6 ms·
Ask a hacker: Top four anti-surveillance apps
- a3_nm 13y agoSadly, TextSecure and RedPhone are distributed on the Google Play platform, so, if you don't want to tie a Google account to your phone or use Android without the proprietary Google applications, you're out of luck. (They are not included in the free and open source f-droid repository due to disagreements with the author.)
- mtgx 13y agoYou should be able to find the apps on other sources, and the nice thing about Android (and the "old" Windows) is that you can still install apps from other sources. That's becoming less and less the case with other operating systems, though.
- superuser2 13y agoIf they have an IMEI, camera, microphone, GPS, all the contents of your text messages, all your phone calls, all your mobile web browsing (this is the purpose of a cell carrier, no?) do you think it really matters if they have your Google account?
- moxie 13y agoWe don't distribute our apps on f-droid because we feel it's insecure, and because it doesn't provide the features we need to develop stable and secure software. However, we are willing to distribute our apps outside of the Play Store, but we need the following things first: * A built in crash reporting solution with a web interface that allows us to visualize crashes and sort by app version, device type, etc. This is essential for producing stable software. * A built in statistics gathering solution with a web interface that allows us to visualize aggregate numbers on device type, android version, and carriers for our users. This has been crucial in shaping support and development direction. * A built in auto-update solution. Fully automatic upgrades won't be possible outside of Play Store, but we at least need something that will annoy the hell out of users until they upgrade. This is necessary for ensuring that new security features and bug fixes can be propagated quickly. * A build system that allows us to easily turn these features on and off for Play and non-Play builds. Gradle should make this easier. If you're interested in seeing Open Whisper Systems apps distributed outside of the Play Store, we'd welcome your contributions.
- aroch 13y agoAny plans on bringing WhisperCore back for the new Nexus family? I'm somewhat sad that it appears Twitter bought you out to stop making it
- ge0rg 13y agoSpeaking as a developer who's app is both on Google Play and on f-droid, I somehow share your feeling about f-droid being "insecure"(x), but consider all of the other points very thin. Crash reports and statistics are great, except if you explicitly want to NOT spy on your users. Auto-updates are ok, but forced auto-updates take the user's autonomy away, and are only one step short of forced remote uninstalls (which are already documented with Google Play, so far only for malware). A proper build system is great indeed, but has nothing to do with the distribution medium. (x) f-droid security: by having f-droid build all the apps from source by default, and signing them with their own keys, two problems appear: a) you can not switch easily between f-droid builds and maintainer builds b) you as the user need to trust both the author and f-droid to not be evil, instead of just the author.
- losethos 13y agovoid CInGodsTimeDlg::OnStop() { int l,col; LARGE_INTEGER count; // char buf[128]; QueryPerformanceCounter(&count); UpdateData(); switch (pick_mode) { case pm_numbers: m_num=(count.LowPart/DIVISOR)% m_max+1; break; case pm_words: if (num_hash_entries) { l=m_main.GetLength(); col=l-1; while (col>0 && l!=0) if (m_main.GetAt(col)==13) break; else col--; if (l-col>55) m_main+="\r\n"; // sprintf(buf,"\r\n% 010u ",count.LowPart/DIVISOR); // m_main+=buf; m_num=(count.LowPart/DIVISOR)% num_hash_entries; m_main+=word_list[m_num]; m_main+=" "; m_num=1; } break; } UpdateData(FALSE); } ---------------- Fucken niggers. http://www.randomnumbers.info/ http://www.randomnumbers.info/ 5 digits 0-9 line 58650 in King james 22:8 And he discovered the covering of Judah, and thou didst look in that day to the armour of the house of the forest. 22:9 Ye have seen also the breaches of the city of David, that they are many: and ye gathered together the waters of the lower pool. 22:10 And ye have numbered the houses of Jerusalem, and the houses have ye broken down to fortify the wall. 22:11 Ye made also a ditch between the two walls for the water of the old pool: but ye have not looked unto the maker thereof, neither had respect unto him that fashioned it long ago. 22:12 And in that day did the Lord GOD of hosts call to weeping, and to mourning, and to baldness, and to girding with sackcloth: 22:13 And behold joy and gladness, slaying oxen, and killing sheep, eating flesh, and drinking wine: let us eat and drink; for to morrow we shall die. ---- Niggers
- buro9 13y agohttps://silentcircle.com https://silentcircle.com should have a mention too.
- howeyc 13y agoClaims that keys are stored locally and not sent to their network. Applications not open source, no way for anybody anywhere to verify such claims. These are for paranoids, paranoids may not be able to read the source code and verify such things, but the fact the at least someone can certainly helps.
- JshWright 13y agohttps://github.com/SilentCircle https://github.com/SilentCircle
- einhverfr 13y agoI think the best apps are yet to be written. I recently wrote a blog post (http://ledgersmbdev.blogspot.com/2013/06/tangent-design-thougths-about-next-gen.html http://ledgersmbdev.blogspot.com/2013/06/tangent-design-thou...) outlining ways I thought the SSL PKI could be tweaked to make it quite resistant to this sort of eavesdropping. It is still on the HN new feed, if folks want to discuss technical details, but the reason I want to mention it here too is that key management is very hard in a case of resisting surveillance. The current PKI ideas place too much trust in third party certificate authorities (meaning the government can easily pull off man in the middle attacks with the help of network providers if they want, even without your keys), and because each negotiation occurs without context of past ones, there is no way to detect such behavior other than "the CA said watch out" or "this certificate isn't even plausible." Of course you can solve these by enforcing that everyone on your network uses th same local CA that you control but that breaks as soon as you want to talk to someone outside. Building a PKI that can resist such efforts is not trivial and it involves challenging our assumptions. Until we do so however, we will run into all kinds of problem. I may be being paranoid, but it seems like this is a good time to be paranoid. One of the things that SSH gets right is that it takes a diachronic approach to key validation. We should be building this in everywhere and alerting on key changes, while providing a way to ensure that keys can be safely and securely changed without having errors.
- dualogy 13y ago> It is still on the HN new feed Lazy link: https://news.ycombinator.com/item?id=5844621 https://news.ycombinator.com/item?id=5844621
- dave1010uk 13y agoIf you have an Android phone, I'd recommend getting an Open Source ROM (so you can verify it is secure) and removing as much proprietary software as possible. I'd also use Firefox as Chrome for Android isn't Open Source (even though Chromium, Blink, etc are).
- Spearchucker 13y agoThis suggestion comes up a lot, and yet isn't practical. I can read and write code, like many, but haven't the time or inclination (and arguably skill) to "verify it is secure". I can however watch what an app sends over the wire, which applies as much to proprietary as it does to open source software. How do you go about verifying an arbitrary app is secure?
- drcube 13y agoYou can trust that there are a lot more developer eyes on open source software than proprietary software. You personally may not be able to verify every piece of software you have, but if you run free/open software, you know it's theoretically possible to discover vulnerabilities, and that you'll find out eventually if those security holes are found. In the worst case, you can hire a security professional to personally audit a program that is particularly important to you or your business. You have no such options with closed software.
- Spearchucker 13y agoI realise that I'm risking being contrary, but my question is serious. How would I know that an app has had lots of developer eyes on it or not? It's crazy difficult to uncover the latest known security posture of open source software. Finding out eventually is the exact same risk I take when I use proprietary software. It requires my trust. And it's theoretically just as possible to discover vulnerabilities in closed-source software (Windows, for example).
- dm2 13y agoYou really trust a custom compiled version of Android from "1337haxor2" which has auto-update capabilities built in? The easier way would be to monitor network traffic. If random encrypted information is uploaded, then block it, whether or not you have an "open source" rom. Better yet, just get a Nexus device without the carrier apps pre-installed. Stock Android does not have a "upload all data to the NSA" feature built in, it would be easily discovered and would be the biggest news story of the decade. Unless you are the NSA, then I wouldn't advise using a custom version of Android, you'd likely be much less secure than with a stock (and up to date) version.
- jiggy2011 13y agoNo iOS suggestions?
- IlPeach 13y agohave apple ever approved any app like that? just asking...
- pseut 13y agoChatSecure and IM+ both support OTR instant-messaging on the iphone, so depending on what you mean by "like that"... yes. ChatSecure is opensource too fwiw: https://github.com/chrisballinger/Off-the-Record-iOS https://github.com/chrisballinger/Off-the-Record-iOS
- mahyarm 13y agoChatSecure crashes so much it's unusable. IM+ OTR costs $6 and is closed source.
- casca 13y agoIf you're jailbroken (which you probably should consider if privacy is a concern), FirewallIP is the reason I still haven't switched to Android: http://yllier.webs.com/firewall.html http://yllier.webs.com/firewall.html
- jiggy2011 13y agoThat's unfortunately the problem. We want to make secure software easier to use but we can't get past step 1 if people can't just buy it from the app store.
- BryanB55 13y agoCan you expand on why one should jailbreak? Any other jailbroken app suggestions? I was under the impression that jailbreaking also opened you up to be hacked and made the phone less secure.
- 13y ago
- klibertp 13y agoI would appreciate if someone went and fixed the title to have the word "mobile" in it. I was expecting something very different than I got :)
- gasull 13y agoFor the desktop: Tor and Bitmessage.
- IlPeach 13y agoI remember the time, about 6 or 7 years ago when I've asked in front of the whole class to the associate professor of the security course, whether building a text messages encryption app would have been a good idea as project for the course. The answer was a smickering "only a drug dealer would be interested in such a thing". oh man, that hurt... if I only knew a valid point against the "I've got nothing to hide" argument as I do now...
- e40 13y agoI've got nothing to hide Got a handy link to that or similar arguments?
- andy_boot 13y agoI would tell anyone to watch the 'Lives of Others' - great film about how surveillance can be abused.
- networked 13y agoHow about something like this for the grandparent's case: "In some countries people can be persecuted for their religious beliefs, politics or sexuality. Their text messages could potentially reveal all of the above to the government and/or someone listening in on GSM traffic [1]. Those people could use an SMS encryption app to provide them with plausible deniability or, should their local law doesn't have that notion, at least help them avoid automatic keyword detection." [1] See, e.g., http://www.ti.bfh.ch/uploads/media/19_Vadym_Uvin.pdf http://www.ti.bfh.ch/uploads/media/19_Vadym_Uvin.pdf.
- tripzilch 13y agoI keep this one bookmarked, for exactly that reason: Why Privacy Matters Even if You Have 'Nothing to Hide' http://chronicle.com/article/Why-Privacy-Matters-Even-if/127461 http://chronicle.com/article/Why-Privacy-Matters-Even-if/127... The problem seems to be, to me it's so obvious that it matters even if you have "nothing to hide", that whenever someone confronts me with that argument I'm a bit dumbfounded :)
- dapole 13y agoI think the real question should be is there possibly a back door on your mobile os of choice, because it won't matter what app you use if your os is already capable of capturing that data system wide.
- AJ007 13y agoRead these "Bugs, Caveats, Side Notes" published on the Onion Browser app's web site: Major iOS SDK Limitation: Websites using HTML5 <video> tags will leak <video>-related DNS queries and data transfer outside of Tor. This includes YouTube, Vimeo, and any website using iOS-compatible HTML5 video. This is a behavior of the embedded QuickTime player and there is currently no known workaround. (h/t to josyw.) iOS SDK Limitation: Javascript cannot be disabled in the `UIWebView`, so script-based detection may identify your device even if User-Agent Spoofing is enabled. iOS SDK Limitation: Related to above, the HTML5 Geolocation API cannot be disabled. The browser will ask you for permission to access your location if a website asks for it via the HTML5 Geolocation API. If you allow this, then said website will (obviously) know your actual current location. That doesn't sound remotely safe to me.
- gasull 13y agoFor the desktop: - Tor - Bitmessage Bitmessage is specially interesting because it's not only encrypted and private, it actually solves the problem of spam and offers 3 kinds of messaging under the same interface: email-like, broadcast messages ala Twitter and chan boards.