6 ms·
Whisper Systems' headquarters is located in San Francisco, according to http://en.wikipedia.org/wiki/Whisper_Systems http://en.wikipedia.org/wiki/Whisper_System
by petsounds 13y ago
Whisper Systems' headquarters is located in San Francisco, according to http://en.wikipedia.org/wiki/Whisper_Systems http://en.wikipedia.org/wiki/Whisper_Systems
Doesn't that make them susceptible to a search warrant forcing them to give up the private keys (or equivalent) to TextSecure, ala Lavabit?
- deleted 13y ago[deleted]
- privong 13y agoI'm pretty sure Whisper Systems never get any private keys, because the private keys are only stored on the end user devices.
- jpollock 13y agoLegal intercept legislation would likely require them to patch customer systems to allow the reporting of the key.
- anaphor 13y agoIf you're really paranoid then you should build the code yourself from github, not just install the version on the play store.
- bduerst 13y agoIn a compiler that was compiled by someone else. /tinfoil hat
- TacticalCoder 13y agoThat's why in the future we'll be using compilers which are open-source and using deterministic builds and double-compilation (or "n-compilation") : )
- sneak 13y agoI recently discovered that there are no basic deterministic OS image builds (like a bootable .iso) with just a toolchain and wget and gpg and a shell. I was surprised; seems like a good basic target.
- LeonidasXIV 13y agoDebian has an ongoing project for this, https://wiki.debian.org/ReproducibleBuilds https://wiki.debian.org/ReproducibleBuilds driven by Lunar from the Tor project.
- albeertoni 13y agoIntercept legislation that applies to makers of non-interconnected (i.e., doesn't touch the PSTN) chat functions is extremely unlikely. I'm guessing whisper falls into that category. I use Silent Circle myself, but I assume on Whisper you can't just type in a normal mobile number and have the chat message go to the right person. If you can, then those chats at least are subject to intercept, and maybe the other chats (whisper-whisper chats) are too. I don't remember how all those rules shake out/how courts have decided.
- pbhjpbhj 13y agoWouldn't the relevant TLA just tell Google to enable the backdoor and then sniff the necessary keys from the device ...
- privong 13y agoUpon compiling TextSecure from source and installing it on my phone (I don't have the play store), I've discovered it requires the Play Store to do the "iMessage" style messaging over data. I guess the encryption is still done on-phone before being sent through whatever data API, but I still wonder if that (the play store being installed) might enable key-sniffing? Perhaps that's somewhat negated by users having a strong passphrase though?
- sigil 13y agoYes it would make them susceptible...if, like Lavabit, they actually held private keys that secured your communications. They don't. While I have the utmost admiration for Levison's stand, the fact that Lavabit held centralized private keys for its users was a very bad technical and security decision. Moxie has more about this here [1]. Now some may be wondering, what's to stop Whisper Systems from backdooring TextSecure by court order? In a word, this: [2]. The TextSecure client is open source. Not only can the community scan the source for something suspicious, but we can build and verify the binaries ourselves. [1] http://www.thoughtcrime.org/blog/lavabit-critique/ http://www.thoughtcrime.org/blog/lavabit-critique/ [2] https://github.com/WhisperSystems/TextSecure/ https://github.com/WhisperSystems/TextSecure/
- georgemcbay 13y agoThe fact that the app is open source is nice, but realistically speaking very few users will build their own copy from source over just downloading an existing binary from Google Play or the Apple App Store. Nothing (but garden variety trust in the source of the binaries) is stopping a situation where there is a clean open source version and then a version with a backdoor built into binaries submitted to the app stores. And even if you are one of those paranoid users who builds from source, a backdoored central build could still impact you personally unless you're sure everyone you are messaging has also built their own from clean source. Personally I wouldn't worry too much about this scenario playing out, but I don't see that the client being OSS really buys you much safety practically speaking.
- rtfeldman 13y agoThis is true, but at least it lets a small group of people do the verification work and post in a public place if the publicly distributed binary stops matching up with the one built from source.
- deleted 13y ago[deleted]
- georgemcbay 13y ago
- Bob_Sheep 13y agoThat is Whisper Systems, not Open Whisper Systems. They are different.
- 01Michael10 13y agoWrong, Whisper Systems is Open Whisper Systems but whether they are still located in SF I don't know.
- fnsa 13y agoWasn't Whisper Systems/Moxie bought by Twitter some time back?
- not_rhodey 13y agoKind of-- some older code was (is?) copyright WS, newer code is OWS, in both cases everything is GPLv3 and all future code will continue to be OWS & GPLv3.
- danielsiders 13y agoI don't think they retain keys, but aren't all the messages (encrypted) routed through their servers, giving them access to metadata?
- deleted 13y ago[deleted]
- hershel 13y agoYes, but they mentioned the option of letting people run their own servers.