7 ms·
Subrosa – An encrypted communication platform
- Scaevolus 12y agoMatasano's "Javascript Cryptography Considered Harmful" is yet again applicable. http://matasano.com/articles/javascript-cryptography/ http://matasano.com/articles/javascript-cryptography/ These statements are mutually exclusive: End to end encrypted: Nobody, not even us, can read or listen into your conversations. Works everywhere: Visit subrosa.io from any computer. No download or install needed.
- phibit 12y agoCan you explain how these two statements are mutually exclusive? These statements are mutually exclusive: End to end encrypted: Nobody, not even us, can read or listen into your conversations. Works everywhere: Visit subrosa.io from any computer. No download or install needed.
- CJefferson 12y agosubrosa can choose at any time to send you javascript which will send your password back to them. You have no way of checking for this (well, except reading all the javascript, every time you log in)
- phibit 12y agoAh yes, that makes sense, thanks!
- technomancy 12y agoExcept it's a GPL'd web application, so you're free to run your own server.
- schoen 12y agoSure, but if you run your own server, then the site's claim that there was "no download or install needed" doesn't apply to you. If you don't run your own server, the site's claim that "nobody, not even us, can read or listen into your conversations" doesn't apply to you. There's nobody to whom both claims apply at the same time!
- technomancy 12y agoIf you run your own server, you can make trusted calls from machines that don't have any client software set up, as can others using your server. Seems straightforward enough. It's clear the "no install" claims are about the client.
- schoen 12y agoI read the claims on their home page as referring to the use case where someone starts using it immediately. (The benefit that they mention on the home page from open source is third-party auditability; the home page doesn't even mention the ability to create your own instance!) The developers might well be thinking along the lines that you describe, but I don't think that a visitor to the site is likely to understand the threats that way. Edit: Looking at https://subrosa.io/security https://subrosa.io/security I think it's even more clear that they're making these claims for their own hosted instance of their software -- and that's what people here are most skeptical of.
- acveilleux 12y agoYou can use github or you can run a private gitorious install (assume here function parity.) Most people will choose github because that's where the people are. Subrosa's value proposition is more as a meeting place then as a "secure" chat software.
- hluska 12y agoThat is such a good article and I cannot believe that I am just reading it for the first time now. Thank you so much for posting the article and your explanation of the two mutually exclusive statements. Crypto is just about the coolest thing I have ever heard of and I love learning about different types of attacks!
- explorigin 12y agoThis is not a "good" article. It's very hand wavey with lots of fud. For example, he talks about the chicken and egg problem of delivering javascript over an insecure connection and then solves it later with SSL/TLS (but he doesn't acknowledge that this is a valid solution). Furthermore, we're all harping on javascript when you can't download PuTTY over an SSL connection. He talks about browser cache but says that javascript can't control it. That doesn't mean it can't be controlled (see MANIFEST file). I could go on, but the point is made, there are answers to the problems raised in the article. They may not be _easy_ (as the article complains some things are complex), but it's security on wildly complex systems...of course it's hard.
- dublinben 12y ago>we're all harping on javascript when you can't download PuTTY over an SSL connection This shouldn't matter, and would just provide a false sense of security. You ought to be verifying the signature of any program you're installing before you use it. Since you're running Windows the point is probably moot, but it is possible to install software reasonably securely.
- jimktrains2 12y agoBut those sigs are also coming over a non-ssl connection:-p Honestly, whenever you download anything, evne over SSL, you're essentially trusting that the remote computer is not only who you think the computer is, but the person you expect to be controlling it is the only person controlling it. Out-of-band communication built out-of in-person trust are really the only way around that (i.e. trusting someone who trusts the PuTTY devs and gets you the hash/sig).
- api 12y agoEverything this article says is true. That being said, it also applies to any regular application that can be upgraded automatically or that's upgraded at all by a third party. Anything you get off an app store can have its code switched out from under it with minimal and routine or in some cases even no user interaction. All someone has to do is compromise the signing key, which is probably not that hard in many cases.
- Scaevolus 12y agoScarily true. The amount of damage malicious actors with keys can do is greatly magnified by the auto-update mechanisms that developers love.
- api 12y agoI have an app with auto-update, and one day I realized that I had (more or less) root on hundreds of users' machines. I'm not special in this regard. I take fairly strong precautions with my keys: offline storage, encrypted, signing on an air-gapped machine. I'd bet you money that most people aren't so careful. There are probably a lot of secret signing keys sitting in DropBox.
- jtheory 12y agoSure; but there's a world of difference between communicating with a webapp that claims to protect your privacy even from the NSA (but actually cannot) vs. "any regular application", which makes no such security claims, and from whom savvy users won't expect that kind of protection. People with important information to communicate that they must protect from the powers that be (quite possibly to protect their own lives) will seek out secure methods; at the same time, the powers they're avoiding will be targeting secure communication methods.
- tptacek 12y agoThis application doesn't protect communications from the owners of the application under any circumstances. Forget about the NSA.
- vsakos 12y agoFirst impression: - There is no demo, i can only guess that this is a "browser-based skype". I hate when i can't try it but it's free. - Open-source, but no git repo? Btw I had the same idea before (I posted it to an Idea Sunday thread) but I dropped the idea because i realized that no one needs this level of security, NSA is not interested in your chat with family and friends...
- phibit 12y ago"There is no demo" -- just make an account quickly and try it out. I did this and it was easy. "Open-source, but no git repo" -- Open-source does not always entail git or Github. "I dropped the idea because i realized that no one needs this level of security, NSA is not interested in your chat with family and friends..." -- I'm glad you dropped the idea because someone who doesn't understand why privacy is important shouldn't be making privacy applications. The NSA doesn't care about your chat with family and friends, until suddenly they DO start caring and everything you've said can be manipulated and transformed against you, whether your conversations were innocent or not.
- vsakos 12y agoI know it can be open source without git, but GitHub gives a lot of benefits. Also as I understood, you don't have Facebook, Twitter, Skype, Googe, Outlook, YouTube, and even HN account because NSA could one day transform everything against you?!
- orthecreedence 12y agoPossible scenario: you are chatting with a friend about how you bought bitcoin at 300 and sold at 500, making 6000USD on the trade. Your money is in an offshore exchange. Next year, you receive a bill from the IRS wanting their cut of the $6000. How did they know? You never pulled out your money. Well, the NSA gave them a tip. Now imagine you're running for public office and your opponents will pay top dollar for dirt on you. Imagine that one day you're at odds with your government and they'll use every piece of information they can to prosecute you. Privacy from one's government and those who control/buy into it is something that nobody needs until they do. That doesn't mean you can't have a public life as well. But why give out more than you need to?
- rubbingalcohol 12y agoUnless they're using a browser extension, there's no way a user can trust this application. It's a web app. At any moment the developer or a malicious third party with unauthorized server access can remotely modify the JavaScript files to dump all data in plaintext to the NSA.
- swordswinger12 12y agoIn the description of the key exchange mechanism (section 'Conversation Keys' under 'Security') it sounds like they're using one symmetric key for both directions of a two-way channel. If true, this is a pretty serious security flaw. Anyone from Subrosa care to comment?
- orthecreedence 12y agoNot really, from what I understand. Seems they are exchanging a symmetric key via RSA to facilitate two-way encrypted communication. This is pretty standard, browsers do this via TLS.
- ctz 12y agoTLS does not use a single symmetric key for bidirectional comms. It establishes keys per direction.
- acveilleux 12y agoMore importantly, one of the party is trusted to come up with the key alone. The other party just has to accept that it's a good key with no other proof then that it was encrypted with their public key. The description is really weak on details. They keep repeating they've been audited but not naming the auditors.
- ctz 12y ago"Nobody, not even us, can read or listen into your conversations." This cannot possibly be true, given they are the root of trust for establishing the recipient's authentic public key. Also, minified javascript really does not count as a source code release.
- jtheory 12y agoQuite right. If they were compelled -- e.g., "insert this backdoor or we'll imprison you" -- they might trivially serve up a tweaked version of their JavaScript to the one user the NSA was interested in. And it wouldn't take a complicated tweak at all to sneak the real password (or some sufficient version of it) back to the server, after which point certainly "even us" can read & listen in to all of that user's conversations.
- danielweber 12y ago(Comment moved to today's topic.)
- carlozt03 12y agoI ran this through the SSLlabs SSL Test and it came back with an F. Perhaps an oversight on their end?
- ceejayoz 12y agoLooks like it's because it's vulnerable to the OpenSSL CCS exploit. http://ccsinjection.lepidum.co.jp/ http://ccsinjection.lepidum.co.jp/ A system bragging about security leaving a known, patched hole like this open isn't a great sign.
- Canada 12y agoA quick check with wireshark reveals the use of a VBR codec for audio, so there's another probable side channel besides the Javascript related issues already discussed. I don't know much about WebRTC, but I think it's something you can set and Subrosa should be doing so in app-webrtc.js.
- acveilleux 12y agoThe login protocol require sending a hash of the key used to decrypt the rsa key bundle stored server-side. I hope they implemented a constant time compare for that hash so that verification can't be used to work out key...
- danielweber 12y agoWhy have both "username" and "display name"? At first I thought it was an extra layer of security , like most online games have, to discourage username/password bruteforcing. (It's an obscurity layer, but obscurity layers are not by definition bad.) But you need to tell others your username to communicate with them.