Live data from Hacker News

How Secure is TextSecure?

eprint.iacr.org

21–23 of 23 posts

Re: How Secure is TextSecure?

#21

Earlier quoted context omitted.

The TextSecure protocol is now named the "Signal Protocol"; it's developed by Open Whisper Systems. It is the protocol used by the Signal app on Android and iPhone, and as of this week, also used by WhatsApp. Here is an older post where the authors of the protocol explain why not OTR: https://whispersystems.org/blog/advanced-ratcheting/ The main takeaway: text messaging, unlike traditional instant messaging, is prima…

Do you happen to know whether this is the same protocol used in SMSSecure? I know it is a fork of TextSecure but am not clear on whether TextSecure changed their protocol after the fork in the process of becoming Signal.

It's the same. TextSecure called it "Axolotl", but the "Signal protocol" appears to just be a branding change.

Re: How Secure is TextSecure?

#22

Seems pretty good overall. The only primary bullet point to "fail" was here: >In conclusion, TEXTSECURE only achieves deniability theoretically. Content deniability is provided due to our security proof but we can not prove that no delivery request will be recorded at the TEXTSECURE server.

I would like to see a tool, perhaps even a companion app, that does this HMAC gymnastics to prior discussions to make deniability actually plausible instead of just theoretically plausible.

"Your honor, the defendant is clearly not Moxie Marlinspike. She said these things." "Objection! My grandmother can use Axylnotly to forge previous discussion and she is also not Moxie Marlinspike." " ... sustained."

Re: How Secure is TextSecure?

#23
The mayor issue IMHO is the dependency to Google Cloud Messenger as the only available push notification system for android devices and its dependency to Google Play store. I believe an actor as powerfull as Google can detect paterns and learn from the notifications it handles even if the text is encrypted.
Post reply on HN