4 ms·
Moxie Marlinspike is a lot of things but I'm pretty confident the queen bee of a honeypot is not one of them.
by kyledrake 4y ago
Moxie Marlinspike is a lot of things but I'm pretty confident the queen bee of a honeypot is not one of them.
- timschmidt 4y agohttps://github.com/signalapp/Signal-Android/issues/127 https://github.com/signalapp/Signal-Android/issues/127
- prophesi 4y agoConfused by this; Moxie did eventually concede and provide a signed APK.
- timschmidt 4y agoDrew DeVault took the time to write it up: https://drewdevault.com/2018/08/08/Signal.html https://drewdevault.com/2018/08/08/Signal.html
- ruszki 4y ago> Truly secure systems don’t require trust. This blatant absolutist statement is completely false. It exactly means, that there is no computer which is secure today. It also means, that it’s pointless to care about security on any phone in existence, because it cannot be achieved that currently.
- wkat4242 4y agoYeah moxie is diametrically opposed to me. This is why I don't promote signal and only use it through matrix for those two people who don't use anything else. Which is also in contravention to his highness' wishes because he hates third party clients. Moxie believes in security above everything even if it takes choices away from the user and forces you to trust a third party (in this case him, but also the mobile vendor and Google because he doesn't trust custom firmware either). Basically what he calls the mobile security model. And the reason I hate mobile devices with their closed model and attestation crap to make sure I play by the vendor's rules. I believe a user should always have the final say in everything. If the user makes it insecure that's their business. Basically the desktop security model. And the reason I don't like working on mobile devices if I can avoid it. I'm as principalled as he (and other people like him) is so I wouldn't even enter an argument, there's no point.
- kelipso 4y agoHaha I'm sorry but a name like Moxie Marlinspike seems designed by professionals to tickle the so quirky so he must be safe button in the nerd community.
- kyledrake 4y agoDespite the "trustless" credo that gets passed around in cryptography, it's actually often very important to know the people that work in this space and I invite you to read more about this particular person, his background and roots and make a determination as to his intentions in this space and the level of trust you are willing to put in his work (and/or the stuff he previously worked on) and not just make a base judgement on his name alone. FWIW, I've been familiar with his work since before I even used or cared about cryptography.
- VulgarExigency 4y agoSignal is funded by the US State Department[1]. I'm sure you can trust it to send messages to your drug dealer, your mistress, or the competitor you are selling you company's secrets to. I wouldn't trust it if I wanted to keep secrets from american 3 letter agencies, though. [1] https://www.mintpressnews.com/the-open-technology-fund-makes-privacy-apps-staffed-spies/279147/ https://www.mintpressnews.com/the-open-technology-fund-makes...
- kyledrake 4y agoDARPA was going to contribute money to the OpenBSD project (which also maintains OpenSSH) before Theo said some things critical of the Iraq war and they retracted it. I wonder how many people would have accused them of being CIA plants if they took the grant money. Regardless, there are many competing interests and bureaucracies in the US government and it's not a safe assumption that they are in cahoots with each other on encryption they can break on demand. It's usually a more complicated picture than just "the government". Some of this funding is likely with the well meaning intention and goal of strengthening the security and privacy of communication between Americans.
- tialaramex 4y agoAlso see the history of "window" (chaff) in World War II. R&D people for both the Allies and the Germans realised, as improvements of the new "radar" continued, that radar doesn't see a difference between an aeroplane and a suitably sized radio-reflecting object, say a strip of foil. So, if you chuck a bunch of these foil strips out of a plane, now the enemy radar is full of "planes" that don't really exist. Both sides stalled deployment of this trivial yet effective countermeasure because they believed once they used it their opponents would immediately understand how it was done ("Gee, immediately after the German bombers did that trick which messed up our radar we found loads of metal strips in trees all over the area they attacked...") and so copy it - and both had "official" estimates made which said their opponents would surely benefit more than they would once it came into use.
- dTal 4y agoMoxie Marlinspike - and Whisper Systems - have assumed a variety of concerning positions over the years. Concerning, because their flaws are obvious, yet Moxie - a very smart guy - pretends not to notice them. For example, Moxie defended discontinuing encrypted SMS on the grounds that it leaked metadata to telcos - yet failed to emphasize that this was merely the same metadata leaked to Whisper Systems, or justify why we should trust Whisper Systems more. "Just trust us" policies are worrying. Moxie's defense of failing to provide any alternative to downloading Signal/TextSecure from Google Play also contained a number of very eye raising frank admissions, including that Whisper Systems was motivated by the ability to silently push updates and monitor its users (there's that "just trust us" again). Followed by the very weird assertion that "Avoiding Play alone is not a privacy win", which is a bit like saying there's no point wearing a seatbelt because you might get injured in other ways. Whisper Systems is notoriously hostile to any use of Signal that doesn't involve their official client, going through servers they administrate (servers which run code they release infrequently if at all). Signal has made no attempt to bootstrap a federated system, even though this would save them money. They are extremely keen to maintain ironclad control over both the app and the server, and are willing to take unusual security postures in service of this. I've read enough stuff from Moxie that makes me say "what, that doesn't make sense" to make me very suspicious.
- anonym29 4y agoThe SMS support that was discontinued was for plain SMS to/from other plain SMS numbers from within the Signal app - it was not encrypted.
- hutzlibu 4y agoEven assuming Moxie is beyound doubt, that won't help much today, as he resigned as Signals CEO. "https://www.bbc.com/news/technology-59937614 https://www.bbc.com/news/technology-59937614" (He is still part of Signals board, though).