7 ms·
How secure is TextSecure?
- lmedinas 12y agoGot to love Simpsons analogy in the text.
- Tepix 12y agoRight now, the most insecure aspect of TextSecure is that it's not yet available on iOS. Can't wait! Also, I hope in the long run it'll be decentralized like XMPP. I'd prefer to run my own server to make it harder to gather metadata on a large scale.
- laex 12y agoThey're set to add the messaging feature to the "Signal - Private Messenger" app. Although, when is the question. https://itunes.apple.com/app/id874139669 https://itunes.apple.com/app/id874139669 https://github.com/WhisperSystems/Signal-iOS https://github.com/WhisperSystems/Signal-iOS
- furyg3 12y agoDon't hold your breath. Every now and then I check out the GitHub repo but there's not a lot of activity there. It's a pity... I'd be willing to pay for an iOS port, if only to be able to push my friend circle to switch away from WhatsApp.
- hobarrera 12y agoWhat I actually haven't understood yet, is why people insist on using TexSecure, when it's in no way superior to XMPP (+OTR, if you want privacy), and is also centralized. You even seem to be aware of the existance of XMPP, so why do you choose this new, inferior alternative?
- Veratyr 12y agoAs far as I know, XMPP requires keeping a connection alive when you want to receive realtime messages. On most mobile OS, keeping alive that connection and responding to it requires keeping the CPU awake, which severely affects battery life. TextSecure can use the mobile OS's built in push notifications, which gives you realtime message receipt without killing your battery. XMPP may be superior when it comes to security/technology but TextSecure is superior when it comes to usability and practicality on mobile devices.
- smnrchrds 12y agoHow does TextSecure do group chat?
- morsch 12y agoLike this: https://whispersystems.org/blog/private-groups/ https://whispersystems.org/blog/private-groups/
- kristofferR 12y agoA few friends of mine really really tried to switch from Hangouts to TextSecure, but we couldn't do it - it was just too painful, complicated and buggy. We're using Telegram now and it's at least way better than Hangouts and TextSecure on the user experience, even though it's less secure than TextSecure. Are there any good secure messengers out there that truly works cross platform (iOS, Android and Web/Win/OSX)? It's a shame that something like Telegram seems to be the best right now, considering its dodgy security model.
- huuu 12y agoimho there is only 'secure' and 'insecure'. Less secure == insecure.
- kcorbitt 12y agoIt depends on the threat profile. Something can be "secure from a MITM on the coffee shop wifi" without necessarily being "secure from a directed attack by the NSA". For any practical security scheme, you do have to make some assumptions about the limitations of your adversary's capabilities. In the extreme case of "attacker has ability to read contents from memory on the end user's machine at will," I'm not aware of any secure cryptographic solution short of memorizing the key and performing all encryption/decryption by hand.
- _asummers 12y agoTo add to this, there is a time component as well. If your data only needs to be secure for 20 years, it has a different threat profile than one that needs to be secure for 200 years. Then the question becomes "20 years for who?". The safe industry, as an example, thinks about their security problems in this manner.
- saraid216 12y agoNot really. There's only "insecure" and "less insecure". "Secure" just means that no one has figured out how to break it yet, or that you don't care if the people who can break it do so.
- manuw 12y agoNever had problems with Secure text. I use it every day.
- ll1t 12y agoI'm one of the authors of "How secure is TextSecure?". Here is my take on the paper and the developers' comments: https://medium.com/@ll1t/re-how-secure-is-textsecure-cd0ff0f2fcfb https://medium.com/@ll1t/re-how-secure-is-textsecure-cd0ff0f...
- georgemcbay 12y agoHaven't looked at it in a while but when I did previously it was prone to the nearly universal Android issue of leaking data through AccessibilityService, which is basically this: I leave my phone on my desk, Bob grabs it while I'm in the bathroom, turns on Unknown Sources, installs an apk from a known URL which implements an accessibility service that forwards all TextView contents over to his nefarious logging servers. Once he installs this service (rooting and USB connection not required, just physical access to a non-PIN-locked phone and takes about 5-10 seconds to do if you've already posted an apk ready to install to some public url) it will always be running and come up on startup whenever the phone is rebooted and never show me any indication that it is running (unless the service ANRs or crashes or I go to the Accessibility settings page in the OS settings which I am unlikely to do as a user who doesn't require any special accessibility features). Bob then puts my phone back and I begin to use it unawares. All of my data that is displayed to the UI at all is leaking regardless of how secure the network protocol is. Take-aways: If you are an Android user and care about things like secure chat being actually secure, PIN protect your phone or glue the phone to your skin so nobody can install an APK without your knowledge. If you create an ostensibly secure Android app consider querying AccessibilityManager occasionally to take a look and see if any accessibility services are running and if they are indicate this to the user in some visible fashion that explains the risks, this allows people who have legitimate accessibility issues to use the app but mitigates the possibility of a data leak that the user is completely unaware of. Or alternately use an accessibility delegate on all your TextViews and other leaky widgets and have a setting in your app where when this filtering is disabled it is obvious to the user.
- ossreality 12y agoDude, what? If someone else gets physical access to your unlocked electronic device, you're fucked. That's a whole lot of fear mongering about "locally installed malware".
- georgemcbay 12y agoIn response to ossreality's reply (you're hellbanned, btw, so your post is [dead] and I can't reply to it directly): There's a huge difference between "enemy has your device and virtually infinite time to muck with it as he pleases" and "software that can be installed in a matter of seconds with no privilege escalation can subvert the security of nearly every app on your phone".
- rsync 12y agoTextSecure cannot be any more secure than the intentionally backdoored systems that they run on. Your carrier can install arbitrary code, without your knowledge, on both your baseband and your SIM card, and depending on your phones implementation, have direct (as in DMA) access to your entire application processor and whatever OS and userland is running on it. There is no way around this. If it's a mobile phone, it cannot possible be secure and cannot in any way be considered your device.
- ossreality 12y agoSo does your desktop/laptop, almost assuredly.
- qq66 12y ago> If it's a mobile phone, it cannot possible be secure That treats "secure" as a binary condition where something is either 100% secure, or it's just "insecure." It's somewhat like dividing Supreme Court judgments into those that are 9-0 and those that aren't, treating 8-1 decisions the same as 5-4. It's not wrong, it just throws out a lot of useful information. "Secure" is an analog value for data just like "secure" is an analog value for physical objects. If you have a precious object, locking it up and hiring a security guard to protect it makes it more secure than leaving it on the front seat of your unlocked car. It's not very useful, when discussing various types of safe deposit box locks, to say "a safe deposit box can't possibly be secure since a bank robber can come and steal it." Things can be made more and more secure, but even Fort Knox has vulnerabilities.
- rsync 12y agoTextSecure cannot be any more secure than the intentionally backdoored systems that they run on. Your carrier can install arbitrary code, without your knowledge, on both your baseband and your SIM card, and depending on your phones implementation, have direct (as in DMA) access to your entire application processor and whatever OS and userland is running on it. There is no way around this. If it's a mobile phone, it cannot possible be secure and cannot in any way be considered your device.
- rsync 12y agoTextSecure cannot be any more secure than the intentionally backdoored systems that they run on. Your carrier can install arbitrary code, without your knowledge, on both your baseband and your SIM card, and depending on your phones implementation, have direct (as in DMA) access to your entire application processor and whatever OS and userland is running on it. There is no way around this. If it's a mobile phone, it cannot possible be secure and cannot in any way be considered your device.