Live data from Hacker News

How Secure is TextSecure?

eprint.iacr.org

11–20 of 23 posts

Re: How Secure is TextSecure?

#11
post #7

I've expended 0 effort to find the answer to this myself, but I wonder if this is based on the OTR protocol, and if not, why not.

The TextSecure protocol is now named the "Signal Protocol"; it's developed by Open Whisper Systems. It is the protocol used by the Signal app on Android and iPhone, and as of this week, also used by WhatsApp. Here is an older post where the authors of the protocol explain why not OTR: https://whispersystems.org/blog/advanced-ratcheting/ The main takeaway: text messaging, unlike traditional instant messaging, is prima…

The protocol used to be called Axolotl, if you want to search for older discussions and research on it.

Re: How Secure is TextSecure?

#15
post #12

Earlier quoted context omitted.

This thing is not good, and I strongly recommend against making decisions based on it.

Elaborate please? (I'm not as well versed in security as I would like.)

Here's a quote from a post I enjoyed (https://www.elttam.com.au/blog/a-review-of-the-eff-secure-me...):

> This type of score card drastically simplifies the problem domain, and leads one to question what the tradeoffs are when installing an application from the list. While the advocacy of privacy based communication is something we love to see reach a mainstream audience, we believe the scorecard misses many considerations and metrics that are critical to the discussion.

To quote myself:

> The EFF score card is an embarrassment which is essentially equivalent to one of those "comparison table of our competitors" on a SaaS website. That's a good analogy for it, because it uses the same questionable metrics and even more questionable ranking system that one of those tables would use. The score card gives Signal the same ranking as Cryptocat - that's an instant negative result for its usefulness.

Re: How Secure is TextSecure?

#16
post #7

I've expended 0 effort to find the answer to this myself, but I wonder if this is based on the OTR protocol, and if not, why not.

The TextSecure protocol is now named the "Signal Protocol"; it's developed by Open Whisper Systems. It is the protocol used by the Signal app on Android and iPhone, and as of this week, also used by WhatsApp. Here is an older post where the authors of the protocol explain why not OTR: https://whispersystems.org/blog/advanced-ratcheting/ The main takeaway: text messaging, unlike traditional instant messaging, is prima…

Do you happen to know whether this is the same protocol used in SMSSecure? I know it is a fork of TextSecure but am not clear on whether TextSecure changed their protocol after the fork in the process of becoming Signal.

Re: How Secure is TextSecure?

#17
post #11

Earlier quoted context omitted.

The TextSecure protocol is now named the "Signal Protocol"; it's developed by Open Whisper Systems. It is the protocol used by the Signal app on Android and iPhone, and as of this week, also used by WhatsApp. Here is an older post where the authors of the protocol explain why not OTR: https://whispersystems.org/blog/advanced-ratcheting/ The main takeaway: text messaging, unlike traditional instant messaging, is prima…

The protocol used to be called Axolotl, if you want to search for older discussions and research on it.

The crypto primitives they use are called Axolotl as a group. Axolotl is to signal what RSA is to TLS.

Re: How Secure is TextSecure?

#18
post #17
post #11

Earlier quoted context omitted.

The protocol used to be called Axolotl, if you want to search for older discussions and research on it.

The crypto primitives they use are called Axolotl as a group. Axolotl is to signal what RSA is to TLS.

The Axolotl construction was invented for Signal Protocol, which was itself originally called "Axolotl".

Re: How Secure is TextSecure?

#19
post #12

Earlier quoted context omitted.

This thing is not good, and I strongly recommend against making decisions based on it.

Elaborate please? (I'm not as well versed in security as I would like.)

See this thread: https://news.ycombinator.com/item?id=8557654

Re: How Secure is TextSecure?

#20
post #12
post #6

https://www.eff.org/secure-messaging-scorecard

This thing is not good, and I strongly recommend against making decisions based on it.

I agree. I particularly like your emphasis in last discussion on fact that they "buried PGP." PGP and then GPG have a long history of working against most powerful of the nation-state hackers. The Snowden leaks feature NSA smashing almost everything except for a rare few you can count on one hand IIRC. One of those is GPG. "NSA-proof in 2013" should get put next to its name on top of list, bolded, highlighted, etc.

Curious, what do you think of the worth of a LibreSSL-style effort to clean up GPG's proven code and build better interfaces for integrating it into other apps? Of course, to be done in parallel with development of things like Signal that will get more adoption.

Post reply on HN