3 ms·
Cryptocat has always provided ample warnings that no software can ever be trusted with your life. These warnings appear every time you launch Cryptocat, on the
by kaeporan 12y ago
Cryptocat has always provided ample warnings that no software can ever be trusted with your life. These warnings appear every time you launch Cryptocat, on the website and in various guides and blog posts.
- rancor 12y agoAnd I agree, that's a bare minimum warning for all such software. I appreciate your efforts to make strong crypto more accessible to the general public. That being said, you and I both know that people are using Cryptocat in dangerous situations. And having worked on both medical imaging and secure messaging systems, I have a healthy respect for the consequences of implementation failure. As such, I feel that your disregard for these consequences in broadly releasing such broken software would displease any professional review board, and I frankly doubt you'd ever attain such a license given such a history of poor professional judgment. In short, I take my profession damn seriously, and jokers like you are why nobody trusts software.
- sillysaurus3 12y agoPerhaps we shouldn't call people names?
- diminoten 12y agoYou lampoon yourself with this extremist attitude.
- marshray 12y agoGo read http://tobtu.com/decryptocat.php http://tobtu.com/decryptocat.php and earlier sources before deciding he's being extremist.
- diminoten 12y agoI have, and I still believe he's being extremist. No one is in this space unscathed. For no other product have I seen the same level of vitriol and hate being spit at Cryptocat, despite it being absolutely not the only entrant.
- tptacek 12y ago> No one is in this space unscathed That's both not true, and misleading; even comparing it to applications that have had serious published flaws, this one has vulnerabilities of a number and magnitude that distinguish it.
- kaeporan 12y agoIt's important to note that this audit was commissioned to evaluate a prototype build before release. It was expected to find bugs, and all bugs were fixed before release. I believe I take my job very seriously when I commission such audits on a bi-annual basis and transparently discuss the results. Independent individuals who find bugs (such as "Decryptocat") are also listened to and rewarded for their effort. I believe that I and my team have been competent, honest and hard-working. If all encryption projects were as transparent as us, you would realize that this kind of issues happens everywhere. Please make sure to read our blog post and Github discussions to see the kind of open discussion we're hoping to lead so that our software can benefit. That being said, I suppose comments like yours are why I've been having recurring suicidal thoughts for the past two years. I don't know what else to say at this point.
- tptacek 12y agoYou keep saying "I commission the audits". Isn't OTF the one paying for these audits? Are you taking OTF grant money? If so, aren't you required to have the audits done?
- kaeporan 12y agoI was the person who wrote to OTF asking them to fund our audit. I have no idea if they require it — I'm always the one to initiate the process.
- danielweber 12y ago> I've been having recurring suicidal thoughts for the past two years. I urge you to talk with somebody.
- rancor 12y agoI read the blog post reacting to this batch of audit results quite carefully, in point of fact. In general, when I read vendor responses to such devastating findings, I'm looking for a concrete plan to improve the threat modeling and development practices deficiencies which are inevitably the root cause of the class of issues uncovered by the iSec and Least Authority audits. Without such changes, saying that you're going to keep getting audited is precisely equivalent to saying that you're going to to keep writing security bugs and hope someone finds them before the actual red team owns you. While I agree that the degree of openness your team has maintained is highly desirable, repeatedly shipping bugs which adherence to industry best practices such as "don't use fixed IVs" or "always use constant-time compares" would have avoided makes it difficult to believe that your team possesses the competence you claim as well as undermining the credibility of your communication about such issues. Thus my failure to be impressed by a post which only proposes band-aids and completely fails to apologize for the lapses in judgment which led to this state of affairs. I don't take using this level of harshness in a public forum lightly, and I'm truly sorry to contribute to your unhappiness as a result. Please do talk to somebody, even if it's not a professional, I've found it always helps.