3 ms·
Anyone who knows this stuff can provide additional feedback on apps like ChatSecure and Gibberbot? Are they considered to be good crypto implementations? Updat
by MikeCapone 13y ago
Anyone who knows this stuff can provide additional feedback on apps like ChatSecure and Gibberbot? Are they considered to be good crypto implementations?
Update: I installed ChatSecure on my iPad and it's very easy to set up. So easy in fact that I'm thinking there must be something wrong with it, because otherwise it would probably be recommended more often in these types of threads...
One of the things that seems problematic is that the background session expires after a few minutes, so if someone tries to just randomly message you, chances are you won't be logged in, so this can't be a replacement for IM.
- chrisballinger 13y agoHahaha, perhaps because we don't have a fancy graphic designer, marketing budget or PR firm? Version 2.x does have some bugs that we are working out, stemming from a large refactor to use Core Data. However, we actually don't touch the crypto ourselves and delegate all of it to the official libotr library. If you want to come help improve it, come check out the source: https://github.com/chrisballinger/Off-the-Record-iOS/ https://github.com/chrisballinger/Off-the-Record-iOS/
- MikeCapone 13y agoThanks. One suggestion I would make: Once your things are set up, you shouldn't have to go to the settings screen to log in. Maybe there could be an 'account' button on the main screen or on the buddy list and from there you could sign in and out directly. I think that would make it more friendly to non-techies.
- thaweatherman 13y agoTime out on chatsecure is a draw back of iOS. It forces app to close after 10 minutes of inactivity. Very annoying. I'm with moxie. There are already plenty of good encryption apps out there. That 100,000 could have gone to existing apps that do what they say they do rather than an app that might not turn out as promised.
- nthj 13y agoI never quite understood this. Certainly you don't want to send an unencrypted notification message (“Matt says: here are the meeting times”) to Apple's notification servers. But do you really have to be that verbose? I'm not terribly concerned about the NSA logging “you have $n new messages!” notifications.
- DanBC 13y ago> I'm not terribly concerned about the NSA logging “you have $n new messages!” notifications. But you can appreciate that as part of risk assessment some people might have a valid reason to be concerned about leaking even that much information? GCHQ / NSA are good at finding patterns in data, so a collection of "You have $n new messages!" notifications can provide insight into the organization of a group.
- nthj 13y agoYes, I certainly understand. Most people wouldn't be concerned—and would be far more likely to use the technology if they could enable a feature like "You have $n new messages." I propose it as an option, not a default.
- iuguy 13y agoI've been using threema[1] for a few days and that uses notifications pretty well. [1] - http://threema.ch/en/ http://threema.ch/en/
- thaweatherman 13y agoNot free though. Most people prefer free apps.
- iuguy 13y agoYou mean compromised apps, statistically speaking.
- dobbsbob 13y agoGibberbot is wide open to practical mitm SSL attacks and of course timing analysis to see who you're talking to. If you use it or any other jabber w/OTR, you would want to use it tunneled through another layer of encryption like Tor, so if you and your associates use .onion XMPP servers (and they aren't traffic analysis honeypots or run by incompetent admins/badly configured) then you get an extra layer of encryption to defeat future attacks should there be found a major bug in Gibberbot's OTR implementation and agencies just go back to all the traffic they collected and archived and use the bug to decrypt your old messages.