3 ms·
myth_buster, lisper, & newscracker make interesting points. In researching WhatsApp a while ago, I came across this in a Quora post "But one more point I want
by ac4tw 8y ago
myth_buster, lisper, & newscracker make interesting points.
In researching WhatsApp a while ago, I came across this in a Quora post "But one more point I want to stress here is that, though whatsapp is allowing end to end communication , it does not necessarily mean they can not analyse the encrypted data. in cryptography we call it Searchable Encryption." (https://www.quora.com/Now-that-WhatsApp-can-no-longer-read-your-messages-how-will-they-make-money https://www.quora.com/Now-that-WhatsApp-can-no-longer-read-y...)
I don't know whether it is accurate to WhatsApp, but it's certainly food for thought and also made me wonder how many other end-end encrypted systems use it.
I personally don't trust FB. WhatsApp is not open source, so I have to trust what FB says. I don't.
There are many important considerations in secure messaging and the EFF has done a reasonable job of trying to cover the subject in their series on messaging (https://www.eff.org/deeplinks/2018/03/secure-messaging-more-secure-mess https://www.eff.org/deeplinks/2018/03/secure-messaging-more-...)
- CiPHPerCoder 8y agoYou can reverse engineer any Android app in very little time. Professionals use frameworks like Lobotomy, but you can get by with dex2jar and JD-GUI for most of it. It not being open source is a political argument, not a technical one. EDIT: I ended up doing just that. It took roughly 5 minutes (most of that was making sure I had my PATH for Java set up correctly on this machine) to get decompiled Java code ready to inspect. https://pbs.twimg.com/media/DnkFaKxU8AE4mFn.jpg https://pbs.twimg.com/media/DnkFaKxU8AE4mFn.jpg
- ac4tw 8y ago"It not being open source is a political argument, not a technical one." If I can compare the open source to the reverse engineered code to see what I'm really using/getting, that seems like a technical advantage. Also, all of the reverse engineered code I've worked with has been difficult and time consuming to digest (missing var names, comments etc); open source gives me a technical advantage in analyzing and understanding the code. Lastly, looking at a companies open source lets me assess their technical sophistication and practices which also seems like a technical advantage. I haven't spent much time thinking on this subject, but the political aspect seems to be the line of thinking that says: you will engender trust by making a project open source. Is your reasoning similar? Also are there good tools for reverse engineering iOS deployments?
- CiPHPerCoder 8y agoThere is one tangible benefit to open source: reproducible builds. Everything else comes down to personnel, budget, and scheduling. I'm not an Apple consumer, I don't know anything about iOS in particular.
- saagarjha 8y ago> Also are there good tools for reverse engineering iOS deployments? There are many; since apps are native on iOS a standard disassembler would work. But there are many more specialized tools, such as class-dump and Hopper.
- balladeer 8y agoI know Telegram isn't something truly "open" either (and just to mention, neither is Signal) but I don't need to reverse engineer Telegram app. I actually had its repo cloned and synced and had built and tested it couple of times. Though at the time I ended up not using the Telegram as among my contacts few were using it. My point is open sourced code is much more readable and hence more accessible and you can build it yourself and use it most of the times.
- idlewords 8y agoWhether or not it's open source is irrelevant to the trust issue. You would still have to look at the binary to check whether its behavior matches that of the putative source code. Either way, you end up examining the behavior of the compiled code.
- TheForumTroll 8y agoIt is not irrelevant. If you can't build the binary from code yourself you have no way to know if it is trustworthy. Step one in finding out if it is is to look at the source and then compile it. After that you can look if it does strange things because of something you missed in the code but without step one you might as well not start at all. It will always be at most guesswork.
- tptacek 8y agoVirtually no one who uses software compiles it themselves, so this is not a very interesting rebuttal. Meanwhile, it's not 1994 anymore, and people who know how to look for bugs can (I know this is hard for some people to wrap their heads around) look inside of binaries and draw conclusions about how programs work. There's a name for it; it's a kind of engineering.
- balladeer 8y agoSo, something like Matrix/Riot? Build it yourself and host/use your own app builds and server instances. But then I'll have trust the company I bought my VPS from to host my Matrix instance, isn't it?