20 ms·
The Coder Who Encrypted Your Texts
- patcon 11y agoThank god this man exists.
- dkarapetyan 11y agoYes, but isn't that in an of itself somewhat depressing.
- baudehlo 11y agoSadly, software is complex and security is really hard (and generally a trade-off). See also djb.
- odiroot 11y agoYou should probably thank his parents then.
- yuhong 11y agoI am thinking about why encryption was only used by the military in the first place, back when the infamous Bell monopoly on phone service existed. I think cracking encryption was one of the reasons computers was created in the first place, right?
- tedunangst 11y agoWho could listen to people's phone calls, and how many people were concerned about that happening?
- deleted 11y ago[deleted]
- vezzy-fnord 11y agoBreathing in on your phone has traditionally been the FBI's dominion, in any case.
- yuhong 11y agoYea, I know this kind of control is not possible on the Internet.
- moxie 11y agoI get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.
- thegainz 11y agoWell thank you, and everyone else, for the hard work!
- mirimir 11y agoMaybe you could answer a few questions? That'd be cool. Is there much hope for strong privacy and anonymity using smartphones? Even with secure apps, there's the baseband, controlled by the cell provider. Can it be isolated? What are the chances for open-source hardware? What are the main pros and cons of iOS and Android?
- jrcii 11y agoFor a sandboxed baseband check out the Neo900 project.
- mirimir 11y agoIt seems interesting. But they want an address just to create an account. At least they don't demand a mobile number ;) And the only payment options are bank wire and PayPal. I don't see that they accept Bitcoin. Also, I see no option for anonymous fulfillment.
- programmernews3 11y agoResponse from IRC: http://irclog.whitequark.org/neo900/2015-07-10 http://irclog.whitequark.org/neo900/2015-07-10
- mirimir 11y ago
- PhantomGremlin 11y agoGreat article, not paywalled. Here's the thing that Moxie recognizes, that many other programs don't (in any domain): He says he wants to build simple, “frictionless” apps, adopting a Silicon Valley buzzword for “easy to use.”
- lisper 11y agoNot that I really want to steal any of Moxie's thunder, but if you're reading this comment thread you might also be interested in SC4: https://github.com/Spark-Innovations/SC4 https://github.com/Spark-Innovations/SC4 Strong encryption that runs in a browser. Recently completed its first security audit.
- iamthebest 11y agoI tried installing TextSecure recently but it wouldn't work without the Google Play services. I hadn't herd of their new app Signal. Has anyone tried it? I'm really interested in hearing anyone's experience using it. BTW, I ended up installing Telegram ...and it may be mere co-incidence, but I started noticing some weird things happening that I've never seen before. I connect to the internet exclusively via tethering to my phone and while tethered I started seeing messages in Firefox from my desktop machine giving warnings that were something like "Could not establish secure connection because the server supports a higher version of TLS". My guess is that it was some sort of MITM attack... and I was possibly targeted due to the traffic to Telegram servers. One other thing regarding Telegram: I really don't like that it reads my contact list and uploads it to their server to check if my contacts have a Telegram account. I've blocked the permission for now.
- btczeus 11y agoThis. Why do you require Google Play services? Why do you spy on contacts?
- muppetman 11y agoIt's explained here: http://support.whispersystems.org/customer/portal/articles/1476204-why-do-i-need-google-play-installed-to-use-textsecure-on-android- http://support.whispersystems.org/customer/portal/articles/1...
- muppetman 11y agoTelegram isn't secure. There's been no public audit of their "secure" code and most messages aren't even sent via the secure channel unless you expressly tell it to do so. It has a pretty UI though, so most people seem to think it's great.
- bascule 11y agoTheir UI is a carbon copy of WhatsApp
- btczeus 11y agoThere is not any evidence of encryption on WhatsApp, source code is closed so you can never be safe.
- muppetman 11y agoPeople have sniffed the wire for the WhatApp client (on Android, towards another Android) and seen that it is encrypted. But your point stands - there's no UI to indicate if it was secure or not and the code isn't open so you can't know for sure.
- ikawe 11y agoI'm ignorant. How can you prove that it's encrypted in any meaningful fashion vs, say rot13?
- lovemenot 11y agoWe can disprove the existence of strong encryption with a wireshark, but cannot prove it. Entropy of a rot13 message would be much lower than that of a properly encrypted channel. High entropy is not proof of "meaningful encryption", mind you, since a compressed rot13 or plaintext message would have high entropy too.
- aw3c2 11y agoEncryption on the transport != end-to-end encryption if you consider the users as the ends. The encryption might very well just be from your device to WhatsApp.
- glogla 11y agoOr it might be like with skype - where according to some report (I don't have link right now, sadly) the encryption is used mostly for obfuscating the protocol and to make building alternative clients harder, but it is give so small entropy pool that it's useless for security.
- ulam2 11y ago
- deleted 11y ago[deleted]
- mayneack 11y agoWhisper the app is unrelated to Whisper Systems.
- btczeus 11y agoThis guy is not part of the solution. He is part of the problem. https://f-droid.org/posts/security-notice-textsecure/ https://f-droid.org/posts/security-notice-textsecure/
- theGimp 11y agoFor those interested in the rationale: https://github.com/WhisperSystems/TextSecure/issues/127#issuecomment-13447074 https://github.com/WhisperSystems/TextSecure/issues/127#issu...
- btczeus 11y agoFrom https://github.com/WhisperSystems/TextSecure/issues/53 https://github.com/WhisperSystems/TextSecure/issues/53 Moxie: "I'd like to avoid distributing APKs outside of the Play Store" Why give a single entity the power to push a malicious update anytime?
- lorenzhs 11y agothat's not how the Play store (or Android) works. Moxie signs the APK, phones will only install updates that are signed with the same certificate as the version they already have. Google cannot modify apps. Edit: In contrast, the F-Droid builds were built and signed by F-Droid, so they could at any time include any code they wanted. Whom do you trust more, the developer or some alternate app store?
- Nutomic 11y agoGoogle could also distribute a differently signed apk to selected users. And there's no way for users to check the signature of an apk (if they didn't have it installed before). And I certainly trust an open source project much more than a US company.
- lorenzhs 11y agoBut that angle of attack only works if they target you from the moment you first install the app. It would be much easier to just push a modified Google application update to your phone if that is what they wanted. What it boils down to is that with the Play store, you can be sure that you're not getting malicious updates from some intermediary, as each developer signs their own APKs, and Google doesn't have the keys. Whereas if f-droid is compromised, all applications they build are compromised. That's a much greater risk.
- deleted 11y ago[deleted]
- tedunangst 11y agoFour comments in as many minutes. You're on a roll!
- abalone 11y agoI've had a ton of respect for Marlinspike ever since he published sslstrip, an incredibly simple defeat of HTTPS.[1] It's a perfect demonstration of the fundamental insecurity of the web thus far. When an insecure communication mode (HTTP) is the default and perfectly ok most of the time, the browser has no idea when you are supposed to be operating on a secure channel (HTTPS) but have been tricked into downgrading by a man in the middle attack. I can't prove it but I believe his work is a significant factor behind the shift towards deprecating HTTP in favor of HTTPS all the time. That is the only real solution. [1] http://www.thoughtcrime.org/software/sslstrip/ http://www.thoughtcrime.org/software/sslstrip/
- juhanima 11y ago> the browser has no idea when you are supposed to be > operating on a secure channel (HTTPS) Agree about the sentiment, but there are some ways to help this. The server can for instance tell the client to always require https: https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security Doesn't help if the client hasn't yet connected to the right server at least once, though.
- tzakrajs 11y agoAlso, the browser can opt into HTTPS by using a plugin such as HTTPS Everywhere.
- tedks 11y agoAll of these defenses post-date sslstrip/sslsniff, and if you look at mailing list conversations in the early days of HTTPS Everywhere, you can see that it was developed as a direct response to these attacks.
- abalone 11y agoAll HTTPS all the time is the only real solution. Both those band aids rely on distributing rules to browsers describing when to use HTTPS with what sites. That is totally unscalable, not to mention only as secure as the ruleset distribution channel.
- sergiotapia 11y ago>Unfortunately, if Mr. Marlinspike’s encryption scheme can be applied to imagery, then childporn collectors thank him too. And there we go, highest voted comment on the article: a strawman about child pornography. Think of the keeeds
- RexRollman 11y ago"Think of the childern" is a common refrain of the coward who values safety over freedom.
- perfTerm 11y agoI wonder how many of the people on that think of the children side were either affected as kids, had children who had some awful experience, or are of close relation to someone who was or had kids who did. Because I could easily see something like an awful event happening to a child really warping a persons world view in a strong way. On the other hand, I wonder how many privacy advocates have never experienced anything awful in that sense. I'm on the privacy side myself and it's true child touchers are just hearsay for me. I know they exist, I know it happens, but it's not generally at the forefront of my mind when thinking about much of anything really. And I really wonder what I'd think if everytime I thought about policy I also had poor Timmy's story echoing away for all eternity in my head. And then I wonder for the motivations of the people for whom child touchers are hearsay but are really opposed to privacy. Their motives must include things like drug dealers, terrorists, a belief in their own clean slate, money. It's pretty interesting to think about what goes on behind the scenes of any argument that gains popular traction.
- pgeorgi 11y agoI heard several survivors that were appalled of the "Think of the children" approach because it is too often used to push an agenda that doesn't help children at all. For example, internet blocking of child abuse media (hot topic in Germany a couple of years ago) doesn't help children (who aren't abused 'over the internet' but in real life) because it routes resources away from public education on the matter (such as encouraging victims to speak up), social and health support (so victims that spoke up don't fall into a void) and regular police work (so that the perpetrator gets busted). I guess child abuse on the internet is a popular topic with policy makers because "protecting children" is an easy way to score points in public and "on the internet" hides the fact that this abuse happens somewhere - and closer to any single person than they may be comfortable with. "internet" became a code word for "somewhere else". That's a great platform to win an election. Now, pick any company with > 10000 employees. Just by running the numbers it likely employs a child abuser. You work for such a company? It's likely that one of your coworkers, maybe even somebody you deal with every day, is a child abuser. That's not a great platform to win an election.
- justcommenting 11y agoKudos to moxie and team for their work and their example of positively enabling others to speak freely, for inspiring others to build better alternatives, and for being the change they wish to see in the world. Also wanted to share one of the most provocative moxie-isms I've heard in recent years from him, in reference to WL: "What about the truth has helped you?"
- nly 11y agoDidn't TextSecure stop encrypting SMS a while back? If you lose data connectivity you're sending in the clear, right?
- JupiterMoon 11y agoYes. This is really annoying it was one of the major selling points - I'd got several people to install it on this basis. They had a reason for the change but I was un-impressed The best thing that one can say is that it is well indicated by the UI whether the message will be secure. Blue for encrypted. Green for clear. I've managed to explain this to some very tech unsavy people.
- jumpwah 11y agoJust in case, do you know about https://github.com/SMSSecure/SMSSecure https://github.com/SMSSecure/SMSSecure?
- AdmiralAsshat 11y agoIs that a setting? I use TextSecure, and when my data cuts out, it simply fails to send the message and tells me. Every message I've ever sent (that I can quickly see) has the padlock icon next to it, which I'm assuming guarantees it was encrypted.
- JupiterMoon 11y agoyes
- hookshot 11y agoThe sailing documentary they briefly mention in the article is called Hold Fast. If there are any HN readers that are into sailing I highly recommend it. You can watch it here: https://vimeo.com/15351476 https://vimeo.com/15351476
- nickpsecurity 11y agoInteresting article and interesting guy. I like the work he and his team does on these apps. Unfortunately, they typically run on the type of endpoints that everyone from script kiddies with money to High Strength Attackers can hit. Usually alongside apps not as strong as theirs on TCB's that can at best be described as insecure foundations. I recommend against such apps and platforms for anything other than stopping the riff raff. That's what I use them for. I pointed out the difference between secure code and secure systems in this [1] writeup. Shared much of my framework for analyzing or designing-in security in the process. The TCB of most solutions today is ridiculous: people are building on foundations of quicksand. There's only a few exceptions I've seen such as GenodeOS (architecturally) or Markus Ottela's Tinfoil Chat. Markus has been unusually alert to our concerns and updated his app appropriately even for covert, channel suppression. Quick question: which of the many crypto apps on the market can deliver a covert channel analysis to you at app and system level? Answer: few to none despite it's importance over decades with a rediscovery in past 5+ years in mainstream security. Strong security is hard. Moxie seems awesome as a coder and good to great in both crypto and OPSEC. Thing is, his offerings break the decades old rule of having a strong TCB. Just like most of the rest. It's why they're usually bypassed or broken by strong attackers. Gotta do the whole thing with concern for each aspect of the system. TFC is a clever cheat on that even more than my MILS scheme with a KVM and a highly-assured guard. If you don't cheat around it, you better do it right or your users will suffer the consequences. Those trying to contain vulnerabilities of mainstream OS's and components with any success are expending literally hundreds of thousands of dollars worth of labor per year. It's why I push for clean-slate, hardware and software platforms like DARPA and NSF have been funding recently (eg SAFE, CHERI processors). Alternatives using COTS tech are pretty complex and most users will probably fail to secure them to be honest. [1] https://www.schneier.com/blog/archives/2013/01/essay_on_fbi-ma.html#c1102869 https://www.schneier.com/blog/archives/2013/01/essay_on_fbi-...
- jsprogrammer 11y agoAnyone have a glossary?
- nickpsecurity 11y ago
- chinathrow 11y agoSo it looks like I might have understood something wrong regarding TextSecure. Installed it, used it, uninstalled it. Years later, a contact asks me that he "saw me in TextSecure", sent me a message. Obviously, I didn't get that message. Why - o why - was/is TextSecure pretending to not know about metadata when it does? Why could that happen? Moxie?
- realusername 11y agoThis problem is not specific to TextSecure, it also exist with iMessage and whatsapp as far as I know. You can unregister here: https://whispersystems.org/textsecure/unregister https://whispersystems.org/textsecure/unregister
- wtbob 11y ago> You can unregister here: https://whispersystems.org/textsecure/unregister https://whispersystems.org/textsecure/unregister Well, _maybe_ you can. I spent several days six months ago trying to unregister, and finally just accepted the fact that TextSecure will never let me go. Oh well.
- Strilanc 11y agoMoxie and Frederic and Christine and the rest definitely deserve a lot of credit. Half of me is really happy every time I see Signal getting more popular. The other half is more like OH GOD THE STAKES ARE HIGHER NOW WHAT IF I MADE AN EXPLOITABLE MISTAKE BETTER RE-READ SOME CODE. But seriously, you should read the code. It's there, open for anyone to audit after all. Maybe start somewhere random in the guts [1][2][3] and check for things like "ereh 2# roodkcab"? 1: https://github.com/WhisperSystems/Signal-iOS/blob/master/Signal/src/network/rtp/zrtp/ZrtpResponder.m https://github.com/WhisperSystems/Signal-iOS/blob/master/Sig... 2: https://github.com/WhisperSystems/Signal-iOS/blob/master/Signal/src/crypto/EvpSymetricUtil.m https://github.com/WhisperSystems/Signal-iOS/blob/master/Sig... 3: https://github.com/WhisperSystems/Signal-iOS/blob/master/Signal/src/textsecure/Util/Cryptography.m https://github.com/WhisperSystems/Signal-iOS/blob/master/Sig...
- lukeh 11y ago+[Cryptography generateRandomBytes] should possibly return NSData rather than NSMutableData.
- mahyarm 11y agoAddress book based social networks are nice to get a bit of bootstrapping, but becomes pretty bad when you want to add someone as a text secure contact, or you want to run a version without using SMS gateways. It gets pretty complicated pretty fast compared to 'what is your username'. I hope text secure gets usernames one day that you can associate with phone numbers & emails. The web-browser version is a good development, it shows that desktop and multi-device versions are on the way.
- ianopolous 11y agoI was a great fan of TextSecure until a few days ago. I had encouraged a bunch of friends to install it. One of them couldn't get rid of a notification from TextSecure about an unread message despite there being none, and eventually they uninstalled it. Then, for the next 4 months TextSecure blackholed every message I sent this friend without warning either them or me. They never received a single message from me. After discovering that I uninstalled it.
- moxie 11y agoYou'll find that this is true for every messenger on Android, since there is no way to detect someone uninstalling without unregistering. TextSecure has delivery receipts so you can see when your messages aren't being delivered, and there's a web-based unregistration flow on the Open Whisper Systems website so that users can unregister their numbers if they've uninstalled.
- ianopolous 11y agoThanks for the reply, Moxie. I realise I sound negative, but I do love your work. The app gave me no indication that delivery was failing. Couldn't you detect the failure when you try and forward on the message from your servers (if it is a push architecture)? Happy to give you my details if you want to look into it.
- mike-cardwell 11y agoIt's using the Google Android push stuff, which means to deliver a message to a phone, Moxies server sends a message to Google to ask Google to push a message to the phone ASAP. So he gets no feedback.
- mike-cardwell 11y ago"there is no way to detect someone uninstalling without unregistering" The TextSecure app could ping your server with a "I am still here" message if it goes a week without sending any messages. Don't hear from it for two weeks? Unregister it. Would this not work?
- glogla 11y agoI still can't get over Moxie wanting Google and Apple and Microsoft to be gatekeepers of what you can and can't do with your device and calling sideloading "that old broken desktop security model". I admire your work Moxie, but sadly we stand on different sides of war on general purpose computing. I can't help but be saddened that "the other side" got someone so talented and dedicated.
- Joeboy 11y agoI don't know about Apple or MS, but building TextSecure from source and installing it on an android phone is about as easy as you could reasonably expect it to be. It seems churlish to complain that there are also easier ways to install it. Edit: although, of course you have to trust Github or whoever if you install from source.
- Nutomic 11y agoThey are actively opposing their apps to be published on F-Droid. Instead, they prefer on proprietary services for various (imo bad) reasons> https://f-droid.org/forums/topic/redphone-and-textsecure/#post-12296 https://f-droid.org/forums/topic/redphone-and-textsecure/#po...
- pakled_engineer 11y agoAlso have to trust Google closed binary framework app isn't spying, or can't be remotely exploited to start spying, as it's a hard dependency for Textsecure/Redphone
- rimantas 11y agoThere is no war on general purpose computing. Who even came up with the idea?
- glogla 11y agoCory Doctorow http://boingboing.net/2011/12/27/the-coming-war-on-general-purp.html http://boingboing.net/2011/12/27/the-coming-war-on-general-p...
- em3rgent0rdr 11y agoObama's "problem" is a "solution".
- eloy 11y agoI already knew this would be an article about Moxie before clicking the link.
- BuildTheRobots 11y agoAs TextSecure no longer secures text messages (texts) I really _wan't_ expecting it to be about Moxie and figured it was actually about the implementer of A5/1...
- dates 11y agoSweet article! The movie about Moxie fixing up and sailing a boat was actually was super fun to watch! I'm feeling grateful the comments section hasn't turned into a massive argument over TextSecure dropping SMS support like the whisper systems mailing list alwayssss is...
- JoachimSchipper 11y agoNote that Open Whisper Systems is hiring: https://news.ycombinator.com/item?id=9813309 https://news.ycombinator.com/item?id=9813309.
- nathan_long 11y agoInteresting quotes: > President Barack Obama called [protected-messaging apps] “a problem.” but > Encrypted messaging was viewed [by the U.S. State Department] as a way for dissidents to get around repressive regimes. With help from Mr. Schuler, Radio Free Asia’s Open Technology Fund, which is funded by the government and has a relationship with the State Department, granted Mr. Marlinspike more than $1.3 million between 2013 and 2014, according to the fund’s website.
- deleted 11y ago[deleted]
- teaneedz 11y agoIt's awesome seeing so many privacy and secure messaging apps spring up. The tough part is getting people to use them. I've been using Wickr (I know the black box arguments, but they have a reasonable bounty in place) and it doesn't require number, contact info or addy. The phone call feature of Signal sounds interesting so I'll check it out.
- briandoll 11y agoMoxie gave a great high-level talk on cryptography and Open Whisper Systems at Webstock this year too, for anyone that's interested: https://vimeo.com/124887048 https://vimeo.com/124887048
- btczeus 11y agoWhere's the authentication process in TextSegure? Totally MITM'able. Not secure at all.