4 ms·
It would be nice if you could meet me for coffee and say this to my face, friend. I am trying to protect myself and my open source project, which, by the way,
by magikarp 14y ago
It would be nice if you could meet me for coffee and say this to my face, friend.
I am trying to protect myself and my open source project, which, by the way, has been audited countless times and has progressed greatly towards security. If you have a problem with me, then call me up and discuss it instead of stressing me out even more when I just discovered that the government is building a case against me.
If you don't like my work, file a bug report. Check out our documentation. Review our OTR implementation. Submit a pull request. Hack some code. Just don't say hurtful and untrue things like that in public. You can do better.
- frendiversity 14y agoThey can't help it, friend. :-) It's what the human brain does.
- DanBC 14y agoLaw enforcement officers come to you with a correctly formed legal document - a court order, or a warrant, or somesuch - and ask you to serve a malformed client to some cryptocat users. This malformed client will give the impression of encrypted communication, but will actually allow the law enforcement officers full access to the plain text (but only for the specified users). What do you do? This is the Hushmail attack, and it seems like Cryptocat is vulnerable to it.
- magikarp 14y agoCryptocat is a browser plugin. You need to download it like everything else. The source code is on Github. I swear upon my father's grave I will never do something so dishonest and evil towards everyone who has supported Cryptocat, the most meaningful thing I have made with my life.
- StavrosK 14y agoUnfortunately, I don't think you have a choice in these cases, I think you are obligated by law to do it.
- redthrowaway 14y agoYou always have a choice. In this case, you can refuse and go through the legal system. If you've made that choice already, then you can further raise a big stink about it and hope public pressure forces the gov't to back down.
- StavrosK 14y agoOh, interesting, I didn't know that. Thanks for clarifying.
- andreyf 14y agoExcept he's distributing his client via the Google Chrome Web Store, so if law enforcement had a way of requesting that a particular user's software be backdoor-ed [1], they'd go to Google, which would also be significantly less likely to engage in civil disobedience. 1. I'm not a lawyer, but I'd be surprised if this were legal.
- mctx 14y agoAsk the law enforcement officers to send you a pull request instead?
- polymatter 14y agoYou are handling things exceptionally well under the circumstances. If anything, I find it incredulous how eminently sensible you are being. You have my respect. Some people are fanatics who will never believe. Perhaps there wasn't enough hacking in terminals with falling green letters or he doesn't think crypto software can possibly be easy for non-security professionals. Again, you are doing the right thing. I'm only sorry the only thing I can give you is my support.
- adamnemecek 14y agoI think that the reason you are seeing this response towards your project is that it's not entirely clear what it is intended for. As in who cares about security enough to encrypt their messages but not enough to install a standalone client, which has a stricter security model. That being said, I think it's a cool project and it seems to be pissing off all the right people, so keep it up. And I'm not a lawyer but I don't think that the gov't has a case against you (or am I missing something). In fact, it would appear that this might be warrantless wiretapping so you might have a case against them, but I'm not sure if that is something you want to pursue.
- conformal 14y ago"As in who cares about security enough to encrypt their messages but not enough to install a standalone client, which has a stricter security model." this is so spot on. secure comms have no place in a web browser, which is a complex beast with a large set of underlying dependencies. webkit vulnerabilities leading to comms being blown is a crappy architecture. people who care about comms use a standalone client and a separate server. if you care about the integrity of the server, you run some disk crypto, DDR3 memory, secure it physically, etc.
- sweis 14y agoAre you recommending DDR3 memory because you think it's resistant to cold boot or reset attacks? That is not the case. DDR3 memory will not help you.
- Klinky 14y agomaybe they meant ECC memory?
- randomchars 14y agoIs ECC more secure than regular consumer grade memory?
- conformal 14y agoyour original product was riddled with problems, so much so you had to entirely change the architecture. a stream of ppl popped out of the woodwork and had a laundry list of problems with your original work. making security products that are not built properly endangers those who use it, as i am sure you have heard many times before. you are clearly very talented with marketing yourself and the project, so cryptocat getting lots of media coverage led to an essentially crowdsourced design for cryptocat 2, very similar to mega. sure enough, this design has held up relatively well and gotten through audits without too many serious issues. as someone who cares a lot about secure comms, i have seen and continue to see no reason to use cryptocat. i find it particularly ridiculous that a supposed proponent of free speech suggest i am not entitled to my (negative) opinion of your project. i see no point in filing bug reports for software i will never use. i believe in people doing their own homework, it is not my job to improve your project. if i assume that your govt troubles are indeed legitimate, there are a couple things that seem inconsistent to me: - you seem very concerned about the negative ramifications of angering your local govt, and all this is linked to (1) your dev work and (2) your prominence in the media. if you are so truly concerned about govt action against you, why are you publicizing the harrassment you have experienced? it only serves to promote your dev work and elevate your media presence, which i would expect to further aggravate your local govt. - the govt likely knows that actions like this, properly publicized, only lead to an increase in the reach and use of your product, in direct contradiction to your suggestion that they don't want to have your product circulate. it seems that "cui bono" in the context of your story is that you and your project directly benefit by getting lots of publicity. i found it a bit difficult to fish out details on the ciphers and modes you use with cryptocat 2, which doesn't exactly inspire confidence. i am not a fan of using a stream cipher (AES-CTR) to protect non-streaming comms due to the nonce re-use issues your audit found. ssh using AES-CTR makes sense to me, an IM protocol, not so much.
- randomchars 14y agoSo what would you recommend people to you for secure communications?
- marvin 14y agoYou can be critical without being outright hostile. If this is how you would phrase your criticism to magikarp's face, you are not very courteous.