4 ms·
I am the original author of ChatSecure [1], the only free and open source OTR client for iOS devices. We also released an Objective-C wrapper around libotr call
by chrisballinger 13y ago
I am the original author of ChatSecure [1], the only free and open source OTR client for iOS devices. We also released an Objective-C wrapper around libotr called OTRKit [2] to help other developers integrate their apps with the OTR protocol. Gibberbot [3] is the equivalent program for Android devices, both of which are currently supported by The Guardian Project.
1. https://github.com/chrisballinger/Off-the-Record-iOS https://github.com/chrisballinger/Off-the-Record-iOS
2. https://github.com/ChatSecure/OTRKit https://github.com/ChatSecure/OTRKit
3. https://github.com/guardianproject/Gibberbot https://github.com/guardianproject/Gibberbot
- anologwintermut 13y agoDoes ChatSecure handle conversations moving from desktop to phone? I have an android phone with gibberbot, so its an academic question, but that very scenario has been a pain for me. Do you think the up coming work on multi party OTR helps solve this problem?
- chrisballinger 13y agoOTRv3 [1] has been designed to somewhat help the problem of differing instances and has been available since libotr 4.0.0, but in practice I haven't found a good way to solve the UI/UX problem in a user friendly way. The latest beta builds of Gibberbot support the transfer of private keys from desktop to mobile, but I haven't tested it, or how well it works to transfer a conversation from one device to another. mpOTR [2][3] is designed to solve a different problem, and I believe development has been stalled because the current design doesn't allow chatrooms to scale to large numbers of people. 1. http://www.cypherpunks.ca/otr/Protocol-v3-4.0.0.html http://www.cypherpunks.ca/otr/Protocol-v3-4.0.0.html 2. http://www.cypherpunks.ca/~iang/pubs/mpotr.pdf http://www.cypherpunks.ca/~iang/pubs/mpotr.pdf 3. https://github.com/cryptocat/mpotr https://github.com/cryptocat/mpotr
- acqq 13y agoWhy don't you charge for your iOS app? Is it because you expect that somebody would recompile the sources and charge less? You still have to worry about fraudsters.
- cantankerous 13y agoI know it's not necessarily an accurate selling value of the application, but you could just charge $.99. That would probably head off a lot of the recompilers by making it not-so-worth-it. You never know, though. People will try anything.
- chrisballinger 13y agoSee my response to parent here: https://news.ycombinator.com/item?id=5886613 https://news.ycombinator.com/item?id=5886613
- chrisballinger 13y agoChatSecure will always remain free of charge to ensure that everyone in the world has unrestricted access to privacy technology. The project is mostly funded by very generous grants, so there is no need to "monetize" the project. The amount of money we could make by selling the app directly to users wouldn't even begin to support the actual cost of producing and supporting the software.
- 13throwaway 13y agoHow can we verify that the app on the App Store was compiled with the github source? (So all the code can be examined.)
- chrisballinger 13y agoYou could theoretically clone the source, check out the release tag, compile it, and then compare the checksum of the binary of the .app file, but I'm not sure if that would even generate the same exact file or not. You might also need a jailbroken device to decrypt and extract the App Store binary. If you really want super paranoid level security, communicating digitally is probably not your best bet anyway. Here's the SHA1 checksum of the compiled binary from the latest release (2.0): f9347ae51c3276f4b34fba0be7c0648f20c8c11e /Applications/ChatSecure.app/ChatSecure
- 332485 13y ago> super paranoid level security Considering the fact that Apple is in the NSA wiretapping program and involved in secret tracking [1], don't you think it's unfair to call someone who's asking a way to verify if Apple isn't messing with the code "super paranoid"? [1] https://en.wikipedia.org/wiki/IPhone#Secret_tracking https://en.wikipedia.org/wiki/IPhone#Secret_tracking
- rorrr2 13y agoThere's no easy way. Even if you do verify it, there's no guarantee Apple won't push an update with a backdoor because NSA asked them to. That's why it's better to use Crypto.Cat - its source is the executable. Verifying the hash is enough to make sure the source code didn't change.
- 13throwaway 13y agoI would love to use Crypto.cat, but there is not a mobile app yet. When there is a mobile app it will have the same problem.
- sneak 13y ago
- sneak 13y agoThank you for writing this. Do you have a bitcoin donation address with which we can compensate you for your time and service? I still don't trust it, as the binaries come via the App Store (and without paying another $100 I can't build/install them myself), but it's good that someone's taken the first steps.
- mahyarm 13y agoYou can install on your device if you jailbreak. But you should be using android if you want that kind of control anyway.
- sneak 13y agoI don't want that kind of control, I just want to be able to install software of my choosing. All of the rest of "that kind of control" is time-wasting folly.