Live data from Hacker News

Moxie Marlinspike Makes Encryption for Everyone

popsci.com

51–60 of 144 posts

Re: Moxie Marlinspike Makes Encryption for Everyone

#51

Not for people who don't want Google on their device. He only wants distribution via Google, and even went as far to demand that free/libre Play-alternative F-droid removed their build of TextSecure. See: https://fdroid.eutopia.cz/

> He only wants distribution via Google... Untrue. He only wants distribution through channels that provide the same security assurances and deployment features that Google does through the Play Store. [0][1][2] He's also quite open to replacing use of GCM with WebSockets or some equivalent tech, but if you don't use GCM, the replacement is likely going to significantly reduce battery life of phones on cell networks.…

Pretty much this. The noise about f-droid tends to be a bit misguided, and fwiw building an apk from the Signal source on github is pretty painless.

I'm actually much more concerned with the size of the app; imnho it's way to big and way to hard to even begin to audit. I've been trying to figure out if there are some simple core that could be extracted for building a minimal cli app with minimal media support -- but so far I'm not too hopeful.

It's just far too monolithic a project IMNHO. I want a small easily auditable library along with a small app - but it appears I'll have to implement that myself :-/

Still, at least the code is open, and it builds :-)

Re: Moxie Marlinspike Makes Encryption for Everyone

#52

Earlier quoted context omitted.

> He only wants distribution via Google... Untrue. He only wants distribution through channels that provide the same security assurances and deployment features that Google does through the Play Store. [0][1][2] He's also quite open to replacing use of GCM with WebSockets or some equivalent tech, but if you don't use GCM, the replacement is likely going to significantly reduce battery life of phones on cell networks.…

These are some good points but when you say "He only wants distribution through channels that provide the same security assurances and deployment features that Google does through the Play Store." it must be noted that this isn't a guarantee of security. A quick search of 'Google Play malware' returns many results from 2016 and going back to when it was still called Android Market. This isn't hand-waving, there are m…

> ...it must be noted that this isn't a guarantee of security.

Yes, and if a nation-state is after you, you almost certainly don't have the OPSEC discipline required to keep your computing devices secure. Security isn't binary, it's a gradient. Ever more secure devices require ever higher costs, whether they be monetary costs, lost time, or procedural complications.

> A quick search of 'Google Play malware' returns many results from 2016...

And even a brief dig into the details of those "malware" reports reveals that -if the software was distributed and installed through the Play Store, and the Android device user did not have "Allow installation from unknown software sources" checked- all that pretty much all of that "malware" does is exactly what the permissions it requests permits it to do. [0]

Protip: If the software asks for permission to read your contacts, location information, and system log data, don't be surprised if it exfiltrates that information via the pretty-much-always-on Internet connection that's built into the device it's running on. :)

The fact of the matter is that Google is rather good at software security.

> ...but the only certainty that using Google's store brings is that you must have a first-party relationship with Google to use his app.

Not to be an ass, but you either haven't read or haven't understood either the technical aspects of what the Play Store gives you, or the target audience for Whisper Systems's software.

[0] Vulnerabilities like stagefright are excepted from this list because they are vanishingly rare. I challenge you to find another actual Android sandbox escape. :)

Re: Moxie Marlinspike Makes Encryption for Everyone

#54

Earlier quoted context omitted.

These are some good points but when you say "He only wants distribution through channels that provide the same security assurances and deployment features that Google does through the Play Store." it must be noted that this isn't a guarantee of security. A quick search of 'Google Play malware' returns many results from 2016 and going back to when it was still called Android Market. This isn't hand-waving, there are m…

> ...it must be noted that this isn't a guarantee of security. Yes, and if a nation-state is after you , you almost certainly don't have the OPSEC discipline required to keep your computing devices secure. Security isn't binary, it's a gradient. Ever more secure devices require ever higher costs, whether they be monetary costs, lost time, or procedural complications. > A quick search of 'Google Play malware' returns…

It is your assumption that the perceived threat is a 'nation-state', not mine. Personally I'm not to worried about them and I'm more concerned with advertisers and data brokers.

Let's take that brief dig into those 'malware' reports, shall we? Here's one from the Wall Street Journal[0] from last year. Some choice quotes:

"Security-software maker Avast called out a trio of malicious Android apps that were, until recently, available in the Google Play app store. The apps would go into sinister mode after 30 days on a device, and begin spamming users with advertisements, Avast said in a company blog post. Google told the Journal that, as of now, the infected apps have been pulled from Google Play."

"For those who had the apps installed on their phones for more than 30 days, a threatening ad would pop up each time they unlocked their phone, saying the device was out of memory, experiencing a security hole or some other false claim, Avast said. The pop-ups would then route people to websites where more malware could be installed on devices, said the security company. Anyone with either of the known apps installed should delete them immediately."

Do we blame the users since the apps informed them about permissions?

I've read and understood the same things you have, and reached a diametrically opposite conclusion. Maybe this is because I am also taking into account Android's severe updates problem, which is typically left to the carriers and handset makers to implement. Carriers and handset makers want to sell new phones, not patch old ones, who didn't see that one coming? Good on Google for patching Android security holes, too bad they don't reach the majority of users. I'm sticking to my original view and I guess we'll have to agree to disagree.

[0]http://blogs.wsj.com/personal-technology/2015/02/04/android-...

Re: Moxie Marlinspike Makes Encryption for Everyone

#55

Oh the irony of an article about encryption on a site sans encryption.

Huh? I'm connecting over HTTPS right now. Have you tried it?

This is what it is shown:

"This server could not prove that it is www.popsci.com; its security certificate expired 153 days ago. This may be caused by a misconfiguration or an attacker intercepting your connection. Your computer's clock is currently set to Wednesday, May 11, 2016. Does that look right? If not, you should correct your system's clock and then refresh this page."

Re: Moxie Marlinspike Makes Encryption for Everyone

#56

Earlier quoted context omitted.

> ...it must be noted that this isn't a guarantee of security. Yes, and if a nation-state is after you , you almost certainly don't have the OPSEC discipline required to keep your computing devices secure. Security isn't binary, it's a gradient. Ever more secure devices require ever higher costs, whether they be monetary costs, lost time, or procedural complications. > A quick search of 'Google Play malware' returns…

It is your assumption that the perceived threat is a 'nation-state', not mine. Personally I'm not to worried about them and I'm more concerned with advertisers and data brokers. Let's take that brief dig into those 'malware' reports, shall we? Here's one from the Wall Street Journal[0] from last year. Some choice quotes: "Security-software maker Avast called out a trio of malicious Android apps that were, until recen…

> It is your assumption that the perceived threat is a 'nation-state'...

... That was the opening sentence of my paragraph that demonstrated that there is no such thing as "guaranteed security". If you think that there is such a thing, then you're going to be confused about many things when you think about security matters.

To the rest of your comment:

You need to keep things in perspective. [0]

* On Windows, Mac, and Linux malware can read and write to anything that the user who installed it has access to. It can read what other programs have stuffed in to RAM... including your password manager's temporarily decrypted passwords. It can often record and exfiltrate the contents of one's screen and the output of one's microphone. It can often install keyloggers that capture banking, email, and other credentials. It can often encrypt personal data, lock the computer, send the computer user a friendly ransom note, and then decrypt that data once payment is received. Unless the malware is ransomware, it can do all this without ever notifying the computer user.

* On Android and iOS, malware can do exactly what the pre-installation permissions list says it can. Malware cannot read or write to data for which it does not have permission to read or modify. For instance, malware cannot be a keylogger unless it requests the replace system keyboard equivalent permission. For Android malware to read what other programs have stuffed into RAM, it -effectively- has to be authored and signed by Google and baked into the system image.

* Are you old enough to remember popup web advertising? Because (other than the platform) that's exactly what the section you quoted from that article is talking about. In the PC world, popups are called "annoying" rather than "malware".

Is the permissions system good? No. However, it's dramatically better than what you get in the PC world.

Remember that Signal is software that is intended for rather secure communications. Signal's threat model [1] requires that other programs running on the system be unable to tamper with the data that Signal puts into RAM and on to disk. You can get those properties with a PC, but so many non-technical users' PCs have been hit with real malware ages ago that that's kind of a lost cause. Actual "take over your computer" malware doesn't exist in either the Play Store or the App Store. This is really good for the average computer [2] user.

> Maybe this is because I am also taking into account Android's severe updates problem...

Wot? Other than the ~3 year update window problem, this hasn't been a wide-spread problem [3] since Google put critical system stuff in the Google Play Services package (rather than baked into the system image) ages ago.

> I've read and understood the same things you have...

Read? Maybe. Understood? Clearly not. I hope that you'll take the presence of strong differing opinions backed up by sound reasoning and hard facts as a signal that some of your fundamental assumptions about the topic are incorrect.

[0] Indeed, maintaining perspective is a significant part of talking about security issues.

[1] Learn what that means if you don't already know.

[2] Mobile or otherwise.

[3] Yes, you can point to abandoned phones. I can point to people with missing limbs, but that neither means that the majority of people are missing limbs nor does it mean that there's a severe missing limb problem in the human population. :)

Re: Moxie Marlinspike Makes Encryption for Everyone

#57

Earlier quoted context omitted.

I'm not familiar with this but it looks like an interesting project. My problem however is that I mainly do not like that GPL'd software isn't allowed to be redistributed. I might not be properly informed on this issue (and please correct me if I'm wrong) but from what I've read that seems to be the case.

> I might not be properly informed on this issue. You're not. Here's an okay starting point into the discussion: https://github.com/WhisperSystems/Signal-Android/issues/282 Another thing to remember is that (IIRC) -for approximately forever- Red Hat Enterprise Linux has been a Linux distro that's composed almost entirely of Open Source software, but prohibits folks who receive the binaries from redistributing them.

It's the branding that allows Red Hat to effectively restrict distribution of binaries, due to trademarks. Since the source is still available, GPL is fulfilled.

Re: Moxie Marlinspike Makes Encryption for Everyone

#59

Earlier quoted context omitted.

> I might not be properly informed on this issue. You're not. Here's an okay starting point into the discussion: https://github.com/WhisperSystems/Signal-Android/issues/282 Another thing to remember is that (IIRC) -for approximately forever- Red Hat Enterprise Linux has been a Linux distro that's composed almost entirely of Open Source software, but prohibits folks who receive the binaries from redistributing them.

It's the branding that allows Red Hat to effectively restrict distribution of binaries, due to trademarks. Since the source is still available, GPL is fulfilled.

+1

My memory of the mechanism was a little different but the trademark component is obviously a part. Something in the EULA like "If you distribute RHEL binaries without our consent, we'll cut off your access to security updates and patches ASAP.".

Regardless, people seem to forget (or perhaps never bothered to learn in the first place?) that the GPL doesn't care to speak to binary distribution, just source code (and -sometimes- build instructions) distribution.

Re: Moxie Marlinspike Makes Encryption for Everyone

#60
post #40

Earlier quoted context omitted.

Huge deal breaker for me, regrettably.

Yeah me too, I'm using Conversations[0] on Android and it's pretty awesome actually. Pretty actively developed with a smooth UI and no Play services or phone number requirement. Running a really light prosody[1] instance on my server to host my own XMPP connection, although since it's all E2E, I could have used a public one. [0] https://f-droid.org/repository/browse/?fdid=eu.siacs.convers... [1] https://prosody.im/

I've run this, and I also found it easy to set up and use. However, my understanding is that you only get end-to-end encryption with OTR, and that OTR can only be used with both parties online at the same time. Am I mistaken about this?
Post reply on HN