5 ms·
i know the author (nadim) is in here and this is all a bit fantastic. cryptocat is one of many crypto snake-oil products that i would never consider using for a
by conformal 14y ago
i know the author (nadim) is in here and this is all a bit fantastic. cryptocat is one of many crypto snake-oil products that i would never consider using for any kind of secure communication.
using defective crypto products is much riskier than not using any crypto at all and exercising caution. cryptocat has always seemed a poorly disguised honeypot to me.
- JshWright 14y agoI think a statement like that needs a little more in the way of support. Cryptocat has been fairly well reviewed by a number of fairly smart people. While flaws have certainly been found, they've mostly been addressed, AFAIK. "Snake oil" has been a popular term to throw around ever since the original PGP user's guide, but simply labeling something "snake oil" without any actual proof is a dangerous thing to do (especially when it's an open source product, and you should be able to point to any defects specifically). Edit: I realize the term 'snake oil' predates PGP, I was referring to the crypto community's penchant for it.
- frendiversity 14y agoThe fact that he's young, brilliant, and identifies as a hacktivist make it more feasible. He's a future threat.
- teeja 14y agoThat's how the US has treated its hackers since ... the beginning. And that's why the Chinese are almost certainly eating our crypto-lunch. You'd almost think the authorities are compelled to help CN.
- magikarp 14y agoIt would be nice if you could meet me for coffee and say this to my face, friend. I am trying to protect myself and my open source project, which, by the way, has been audited countless times and has progressed greatly towards security. If you have a problem with me, then call me up and discuss it instead of stressing me out even more when I just discovered that the government is building a case against me. If you don't like my work, file a bug report. Check out our documentation. Review our OTR implementation. Submit a pull request. Hack some code. Just don't say hurtful and untrue things like that in public. You can do better.
- frendiversity 14y agoThey can't help it, friend. :-) It's what the human brain does.
- DanBC 14y agoLaw enforcement officers come to you with a correctly formed legal document - a court order, or a warrant, or somesuch - and ask you to serve a malformed client to some cryptocat users. This malformed client will give the impression of encrypted communication, but will actually allow the law enforcement officers full access to the plain text (but only for the specified users). What do you do? This is the Hushmail attack, and it seems like Cryptocat is vulnerable to it.
- magikarp 14y agoCryptocat is a browser plugin. You need to download it like everything else. The source code is on Github. I swear upon my father's grave I will never do something so dishonest and evil towards everyone who has supported Cryptocat, the most meaningful thing I have made with my life.
- StavrosK 14y agoUnfortunately, I don't think you have a choice in these cases, I think you are obligated by law to do it.
- redthrowaway 14y agoYou always have a choice. In this case, you can refuse and go through the legal system. If you've made that choice already, then you can further raise a big stink about it and hope public pressure forces the gov't to back down.
- StavrosK 14y agoOh, interesting, I didn't know that. Thanks for clarifying.
- mcantelon 14y ago>i know the author (nadim) is in here and this is all a bit fantastic. What aspect seems "fantastic" to you? Have you yourself been involved in activism?
- vidarh 14y agoIt just seems exceptionally incompetently handled. The inconsistent stories? Repeated connection attempts to send data to "obvious" places instead of more careful probes and innocent looking transmission attempts to less suspicious locations. The whole thing sounds like a bad b-movie or someone playing a practical joke, rather than a genuine attempt. Then again, who knows, idiots manage to get hired everywhere.
- betterunix 14y agoSnake-oil? I am not sure I would go that far. I am somewhat concerned about crypto that runs in-browser after the Hushmail debacle, but the term "snake-oil" is usually reserved for cryptosystems that follow proprietary designs or "roll your own crypto," and cryptocat does not seem to fall into either category.
- marshray 14y agoI have spent a fair bit of time discussing Cryptocat with Nadim in person. He is sincere in his development goals for Cryptocat and does not intend for it to be a honeypot.