4 ms·
Wolf is 100% correct. These details make it sound like this product is insecure. We definitely don't want ecb mode or a weak kdf like 1 round of sha256 with no
by steakejjs 12y ago
Wolf is 100% correct. These details make it sound like this product is insecure. We definitely don't want ecb mode or a weak kdf like 1 round of sha256 with no salt.
BUT before anyone lambasts this guy, it's good the author posted so mistakes can be learned from the feedback, that way others get exposed to the issues, and less mistakes are made in the future. In my opinion, there is too much hate for people who make mistakes when writing code, when in reality that's how you learn. Few people learn all the theory first and THEN how to build it, it's often learn to build then the theory.
- moe 12y agoThis is true for every kind of software except security things. It's really hard for a novice to find something that will actually protect them in between all the "convenient cloud solutions" that an intern cobbled together in their lunch break using some javascript they found on github.
- steakejjs 12y agoNo it is even true for security things BUT the authors need to have no problem taking a dose of humble pie and labeling the project as completely insecure. I don't see anything wrong with writing security software that is insecure as long as you don't pretend it is secure....
- moe 12y agoI don't see anything wrong with writing security software that is insecure as long as you don't pretend it is secure.... Except this one very much pretends to offer protection, apparently oblivious of the problems with their design. They should point out very visibly that this is a tech-demo to promote a completely different product, and not an app that anyone should actually use.
- erglkjahlkh 12y agoI wish it were just interns... Example follows. The Finnish security company F-Secure revealed a secure cloud service, called Younited (https://www.younited.com/ https://www.younited.com/). It did not catch on. The active user amounts stayed at near zero level so it was sold to a company called Synchronoss. F-Secure initially hoped that their good reputation, and the fact that the servers are located in countries without draconian spying legislation would be enough. They seriously hoped to make a star product out of their secure cloud service. Well, secure against whom? Simply installing the applications and completing registration process revealed instantly that the service is insecure. Yes, in compliance sense "everything is encrypted", but the keys are clearly held server side. The customer has absolutely no control over the key management and storage, meaning they are at F-Secure's mercy, and F-Secure can technically open everything for authorities. Now the actually interesting part of the story: The problem isn't the implementation. The problem isn't that they marketed it as secure. The important alpha users on this product area are way too savvy, and stayed away. As per the standard innovation diffusion model, they did not drag other users in. Not marketing the service as secure would have yielded better results! It's funny how even serious software security companies screw things up. Even when they are attempting for a strategic new product positioning, and even when at near clear blue sea situation.
- jszymborski 12y agoWhy not just use NaCl or libsodium... no need to muck about implementing things you don't fully understand.