Live data from Hacker News

Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

ezing.de

21–30 of 35 posts

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#21
post #13

Most people here know about Signal, but if you don't: https://play.google.com/store/apps/details?id=org.thoughtcri... Open source, easier to use, much better UI.

Signal also has forward security, last I checked.

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#22
post #17

"It will not be open-source" Pass.

"... but available in full for a review." I don't know what this means? A snapshot (i.e. not an updated repository) available to anyone who asks for it? I don't understand how it could meaningfully be "available in full" without it being equivalent and easier to just open source it.

I expect this means that if you're a security firm with a decent track record, they'll provide you with source code for review purposes.

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#23
post #17

"It will not be open-source" Pass.

"... but available in full for a review." I don't know what this means? A snapshot (i.e. not an updated repository) available to anyone who asks for it? I don't understand how it could meaningfully be "available in full" without it being equivalent and easier to just open source it.

They could provide the source without it being Open Source, ie., freely redistributable. That was the case for PGP for many years.

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#24

I heard* that all smartphones/cellphones are inherently insecure because: 1. By design, the cellular radio controller (called the baseband) accepts important/privileged commands from the cell tower. (For example, "update firmware". Sometimes, there's even "read range of bytes from phone's internal storage".) 2. Portable fake cell towers exist (called Stringrays). Therefore, unfortunately, it seems unreasonable to cla…

If you're worried about an adversary with access to your phone's baseband, one alternative is to get a 4G hotspot and connect over wifi from an iPod Touch, iPad, or similar. You're still relying on the wifi stack not having any holes that a compromised hotspot baseband could get through, and for that matter, relying on the whole OS not having any other holes they could attack. Either way, it's a smaller attack surfac…

It's true, that's a smaller attack surface.

Under what circumstances would a "phone" manufacturer produce a headset that didn't have the baseband problem?

Which might just mean: a phone that consumers would regularly RTM if it did contain the problem?

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#26
post #15

Earlier quoted context omitted.

Zanny, I disagree with your use of the "nothing is completely secure" truism as an argument against "storing private keys inside cellphones is not a good idea". The local police department has ISMI catchers. I estimate they won't have the ability to extract a file via the baseband until something like eZing becomes ubiquitous. At that point, automated private key extraction will just become another feature of the ISM…

> You wouldn't allow OTA updates of your router or PC... Now would you? Have you booted an internet-connected Windows 7/8 machine recently? "Here, have Windows 10, with all the privacy features built in to it switched off! (In fact we're already downloading ot for ypu even before you agree to install it, so it'll be ready as soon as you agree, isn't that _convenient?_)"

> > You wouldn't allow OTA updates of your router or PC... Now would you?

> Have you booted an internet-connected Windows 7/8 machine recently?

No, because I use GNU/Linux.

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#27
post #17

"It will not be open-source" Pass.

"... but available in full for a review." I don't know what this means? A snapshot (i.e. not an updated repository) available to anyone who asks for it? I don't understand how it could meaningfully be "available in full" without it being equivalent and easier to just open source it.

It won't be free software, but you could probably get them to give you the code with a license that isn't free.

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#28
post #13

Most people here know about Signal, but if you don't: https://play.google.com/store/apps/details?id=org.thoughtcri... Open source, easier to use, much better UI.

And it uses Axolotl (which is an improved version of OTR) which has much better security properties for informal messages (the recipient of a message can be convinced the sender sent it but could not prove this to anyone else). PGP should only be used in cases where you are willing to have your signature be made public.

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#30

"Necessary keys are generated within the app so the private key never leaves the device" Funny. With my email+PGP setup, my private key never even enters the device - https://grepular.com/An_NFC_PGP_SmartCard_For_Android

I assume, that no app will ever reach a lot of people if it's not convenient. That collides often with security aspects. Your Yubi-key-solution might be a good extension for eZing to still use PGP without storing the keys inside the phone, but being convenient enough to chat like you do with Whatsapp, what's a lot more convenient than using a mailclient.
Post reply on HN