3 ms·
Is a warrant canary even legal? If it isn't, what's the point of having them? From http://en.wikipedia.org/wiki/Warrant_canary http://en.wikipedia.org/wiki/War
by read 12y ago
Is a warrant canary even legal? If it isn't, what's the point of having them?
From http://en.wikipedia.org/wiki/Warrant_canary http://en.wikipedia.org/wiki/Warrant_canary
The US security researcher Moxie Marlinspike states that "every lawyer we've spoken to has confirmed that [a warrant canary] would not work" for the TextSecure server.
Direct link: https://github.com/WhisperSystems/whispersystems.org/issues/34#issuecomment-49910725 https://github.com/WhisperSystems/whispersystems.org/issues/...
- pakled_engineer 12y agoThe main worry for TextSecure is that Google upon receiving a NSL will send you a targeted update for the TS client and GAPPS framework that sends all your msgs to a three letter agency before being encrypted and sent as usual. So Google would need a canary for the play store
- dublinben 12y agoIf you're concerned about that threat vector, you wouldn't be using GAPPS/Play. Except that's the only way they'll distribute TextSecure.
- jlund 12y agoExcept for the fact that Google does not have the signing keys that are used for the TextSecure binaries. They cannot silently distribute a binary that has been tampered with. This distributed trust system is one of Android's strengths: https://developer.android.com/tools/publishing/app-signing.html https://developer.android.com/tools/publishing/app-signing.h...
- dllthomas 12y agoThough don't they control the code that does the signature checking?
- petertodd 12y agoTo clarify, so Google can distribute a binary that has been tampered with, but it'd be trivial to prove that they had in fact done that?
- jlund 12y agoThat's correct. Android will warn you if the signatures don't match too. Even if we're in the full-on conspiracy theory territory of Google disabling that core security feature, impersonating a third-party developer, and dropping a binary onto a single user's phone, they still couldn't fake the signature.
- jacquesm 12y agoThey could simply disable the warning. It's android giving the warning, not the app.
- StavrosK 12y agoBut they own the OS, so I guess they can intercept whatever they want before it even reaches the app.
- pakled_engineer 12y agoUnless you have a phone still vuln to the Android signature bug, which is millions of devices still running unpatched carrier builds.
- wnevets 12y agoThe EFF quote in your link suggest yes.