposed to mean, but that is rarely from non-technical people.
- Veratyr 9y agoThe problem is that as long as the name has that association at all, it's going to be a way to attack Briar. Darknet now: Anonymous place drugs sometimes happen Darknet if it becomes bigger: That place where terrorists and criminals hide, the FBI and NSA say it's a risk to national security and we have to stop it at all costs! What do you mean it's just a secure messaging app? I'm not a terrorist, I don't need anything like that!
- rhizome 9y agoThey already say that about encryption in general, though.
- Veratyr 9y agoYes but there's also a number of existing applications of encryption that are widely deemed acceptable, like securing bank transactions and medical data. Anonymity is much harder to defend, as it doesn't have such clearly worthy purposes.
- the8472 9y agoYou could also see it the other way around, your application is not secure enough if terrorists, dissidents, drug dealers, whistleblowers and child pornographers don't feel confident to use it. Look at Tor.
- Veratyr 9y agoYou could but I doubt the general public and policy makers are going to see it this way. They're still looking for a backdoor that only the "good guys" can access.
- sam4ritan 9y agoOnce again proving that they dont know how any of this works. And still getting re-elected
- lucaspiller 9y agoFrom an ethical point of view building this software must be difficult. On one hand you are building something that advances technology and could be used to help free people from an oppressive government, on the other hand you are also building something that could be used (and if it works most likely will be used) to aid acts that we all agree are morally wrong.
- thaumasiotes 9y agoAh, the essential ethical dilemma of building encryption software, polaroid cameras, and kitchen knives.
- leshow 9y agoPick almost any technology, even outside of computers. You could make the exact same statement. I don't see the ethical problem.
- Angostura 9y agoWhat is it supposed to mean?
- throwaway91111 9y agoThis is also true of the term "hacker", which is still heavily (and authentically) used
- JoeCoder_ 9y agoWhy not develop tox instead, which is open source, end to end encrypted, on more platforms, and seemingly further along in general?
- secfirstmd 9y agoBriar is also e2e and open source. It also has a ton of mesh networking features that Tox doesn't have.
- sldoliadis 9y agoCan you say a bit ore about the mesh network features of Briar? I've looked through a lot of the documentation and can't find anything other than references to bluetooth and wi-fi, which is opaque to me. I'm kind of wondering about something like briar, but that can connect over a cjdns network if available... is that what it's doing?
- deleted 9y ago[deleted]
- hannob 9y agoMaybe because tox is developed by people who don't know what they're doing. Money quote from a tox dev: "Tox provides some strong security guarantees. We haven't got to the point where we can enumerate them properly, given the general lack of understanding of the code and specification." https://github.com/TokTok/c-toxcore/issues/426 https://github.com/TokTok/c-toxcore/issues/426
- vonuebelgarten 9y agoI have the impression Tox withered and died, which is really sad considering how usable (when compared to alternatives) it is.
- sldoliadis 9y agoFWIW, the git repository looks like it was worked on within the last couple of days.
- baby 9y ago"passes security audit". Is security audit an exam? What does passing mean?
- QAPereo 9y agoPurely naively I would guess that it means during whatever audit they ran, no signs of insecurity were observed. Maybe it would be better to say that it didn't "fail" the audit?
- sillysaurus3 9y agoYou can't really fail an audit though. The point of an audit is to make your application more secure. Using terms like pass/fail just reinforces a sense of fear where there shouldn't be any. A pentest consists of an analysis period, typically about a week. Then any flaws in your app are communicated to you, along with steps to reproduce them. When you feel you've fixed the issues, a retest is scheduled and the pentesters verify that each flaw has been fixed. A healthy application is one that's pentested on a regular basis. Ideally after every release, though only big companies can afford that.
- QAPereo 9y ago>You can't really fail an audit though. The point of an audit is to make your application more secure. Using terms like pass/fail just reinforces a sense of fear where there shouldn't be any. I see, that's a good point I hadn't considered.
- lawnchair_larry 9y agoWant to guess how many audits Microsoft Windows "passed" before the SMB bug exploited by WannaCry became public? :) That was one of the most heavily audited components too.
- burkaman 9y agoYes, a security audit is an examination of an application and the processes around it. In this case passing means the application "is able to offer a good level of privacy and security. In other words, the Briar secure messenger can be recommended for use."
- pasbesoin 9y agoMore "Darknet". I almost passed this by. I'm glad I took a peek. This is actually interesting to me. ...Briar is a secure messaging app for Android. Unlike other popular apps, Briar does not require servers to work. It connects users directly using a peer-to-peer network. This makes it resistant to censorship and allows it to work even without internet access. The app encrypts all data end-to-end and also hides metadata about who is communicating. This is the next step in the evolution of secure messaging. No communication ever enters the public internet. Everything is sent via the Tor anonymity network or local networks.
- siberianbear 9y agoI downloaded the beta and installed it, but I guess I need to physically find a friend who also installed it. I'm not in Silicon Valley, so I doubt that will happen soon....
- shellbackground 9y agoJust leave USB stick somewhere in Nsk and I will catch it.
- vonuebelgarten 9y agoSame problem here. Despite this being the best MITM-prevention strategy, it will be hard to assemble a group of people. Maybe allow copying/pasting keys but with a Signal-style post-validation or something like a PGP wordlist to allow voice-based confirmation?
- tptacek 9y agoIt's ironic that this update plays up how Briar "hides metadata" when the audit found that the application deanonymizes its users by exposing DNS lookups during RSS updates.
- e12e 9y agoIndeed. On the plus side, I found the audit very readable, and a great source for some good Android security advice. I do wonder what plans are in place for migrating user data and identities - of all electronic devices, the one most likely to be lost, stolen, broken has to be the phone - and it's not really great if loss of the device means loss of access to the network and built-up web-of-trust. I see there's a mechanism to introduce contacts to each other - perhaps that could be implemented (technically) similar to pgp key signing/web-of-trust - that would still require a means to backup ones secret key, in order to regain access though.
- boomboomsubban 9y agoThis is the first public beta, so presumably anyone testing the software were well aware of the risks, and they would fix the vulnerabilities found before making the release.
- goapunk 9y agoThat's the reason the audit was made before the public release of the beta. The bug is fixed in the public beta ;)
- grote 9y agoThe article says: "All the issues found by the audit have been addressed in this beta release."
- gcb0 9y agoso the current version isn't audited? if they changed the code and design after the audit, then much worse bugs might be hiding now, until that version is audited.
- hamandcheese 9y agoAs far as the audit, I feel like 13 days is surprisingly short. I base this on my experience getting new jobs and familiarizing myself with new code bases. Maybe I'm slow.
- dsacco 9y ago13 days (let's call it two weeks, assuming full person/weeks of time) is not atypical for an assessment. If you have multiple people working simultaneously on a two week assessment, you can "comfortably" assess fairly complex applications. What is surprising to me is that so little of that time was devoted to cryptography. For a secure messenger that time should be ratcheted up a bit (though the security infrastructure and general software implementation stuff is also very important).
- lawnchair_larry 9y agoIt depends heavily on how much code there is and what language it's written in. Also, code auditors can often eliminate large swaths of the codebase with high confidence when it's clear that there is no attack surface, so it isn't always necessary to grok the whole codebase.
- softwarelimits 9y ago"Darknet" is a brainwashing propaganda term. Please do not use it, thanks.
- thinbeige 9y agoWhat is the right term then?
- Angostura 9y agoDifficult to know in this context - what meaning do you think they weed trying to convey, assuming that “designed for illegal use” wasn't it.
- PeterisP 9y agoWho knows? The whole problem is that "darknet" is a label that doesn't mean anything definite, a buzzword but not a term. You may say that a tool/network/protocol is decentralized and/or secure and/or anonymous and/or censorship-resistant and/or routed through Tor and/or doesn't leak identity and/or tamper-resistant and/or has plausible deniability etc etc and all these labels would mean something - "darknet" does not. A "darknet messenger" might tick any set of these boxes, but the meaning is completely different depending on which of these labels apply.
- captainmuon 9y agoThis looks interesting, but I wonder how safe it is in the stated use case of journalists, activists in an authoritarian country. It can use Tor, which hides whom you are communicating with, but the fact that you are using Tor sticks out like a red thumb. The authorities probably just have to flip a switch to put you under closer surveillance if they see you use Tor. Or they'll just send someone to your registered address and see whats going on. What I really think would be cool would be a protocol based on massive steganography and obfuscation. You would have kernels which tell it how to wrap data in an innocent looking container (HTTPS traffic, SMT, IRC, Cat pictures and recipies over plain HTTP, DNS, ICMP pings, ...). Ideally, you would have dozens. And they would be shareable between nodes. You could define them in a DSL, and make them sandboxed and provable (that they round-trip, i.e. can decode what they encode, and terminate properly - that restricts what you can do in them though). You could even autogenerate the kernels. The last two points would require a bit of R&D of course. The goal would be to be able to create new "protocols" faster than authorities can learn to detect them. Then wrap a regular encrypted protocol in this obfuscation layer.
- abrichr 9y agoMaybe I'm missing something, but if the protocol were well defined and open source, it would be trivial to detect, no?
- captainmuon 9y agoNot really, the idea would be to hide data by using different amounts of spaces in text files, in the least significant bits of pixels in images, or in the access pattern to a certain service. The data looks like legitimate traffic. You could run the tool on absolutely all traffic, but that would be computationally intensive. And the data you get out is still encrypted, so ideally you can't tell if it is random (from extracting data where none is hidden) or real encrypted data. Also, you would have dozens or hundreds of kernels, and you could generate them by analyzing innocent traffic, or hiring a bunch of students to write them quickly. My idea is that the kernels are not part of the source code per se, but rather distributed by the protocol. To contact somebody you need to speak a common kernel, but then they can send you new kernels automatically. You could come up with a measure of how well kernels survive censorship and use that to decide which to pass on. It's a bit like auto updating malware, but for good :-). My only novel idea is to make a DSL or bytecode for the kernels, so that you can prove that they are benign and correct, and autogenerate them or use kernels from strangers. I don't know at all if this is feasible or not, but I have a couple of ideas how to make it work. No where near a POC yet so this is all still wishful thinking though.
- Tepix 9y agoIt's not yet available via F-Droid… is it planned?
- lawnchair_larry 9y agoAs someone who does professional security audits, I would just like to say that there is no such thing as "passing" a security audit. In fact, most pen testing shops will carefully dance around actually making that claim in writing for a customer, because they know they are going to look bad when a bug is inevitably found in code they reviewed (and it's probably a dumb idea for liability reasons too). There are certain certifications with falsifiable conditions that can be marked pass/fail. But, as I'm sure many folks here are aware, these are incomplete and often completely dubious. They don't purport to be "security audits". What a real security audit tells you is that of the (probably 2-4) consultants that looked at a product for a few weeks (probably 2-6), these were the security bugs they found. That alone contains little information, because the skill level and domain expertise varies greatly among consultants and companies. I can guarantee that if these results were withheld, and they gave the same codebase to another reputable outfit, the set of findings would be very different. There would likely be some overlap, particularly in the most obvious types of bugs, but bug hunting is way closer to art than science. I know nothing about this project, and my intent is not to create doubt, but users of secure messaging apps should understand what an audit is and what it isn't. Like other commenters, I was surprised to see 3 days of looking at crypto. It could be that the crypto is extremely simple and uses a few well understood APIs in a straightforward way, so this isn't a guaranteed red flag by any means, but it's a bit unusual. And like any software, this is a 1 line patch away from being blown wide open. With every commit, an audit becomes increasingly meaningless. Just ask cperciva! And perhaps I'm being cynical, but I always felt like the "conclusions" section of the audit report has an unspoken purpose of walking back from calling their baby ugly and keeping a decent rapport to ensure the possibility of future business. Not that I think what Cure53 wrote was not genuine, but there are natural incentives to be a little generous there. Again, I'm speaking from experience writing those sections as well. Edit: Basically what tptacek said.
- joveian 9y agoI haven't looked at the audit yet (and agree with your comments), but I can say a bit about what Briar is doing with crypto. The focus is on a time window based hash derivation of keys for symmetric cryptography and tags to recognize streams. It currently uses blake2s and XSalsa20/Poly1305. Bouncy Castle is used for the core algorithm implementations when possible. Connections are made via QR code and use ECDH with cofactor multiplication. There is also a simple bittorrent-inspiried synchronization level that is new and an encrypted storage layer for data storage (I'm not sure but I think this may use pre-existing code). So there is some amount of crypto to look at but it is fairly basic and not doing anything exotic. The layering and heavy use of symmetric crypto makes the crypto simpler than might be expected based on the features (and battery use heavier). Version 1 of anything is likely to have issues and hopefully even the release will have a disclaimer to that effect, but there is always a tradeoff between needing some amount of support for further development and trying to make the best app possible before releasing. Briar has been in development for years and they are aware of that tradeoff and trying to both be cautious and not allow the project to die from lack of usable result. The transport layer spec is at: https://code.briarproject.org/akwizgran/briar-spec/blob/master/protocols/BTP.md https://code.briarproject.org/akwizgran/briar-spec/blob/mast... QR code based key exchange spec is at: https://code.briarproject.org/akwizgran/briar-spec/blob/master/protocols/BQP.md https://code.briarproject.org/akwizgran/briar-spec/blob/mast... Sychronization layer spec is at: https://code.briarproject.org/akwizgran/briar-spec/blob/master/protocols/BSP.md https://code.briarproject.org/akwizgran/briar-spec/blob/mast...
- deleted 9y ago[deleted]
- slim 9y agoI love the fact that the "build from source" section is for everyone, not just developers. It's illustrated with screenshots https://briarproject.org/building.html https://briarproject.org/building.html
- raymond_goo 9y agoCan someone explain how it deals with routers and NAT ? Does it use UDP hole punching ?
- Deathmax 9y agoThe app hosts a Tor hidden service which other peers can connect to. No NAT punch through required as Tor will relay messages instead of a direct P2P connection.
- xcopy 9y agolike
- deleted 9y ago[deleted]
- bartread 9y agoI love the fact that this is a "darknet" messenger service called Briar: "Black Briar". Now where have I heard that before?
- mxuribe 9y agoWow, i had never heard of this project. I'm very much a fan of matrix protocol, and associated riot app...but - besides differences in protocol - I really like the addition of blog posting and rss feed reading. I mean, this could sort of take off, and become the new basis for social interaction - besides just "texting" securely with your contacts. I wish somehow both makers of briar and matrix combined superpowers to combine the perfect, unified stack! Side note: Is there a way to export (basically archive offline) the content; to be clear only one's content, not someone else's? I'd hate to have some important messages lost if I were to lose my phone. Not saying i want a central server...simply some method to archive my own stuff for safe keeping - encrypted of course. Otherwise, briar seems really awesome!
- RRRA 9y agoWhere is the crypto primitives higher level comparison to say axolotl, noise, omemo, etc.?
- _nedR 9y agoHow does this compare with the competition? Like Signal, for example?
- niceplayer 9y agoI wonder how it compares to Threema. Signal's servers are located in the US, and the service requires you to provide a phone number, which is a deal breaker for me.
- jancsika 9y agoWhen I see that one of the requirements for privacy-preserving software is to have been in the same physical location as the person I need to connect with, while running said software, I immediately stop reading and move on to other things. I've done this for roughly five years. Assuming I've never wanted to become a Debian developer, is there any important piece of privacy-preserving software I've missed out on? Is there likely to be any important privacy-preserving software I will miss out on in the next five years? Edit: clarification
- yjftsjthsd-h 9y agoShort of web of trust, which has other issues, how else would you propose to bootstrap?
- jancsika 9y agoUsing PKI, "winging it", etc. Bitcoin - used PKI to download it. Now Bitcoin is reproducibly buildable, so you can read the forum to see if any zealots notice different hashes (which they certainly would unless you are personally being targeted in testing out the software). Make some small transactions to see if it works. Bitmessage - downloaded it a few days after the initial release. Sent a message over Bitmessage to the Bitmessage author. Got one back from the author. Tor - trust that the directory servers are doing their jobs. Signal - haven't used it but if I did I'll piggy-back on phone numbers to message people I already know. git - used PKI to initially grab the code, trust my own dev machine as I've made commits, occasionally posted commit hashes over various secure/insecure mediums for various reasons (may have done this in person wrt a bug, can't remember). Notice that in all these cases, trying out the software (at least in the U.S.) does not at all imply that you trust it. You could practice installing Tor 20 different times, on 20 different untrustworthy Windows machines and simply use it to search for cat pictures. Then, the 21st time, you could take all kinds of precautions and build a special box just for running Tor, armed with all the first-hand knowledge about how it works and what its trade-offs are. I can also completely fuck up something in git and get so frustrated I just clone it again from the repo I don't have to trust because I just check the hashes and go on working. Requiring physical proximity and a formal key exchange before I can even use the software simply cannot work IMO. It a) requires special planning, coincidence, or proselytization to try out a working version of the app, b) it balloons the length of the engineering cycles and makes it hard to just start over, c) the reliance on in-person meeting implies a level of trust between you, your keys, and your smartphones that neither party should take for granted. Also, it doesn't scale.
- ycmbntrthrwaway 9y agoAs for the audit[1], how would HTML sanitization on sender side protect the reader? On page 12 they suggest adding "HTML sanitization" in onSendClick function. It is as lame as protecting against XSS with JavaScript. Attacker will simply remove this code and recompile app. [1] https://briarproject.org/raw/BRP-01-report.pdf https://briarproject.org/raw/BRP-01-report.pdf
- silur 9y agosigh another one p2p e2e crypted messenger of the week released