I've expended 0 effort to find the answer to this myself, but I wonder if this is based on the OTR protocol, and if not, why not.
The TextSecure protocol is now named the "Signal Protocol"; it's developed by Open Whisper Systems. It is the protocol used by the Signal app on Android and iPhone, and as of this week, also used by WhatsApp. Here is an older post where the authors of the protocol explain why not OTR: https://whispersystems.org/blog/advanced-ratcheting/ The main takeaway: text messaging, unlike traditional instant messaging, is prima…
How Secure is TextSecure?
11–20 of 23 posts
Re: How Secure is TextSecure?
#12https://www.eff.org/secure-messaging-scorecard
Re: How Secure is TextSecure?
#13Re: How Secure is TextSecure?
#14Re: How Secure is TextSecure?
#15Earlier quoted context omitted.
This thing is not good, and I strongly recommend against making decisions based on it.
Elaborate please? (I'm not as well versed in security as I would like.)
> This type of score card drastically simplifies the problem domain, and leads one to question what the tradeoffs are when installing an application from the list. While the advocacy of privacy based communication is something we love to see reach a mainstream audience, we believe the scorecard misses many considerations and metrics that are critical to the discussion.
To quote myself:
> The EFF score card is an embarrassment which is essentially equivalent to one of those "comparison table of our competitors" on a SaaS website. That's a good analogy for it, because it uses the same questionable metrics and even more questionable ranking system that one of those tables would use. The score card gives Signal the same ranking as Cryptocat - that's an instant negative result for its usefulness.
Re: How Secure is TextSecure?
#16I've expended 0 effort to find the answer to this myself, but I wonder if this is based on the OTR protocol, and if not, why not.
The TextSecure protocol is now named the "Signal Protocol"; it's developed by Open Whisper Systems. It is the protocol used by the Signal app on Android and iPhone, and as of this week, also used by WhatsApp. Here is an older post where the authors of the protocol explain why not OTR: https://whispersystems.org/blog/advanced-ratcheting/ The main takeaway: text messaging, unlike traditional instant messaging, is prima…
Re: How Secure is TextSecure?
#17Earlier quoted context omitted.
The TextSecure protocol is now named the "Signal Protocol"; it's developed by Open Whisper Systems. It is the protocol used by the Signal app on Android and iPhone, and as of this week, also used by WhatsApp. Here is an older post where the authors of the protocol explain why not OTR: https://whispersystems.org/blog/advanced-ratcheting/ The main takeaway: text messaging, unlike traditional instant messaging, is prima…
The protocol used to be called Axolotl, if you want to search for older discussions and research on it.
Re: How Secure is TextSecure?
#18Earlier quoted context omitted.
The protocol used to be called Axolotl, if you want to search for older discussions and research on it.
The crypto primitives they use are called Axolotl as a group. Axolotl is to signal what RSA is to TLS.
Re: How Secure is TextSecure?
#19Earlier quoted context omitted.
This thing is not good, and I strongly recommend against making decisions based on it.
Elaborate please? (I'm not as well versed in security as I would like.)
Re: How Secure is TextSecure?
#20https://www.eff.org/secure-messaging-scorecard
This thing is not good, and I strongly recommend against making decisions based on it.
Curious, what do you think of the worth of a LibreSSL-style effort to clean up GPG's proven code and build better interfaces for integrating it into other apps? Of course, to be done in parallel with development of things like Signal that will get more adoption.