Viber adds end-to-end encryption
21–30 of 114 posts
Re: Viber adds end-to-end encryption
#22Re: Viber adds end-to-end encryption
#23Re: Viber adds end-to-end encryption
#24Get news to see other services following in the footsteps of WhatsApp!
Re: Viber adds end-to-end encryption
#25Earlier quoted context omitted.
That's just an utterly ridiculous proposition. By that logic the entire application would need to be open source, because nobody would start out by targeting the crypto if they wanted to spy on someone.
ryanlol is correct though. If you open source just the end-to-end crypto part, it doesn't mean that the there's no backdoor elsewhere - it could easily leak the keys or whole conversations. The second problem is - you don't know if that source is what ended up in the binary. So yeah, unless you can compile the whole thing yourself, it should not be considered secure.
It's not a high bar.
Re: Viber adds end-to-end encryption
#26Re: Viber adds end-to-end encryption
#27Earlier quoted context omitted.
ryanlol is correct though. If you open source just the end-to-end crypto part, it doesn't mean that the there's no backdoor elsewhere - it could easily leak the keys or whole conversations. The second problem is - you don't know if that source is what ended up in the binary. So yeah, unless you can compile the whole thing yourself, it should not be considered secure.
Open source client and reproducible builds. Signal already does that. It's not a high bar.
https://www.bishopfox.com/blog/2016/04/if-you-cant-break-cry...
Re: Viber adds end-to-end encryption
#28Get news to see other services following in the footsteps of WhatsApp!
Telegram had e2e private chats for over a year before WhatsApp added e2e
Re: Viber adds end-to-end encryption
#29Earlier quoted context omitted.
That's just an utterly ridiculous proposition. By that logic the entire application would need to be open source, because nobody would start out by targeting the crypto if they wanted to spy on someone.
Even if I were to accept your logic, what's ridiculous about that?
What I find ridiculous though was
>venders that don't agree to an audit should be considered insecure
The same thing applies to every single part of the application, but not equally. No attacker is going to start out by trying to break the crypto, unless it's obviously broken. "Normal" bugs are far more common and often more dangerous (Thing RCE, or in the case of many modern apps: XSS)
Re: Viber adds end-to-end encryption
#30What really impresses me about Viber is the way they went all out and splurged with an honest to god penultimate "e" before the final "r". Most dot-com companies would have settled for "Vibr", but they went the distance and bought an authentic luxurious vowel, precisely where it was called for, without going overboard and throwing in a sometimes-vowel "y" in place of the "i". Very bold and straightforward spelling, I…