5 ms·
What about its design makes it secure? Do you guys have a design document or a description of how you've implemented security? Have any security experts audited
by phobitor 12y ago
What about its design makes it secure? Do you guys have a design document or a description of how you've implemented security? Have any security experts audited the code?
- stqism 12y agoAn audit is currently planned when the core stabilizes.
- aalvarado 12y agoFAQ says it's using the NaCl crypto library, so I guess its protocol is as strong as the encryption. The audit would be less ambiguous, because so many other factors could come into play for all parts of an app, not just the communications part.
- stqism 12y agoYeah, it's more about the implementation and the design of the network/dht itself.
- alex_duf 12y agoThis is a good question. What makes it secure ? "encryption" is not enough. Do you have central servers or is it protocol using P2P ? how do you connect one client to another ? What kind of encryption ? How are the key generated, can we change them etc...
- kragniz 12y agoThe whole protocol is decentralized and peer to peer. Each person in the network has a public and private key. The NaCl library is used to do all of the encryption.
- alex_duf 12y agoCool. Is this direct connection from peer to peer or does the communication bounce from one node to another as a TOR communication would do ? (I'm guessing direct for obvious latency reasons when using audio / video)
- irungentoo 12y agoDirect connection when possible. Connection routed over one TCP node when direct connections are impossible due to NAT issues.
- sitkack 12y agoWhat if I don't want a direct connection for security/anon reasons?
- walterbell 12y agoDoes only the one-time signalling handshake go to a TCP node (NAT hole punching) or does all traffic? Are these TCP nodes similar to Skype "super-peers" - how are they selected? Virtually all consumers are behind NAT devices.
- irungentoo 12y agoThe majority of NATs can be hole punched. If you can't hole punch then you will connect to your friend through a couple TCP nodes. They act like relays. TCP nodes are pretty much randomly selected by peers and anyone can host them. Everything is encrypted and TCP nodes are regarded as being possibly hostile so there should not be any security issues.
- eps 12y agoDo you have exact crypto spec somewhere? "NaCl library" is not a spec and it's still easy to use/apply it incorrectly.
- 12y ago
- dredmorbius 12y ago"Secure" is a lot of things. "Secure against bulk surveillance" is a big push in a lot of areas, it's a button Bruce Schneier and Eben Moglen have been pushing hard for the past year or so. See especially their joint lecture at Columbia Law School in December, 2013, and Schneier's presentation to Stanford Law School in April, 2014 (both are on http://FixYT.com http://FixYT.com). Anonymized persistent IDs associated with physical / persistent IP addresses represents a different level of threat, particularly for those who are engaged in activities for which concern from a APT (advanced persistent threat) such as a state actor, with either legal impunity or significant resources, or both, is a concern. In that case, I'd want to see a system with repudiable identifiers and Onion routing such that endpoints aren't clearly determinable. That said, yours is a crucial question. Related: what are the threat models against which Tox is a response?
- irungentoo 12y agoOur threat model is an attacker that wants to read and record the contents of conversations between everyone, they have the ability to modify/add/remove and log any packets. We assume they do not have any access to the actual machines Tox is running on. The main goal of Tox is to make it hard for a global threat to conduct mass surveillance on everyone at the same time without sacrificing performance. If the majority of the people using Tox have "nothing to hide" and use it because it works better than skype, the minority that does need the crypto will be able to use it without being discriminated against.
- dredmorbius 12y agoThanks, that's a nice and concise statement. NB, a comment by Peter da Silva, who's been doing networking / communications / security stuff for quite a while: "Don't like the callback model in the API, they need a version of tox_wait() that takes a select() fd mask." https://plus.google.com/u/0/104092656004159577193/posts/MDYUCSjcjQd https://plus.google.com/u/0/104092656004159577193/posts/MDYU...
- irungentoo 12y agoEvery peer is identified by a curve25519 public key. To add someone as a friend, you add that public key. Connections between friends are encrypted. http://nacl.cr.yp.to/box.html http://nacl.cr.yp.to/box.html is the crypto used. https://github.com/irungentoo/toxcore/blob/master/docs/Tox_middle_level_network_protocol.txt#L39 https://github.com/irungentoo/toxcore/blob/master/docs/Tox_m... describes the protocol used to connect securely to friends after they find themselves. This protocol has PFS, message padding to prevent length based leaking and should be immune against replay attacks. What makes it secure is that you know the long term public key of your friends making it really easy for the software to establish secure connections to them.
- nly 12y agoAre IP addresses encrypted in the DHT?
- irungentoo 12y agoInstead of doing things like encrypting ips, peers have temporary DHT public keys. The only way to get the ip of someone from their Tox id is by knowing their public DHT key which they will only send you if they are your friend. How this works is described in detail: https://github.com/irungentoo/toxcore/blob/master/docs/Prevent_Tracking.txt https://github.com/irungentoo/toxcore/blob/master/docs/Preve...
- Byzantine 12y agoSo basically, everybody who gives out their Tox ID on 4chan is also giving out their IP address. Great.
- irungentoo 12y agoNo. They have to be friends with you.
- Byzantine 12y ago