4 ms·
your original product was riddled with problems, so much so you had to entirely change the architecture. a stream of ppl popped out of the woodwork and had a la
by conformal 14y ago
your original product was riddled with problems, so much so you had to entirely change the architecture. a stream of ppl popped out of the woodwork and had a laundry list of problems with your original work. making security products that are not built properly endangers those who use it, as i am sure you have heard many times before.
you are clearly very talented with marketing yourself and the project, so cryptocat getting lots of media coverage led to an essentially crowdsourced design for cryptocat 2, very similar to mega. sure enough, this design has held up relatively well and gotten through audits without too many serious issues. as someone who cares a lot about secure comms, i have seen and continue to see no reason to use cryptocat.
i find it particularly ridiculous that a supposed proponent of free speech suggest i am not entitled to my (negative) opinion of your project. i see no point in filing bug reports for software i will never use. i believe in people doing their own homework, it is not my job to improve your project.
if i assume that your govt troubles are indeed legitimate, there are a couple things that seem inconsistent to me:
- you seem very concerned about the negative ramifications of angering your local govt, and all this is linked to (1) your dev work and (2) your prominence in the media. if you are so truly concerned about govt action against you, why are you publicizing the harrassment you have experienced? it only serves to promote your dev work and elevate your media presence, which i would expect to further aggravate your local govt.
- the govt likely knows that actions like this, properly publicized, only lead to an increase in the reach and use of your product, in direct contradiction to your suggestion that they don't want to have your product circulate. it seems that "cui bono" in the context of your story is that you and your project directly benefit by getting lots of publicity.
i found it a bit difficult to fish out details on the ciphers and modes you use with cryptocat 2, which doesn't exactly inspire confidence. i am not a fan of using a stream cipher (AES-CTR) to protect non-streaming comms due to the nonce re-use issues your audit found. ssh using AES-CTR makes sense to me, an IM protocol, not so much.
- randomchars 14y agoSo what would you recommend people to you for secure communications?
- marvin 14y agoYou can be critical without being outright hostile. If this is how you would phrase your criticism to magikarp's face, you are not very courteous.