Most people here know about Signal, but if you don't: https://play.google.com/store/apps/details?id=org.thoughtcri... Open source, easier to use, much better UI.
Show HN: EZing – Mobile email client that looks like Messenger and uses PGP
21–30 of 35 posts
Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP
#22"It will not be open-source" Pass.
"... but available in full for a review." I don't know what this means? A snapshot (i.e. not an updated repository) available to anyone who asks for it? I don't understand how it could meaningfully be "available in full" without it being equivalent and easier to just open source it.
Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP
#23"It will not be open-source" Pass.
"... but available in full for a review." I don't know what this means? A snapshot (i.e. not an updated repository) available to anyone who asks for it? I don't understand how it could meaningfully be "available in full" without it being equivalent and easier to just open source it.
Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP
#24I heard* that all smartphones/cellphones are inherently insecure because: 1. By design, the cellular radio controller (called the baseband) accepts important/privileged commands from the cell tower. (For example, "update firmware". Sometimes, there's even "read range of bytes from phone's internal storage".) 2. Portable fake cell towers exist (called Stringrays). Therefore, unfortunately, it seems unreasonable to cla…
If you're worried about an adversary with access to your phone's baseband, one alternative is to get a 4G hotspot and connect over wifi from an iPod Touch, iPad, or similar. You're still relying on the wifi stack not having any holes that a compromised hotspot baseband could get through, and for that matter, relying on the whole OS not having any other holes they could attack. Either way, it's a smaller attack surfac…
Under what circumstances would a "phone" manufacturer produce a headset that didn't have the baseband problem?
Which might just mean: a phone that consumers would regularly RTM if it did contain the problem?
Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP
#25Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP
#26Earlier quoted context omitted.
Zanny, I disagree with your use of the "nothing is completely secure" truism as an argument against "storing private keys inside cellphones is not a good idea". The local police department has ISMI catchers. I estimate they won't have the ability to extract a file via the baseband until something like eZing becomes ubiquitous. At that point, automated private key extraction will just become another feature of the ISM…
> You wouldn't allow OTA updates of your router or PC... Now would you? Have you booted an internet-connected Windows 7/8 machine recently? "Here, have Windows 10, with all the privacy features built in to it switched off! (In fact we're already downloading ot for ypu even before you agree to install it, so it'll be ready as soon as you agree, isn't that _convenient?_)"
> Have you booted an internet-connected Windows 7/8 machine recently?
No, because I use GNU/Linux.
Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP
#27"It will not be open-source" Pass.
"... but available in full for a review." I don't know what this means? A snapshot (i.e. not an updated repository) available to anyone who asks for it? I don't understand how it could meaningfully be "available in full" without it being equivalent and easier to just open source it.
Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP
#28Most people here know about Signal, but if you don't: https://play.google.com/store/apps/details?id=org.thoughtcri... Open source, easier to use, much better UI.
Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP
#29"It will not be open-source" Pass.
Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP
#30"Necessary keys are generated within the app so the private key never leaves the device" Funny. With my email+PGP setup, my private key never even enters the device - https://grepular.com/An_NFC_PGP_SmartCard_For_Android