Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kaeporan
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
kaeporan
12y ago
> You should have just conceded the point (it turned out later in the thread that you were wrong to have brought it up). Instead, you relentlessly personalized it. Now you're unhappy with how that went for you. Maybe this can be a
2.
▲
by
kaeporan
12y ago
Since you've asked me not to share contents of private emails, I won't. But your insistence on assuming bad faith on my part and rudely rejecting any conflict resolution from my end is deplorable, and you should be ashamed of how
3.
▲
by
kaeporan
12y ago
I'll make sure to answer any other comments so long as I have something to contribute.
4.
▲
by
kaeporan
12y ago
I need to investigate this properly before I offer you an educated answer with details.
5.
▲
by
kaeporan
12y ago
I hope I'm not mistaken, but my understanding is that you can have the same message C that would decrypt with K1 to the plaintext "Hello world" but with K2 to another plaintext of your choice ("Jello Warld" or whate
6.
▲
by
kaeporan
12y ago
Sorry, Thomas, but after you repeatedly replied to my private requests for conflict resolution with threats and abusive remarks, I refuse to interact with you entirely, publicly or privately. Those curious as to why I'm saying this sho
7.
▲
by
kaeporan
12y ago
The attacker could send different Ks to each user so that K decrypts C to a different plaintext.
8.
▲
by
kaeporan
12y ago
I don't think it would be trivial (it's likely possible to some degree, but authentication and integrity checks might make it slightly more difficult), but the issue with this protocol is that you don't even need server contr
9.
▲
by
kaeporan
12y ago
I endorse continuous transcript consistency, but believe that TextSecure currently does not allow its users to benefit from it and that this should be resolved. I think mpOTR is irrelevant to this discussion. I hope that's clear!
10.
▲
by
kaeporan
12y ago
Thanks for laying out your thought process, it's very helpful. > I pointed out that the protocol Cryptocat builds that UI on is so bad that you conceded downthread that you're building a new protocol --- you made that concessio
11.
▲
by
kaeporan
12y ago
It really seems like you wrote this comment not to add anything to the conversation, but simply to discourage me from commenting. I really don't understand. I'm trying to be constructive here and I wish you'd join me. Your co
12.
▲
by
kaeporan
12y ago
UI is absolutely a very difficult part of the problem, and here we see an example outlining this. Even a capable protocol still has problems if the UI fails to translate the capabilities into benefits and security increases for users. I spe
13.
▲
by
kaeporan
12y ago
My original comment was simply to point out a current problem in this protocol design. There are some ways one can deploy to make it more difficult for Alice to send different messages to Bob and Carol without being detected, and they are d
14.
▲
by
kaeporan
12y ago
Thanks for agreeing to turn the discussion in a more constructive direction, Thomas. I agree that mpOTR is a dead end. The initial paper by Goldberg et al describes a protocol that is bulky and largely undefined. I should mention that for t
15.
▲
by
kaeporan
12y ago
I'm sorry, but I don't think your approach to this discussion is constructive. I hope TextSecure developers address my initial concern, and that's all for me.
16.
▲
by
kaeporan
12y ago
I think TextSecure is an excellent and inspiring project. All I'm trying to do is identify an area of concern for me. I'm not sure why you're attacking me personally here. I think my initial point of concern stands and I hope
17.
▲
by
kaeporan
12y ago
I'm quite certain that the current TextSecure chat allows my proposed scenario with Alice, Bob and Carol to go through without issue. This is the main problem here. So while transcript consistency is discussed in the blog post, it rema
18.
▲
by
kaeporan
12y ago
Yes, per your quote, transcript consistency is discussed. But the discussion simply outlines problems with implementing it in their mobile use case — to my understanding the current version being offered to users doesn't have strong tr
19.
▲
by
kaeporan
12y ago
The fact that transcript consistency is waved aside, despite being an essential property of a messaging protocol especially in a group context, is problematic, from my perspective. Consider a group chat between Alice, Bob, and Carol. With
20.
▲
by
kaeporan
12y ago
I disagree; I don't think your summary is accurate. This is an audit of a pre-release prototype. All the bugs were fixed before release, and our blog post at https://blog.crypto.cat/2014/04/recent-audits-and-c
21.
▲
by
kaeporan
12y ago
To be clear, I'm not trying to cast aspersions. As I've already stated, TextSecure is a great project that I strongly recommend. I'm trying to have a serious discussion regarding transparency of audits. I feel your reaction i
22.
▲
by
kaeporan
12y ago
Why isn't Moxie replying? Publishing an audit, with or without vulnerabilities, surely is beneficial to TextSecure. I don't understand their reticence to publish audits. We know OTF has commissioned at least two audits for them, b
23.
▲
by
kaeporan
12y ago
I was the person who wrote to OTF asking them to fund our audit. I have no idea if they require it — I'm always the one to initiate the process.
24.
▲
by
kaeporan
12y ago
It's important to note that this audit was commissioned to evaluate a prototype build before release. It was expected to find bugs, and all bugs were fixed before release. I believe I take my job very seriously when I commission such a
25.
▲
by
kaeporan
12y ago
Hmm. Cryptocat was actually the first ever OTF project. I believe they've always asked for the publication of audits. What I'm curious about is, why don't other projects such as TextSecure publish their audits as well? I'
26.
▲
by
kaeporan
12y ago
Since I am familiar with the process, I know for a fact that OTF asks every project whether they'd like to publish their audits, including TextSecure. That being said, what is stopping you from publishing the audits today?
27.
▲
by
kaeporan
12y ago
Cryptocat has always provided ample warnings that no software can ever be trusted with your life. These warnings appear every time you launch Cryptocat, on the website and in various guides and blog posts.
28.
▲
by
kaeporan
12y ago
We submitted a pre-emptive build just to obtain approval from Apple. We were going to wait to update it with the audited build before actually releasing it (Apple lets you schedule releases in advance.) In retrospect, it was lucky we got Ap
29.
▲
by
kaeporan
12y ago
iSEC also audited TextSecure, but TextSecure chose not to publish the audit.
30.
▲
by
kaeporan
12y ago
I agree! TextSecure is an excellent project. We're actually very lucky to be able to bring in Trevor Perrin this month to contribute to Cryptocat.
More ›