8 ms·
These applications should be treated as Trojan horses. If they aren’t open source and you are a journalist/dissident or anyone targeted by nation states you hav
by DSingularity 4y ago
These applications should be treated as Trojan horses. If they aren’t open source and you are a journalist/dissident or anyone targeted by nation states you have got to assume your WhatsApp/Facebook is being used to compromise your device.
- als0 4y agoEven the App Store version of Signal is allegedly not the same as what's in the open source project. So unless you compile and install the applications yourself, there's no way of knowing anything.
- lucakiebel 4y agoSo Apple has their Xcode Build service, why not add a badge to verify that an app was built from a linked public Github/Gitlab Repo
- nonasktell 4y agoif you can't trust Meta, why could you trust apple?
- kingnothing 4y agoApple has been building their brand on privacy and trust for at least a couple of years now. Can you be sure they're not sending everything to the NSA? Of course not. But they also make their money by directly charging users for services unlike the ad-based companies. There have also been many attempts by various governments to publicly force Apple to insert backdoors or prevent them from fixing security vulnerabilities which have failed.
- polyomino 4y ago> But they also make their money by directly charging users for services unlike the ad-based companies. this does not make them more trustworthy > There have also been many attempts by various governments to publicly force Apple to insert backdoors or prevent them from fixing security vulnerabilities which have failed. Except in china, I suppose.
- LtWorf 4y agoWhy would I think there is any truth in something apple's marketing department is saying?
- mhoad 4y agoI really need you to understand the difference between their marketing claims and reality. Apple is really not the champion for privacy they claim to be beyond the extent that they can try and hurt Google in their marketing.
- xvector 4y agoApple's privacy is a marketing farce. They run data centers in China that provide full access to the government. Their anti-ad campaign was simply a push to gain dominance in the space themselves. They make a big fuss about end-to-end encryption but don't even bother to end to end encrypt your photos and backups! I actually worked at Apple a few years ago in security. I was wondering why we didn't E2EE photos. The reason seemed to be - from what other engineers told me - is that it was at the behest of law enforcement. Lot easier to cooperate with LE and comply with NSLs when you can simply hand over the data they need. Until Apple end-to-end encrypts these two things, it's all for naught. It doesn't fucking matter if your HomeKit data is E2EE if someone can take a look at your nudes without any cryptographic barrier. Take that for what you will. Having worked at both companies during my career in a security capacity, I see no reason to trust one over the other wrt cloud services. N.B. There are people at Apple that are very passionate about security and privacy. I was privileged to work with these people during my career. They really try to - and do - make a difference. My post is not an attack on them, but on the wider vision of the company, which is somewhat hypocritical.
- deleted 4y ago[deleted]
- fshbbdssbbgdd 4y agoApple has a multi-billion dollar ads business and is going all-in to expand it.
- neodypsis 4y agoThat'd be cool.
- consumer451 4y agoThat's interesting. Do you have any links for more info?
- nonasktell 4y agoBefore any backdooring purposes there is probably some marketing/analytics reasons, keys, OTF updates etc...
- godelski 4y agoIt's not a realistic danger and just fear mongering. I'm not sure why people on HN feel the need go after Signal so hard. I do think criticism is important (and Signal definitely deserves plenty) but these types of criticisms are off base and not specific to Signal, nor are they that relevant (kinda how people post on Signal's tweets about Iran complaining about lack of usernames. Not the time nor place). It isn't meaningfully different from saying that Google/Apple can pretend to put the real App in the App Store but replace it with one that has a backdoor. This is entirely possible. But also the risk of this is extremely high and people do decompile apps like Signal, WhatsApp, and Telegram (albeit this can only go so far). These are all high profile and highly scrutinized apps. It is just fear mongering.
- gengear 4y agoeven if you compile yourself you can't be sure. [Reflections on Trusting Trust ](https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...)
- 5d8767c68926 4y agoHas that attack ever been observed in the wild? While I don't know if the current incarnations of Nix/Guix will succeed, I think we are slowly making progress towards reproducible builds everywhere.
- whydoyoucare 4y agoNo one knows for sure, though compromised compilers are not far fetched - there has been an implicit trust on compiler toolchains. Reproducible builds are a few years out from full general adoption.
- LtWorf 4y agoAssembly code can be read to see if it matches.
- marcodiego 4y ago> Has that attack ever been observed in the wild? Yes: https://www.quora.com/What-is-a-coders-worst-nightmare/answer/Mick-Stute https://www.quora.com/What-is-a-coders-worst-nightmare/answe... Also, I remember in the 90's, people talking about a virus that infect pascal source code files. Memory is spotty about it. > While I don't know if the current incarnations of Nix/Guix will succeed, I think we are slowly making progress towards reproducible builds everywhere. Fortunately, the answer is also positive here.
- anthk 4y agoNot with Guix and Mes.
- 4y ago
- marcodiego 4y agoThat is why we must support initiatives like f-droid. They put a special focus on reproducibility.
- NayamAmarshe 4y agoWe already know Signal team doesn't like F-Droid. They've got 100 totally outdated reasons why they won't put it there.
- lmm 4y agoIf you're running iOS then I always assume the random number generator is backdoored by the NSA anyway. That's got to be the single juiciest target going; frankly if the NSA haven't backdoored that then what are they even spending tax dollars on?
- UncleMeat 4y agoBeing open source doesn't actually save you from exploitable vulns related to integer arithmetic.
- deleted 4y ago[deleted]
- LtWorf 4y agoIt saves you from obviously planted ones that can be found by code scanners.
- UncleMeat 4y agoIs there any evidence that this overflow was easily found with straightforward static analysis?
- omniglottal 4y agoSeems you might be missing a key point - see, without transparent, open access to the source code, there is nothing easily found. At a certain point, if a murderer keeps "losing" the murder weapon, you might consider the evidence you find to be that of criminal obstruction. There is evidence that everything is more easily found when it's not hidden, obfuscated, or obstructed.
- UncleMeat 4y agoSure. It is easier to throw an off the shelf analysis at source than worrying about binary decompilation with ghidra or whatever (well, for binaries - for bytecode it is almost exactly the same when given bytecode or source). But is this a meaningful difference? Real researchers, both academic and non-academic, do inspect open source code and report vulns they find. But this isn't actually actionable information from the perspective of a user who wants to make a risk assessment about their software choices. "Hey, you can run ${STATIC_TOOL} on this app" does not actually convert to "app is free from vulns." It just doesn't. I love static analysis for vuln detection. I did my PhD on it. It remains my day job. It helps us find vulns. It doesn't actually convert us from unsafe software to safe software.
- upofadown 4y agoThere was an interesting case where a bunch of Android messenger things got a WebRTC based remote code execution[1]. Signal got dinged to the extent that an attacker could trigger it with no action on the user's part. The root problem here is that users want lots of features. Each added feature, particularly super complex ones like video, takes away from security. There is not point in spending a lot of time on your own code if you are going to end up invoking a whole lot of code that you can't control. [1] https://googleprojectzero.blogspot.com/2020/08/exploiting-android-messengers-part-3.html https://googleprojectzero.blogspot.com/2020/08/exploiting-an...
- xvector 4y ago> The root problem here is that users want lots of features Do devs have to implement these features in shitty memory-unsafe languages?