Live data from Hacker News

Moxie Marlinspike Makes Encryption for Everyone

popsci.com

61–70 of 144 posts

Re: Moxie Marlinspike Makes Encryption for Everyone

#61

Earlier quoted context omitted.

It is your assumption that the perceived threat is a 'nation-state', not mine. Personally I'm not to worried about them and I'm more concerned with advertisers and data brokers. Let's take that brief dig into those 'malware' reports, shall we? Here's one from the Wall Street Journal[0] from last year. Some choice quotes: "Security-software maker Avast called out a trio of malicious Android apps that were, until recen…

> It is your assumption that the perceived threat is a 'nation-state'... ... That was the opening sentence of my paragraph that demonstrated that there is no such thing as "guaranteed security". If you think that there is such a thing, then you're going to be confused about many things when you think about security matters. To the rest of your comment: You need to keep things in perspective. [0] * On Windows, Mac, an…

At issue further up the thread was whether insisting on using Google Play to distribute Signal for security reasons was sound logic, right? Forgive me if I missed the point but I thought that's what we were debating. That's why I provided the specific example above which showed malware distributed via the Google Play store. this advanced my position that an app insisting on distribution via Google Play store exclusively is not automatically more secure than alternative distribution methods.

What part of your response above advances your counter-argument please? The closest you came was saying that "Actual "take over your computer" malware doesn't exist in either the Play Store or the App Store." but this is directly contradicted by this story from just yesterday: http://www.slashgear.com/viking-horde-malware-uses-google-pl... (plenty of other sites covering this too)

I'm also unclear about missing limbs being somehow analogous to 'abandoned' phones. Let's set that aside and have a look at this chart on Wikipedia: https://en.wikipedia.org/wiki/Android_version_history Can you look at that and still say that updates are not a wide-spread problem? It links to sources and indicates to me that most Android phones are not using a current version with up-to-date security patches. Do you disagree?

I've stated from the beginning that I disagree that distribution via Google Play is any guarantee of security and provided links to specific examples of malware in the Google Play store as evidence that Google Play has repeatedly been used to distribute malware to many millions of devices. Can you rebut this?

As an aside, I'm reading your reply and I'm thinking to myself "If someone needed a comprehensive 'how-to' for a straw man argument then this one is pretty good". Also please consider that popups were a real problem as late as the early 2000's. That means you must be thinking I am in my early teens, if I am to take your "Are you old enough to remember popup web advertising?" comment at face value. I have to say it isn't helping to persuade me, and is having the opposite effect.

Re: Moxie Marlinspike Makes Encryption for Everyone

#62

Not for people who don't want Google on their device. He only wants distribution via Google, and even went as far to demand that free/libre Play-alternative F-droid removed their build of TextSecure. See: https://fdroid.eutopia.cz/

Moxie recently posted more of his thoughts on the subject:

https://news.ycombinator.com/item?id=11672892

Re: Moxie Marlinspike Makes Encryption for Everyone

#63
post #48

Earlier quoted context omitted.

Signal has reproducible builds for Android: https://whispersystems.org/blog/reproducible-android/ ...that just doesn't work with F-Droid. And building on their farm means that you have to trust them, and their build farm becomes a prime target if you want to infect lots of apps at once. In the play store, you sign your build, and Android will only let you install builds signed with that same key as updates. By moving…

> By moving the signing to F-Droid, you have to completely trust them. Which you do anyway if you use Google Play Services. ...

A user that is prepared to access the apk can verify the signature of the app they have on their device.

(So the compromise of F-Droid that results in a signed, compromised binary can't happen on Google Play, the apk is signed before it is sent to the store)

Re: Moxie Marlinspike Makes Encryption for Everyone

#64

Not for people who don't want Google on their device. He only wants distribution via Google, and even went as far to demand that free/libre Play-alternative F-droid removed their build of TextSecure. See: https://fdroid.eutopia.cz/

I think we're missing some information here. The supplied link says that the applications have been renamed due to legal threats. This seems completely reasonable to me. The names of the apps are trademarks and for a security product, who builds it is important to the integrity of the mark. I'm trying to remember how Android works, but I seem to recall that you need to sign the packages differently on Play and Fdroid…

> He decided not to. That's completely his right. He doesn't go into a lot of detail about why he has decided this, but it's completely up to him.

He doesn't like how F-Droid uses centralized signing keys which are stored online: https://github.com/WhisperSystems/Signal-Android/issues/127#...

Re: Moxie Marlinspike Makes Encryption for Everyone

#65
post #17
post #9

Earlier quoted context omitted.

Here is moxie's reply in that matter https://news.ycombinator.com/item?id=10665520

I don't buy his arguments. It's one thing to say we have to be on Google Play Store or we have to use phone numbers despite the privacy implications because that is what people use. But ignoring much of the developing countries (see whatsapp), China or the people who are your strongest user base by saying "you can just" isn't pragmatic at all. Nor is it actually reasonable that we should expect to or rely on a few pe…

> But ignoring much of the developing countries (see whatsapp), China

Moxie says Signal works fine in China: https://github.com/LibreSignal/LibreSignal/issues/37#issueco...

Re: Moxie Marlinspike Makes Encryption for Everyone

#66
post #48

Earlier quoted context omitted.

Signal has reproducible builds for Android: https://whispersystems.org/blog/reproducible-android/ ...that just doesn't work with F-Droid. And building on their farm means that you have to trust them, and their build farm becomes a prime target if you want to infect lots of apps at once. In the play store, you sign your build, and Android will only let you install builds signed with that same key as updates. By moving…

> By moving the signing to F-Droid, you have to completely trust them. Which you do anyway if you use Google Play Services. ...

What does Play Services have to do with anything? APKs downloaded from the Play Store are signed by a key the developer holds and validated by Android's PackageManagerService which is open source.

Re: Moxie Marlinspike Makes Encryption for Everyone

#67

Earlier quoted context omitted.

These are some good points but when you say "He only wants distribution through channels that provide the same security assurances and deployment features that Google does through the Play Store." it must be noted that this isn't a guarantee of security. A quick search of 'Google Play malware' returns many results from 2016 and going back to when it was still called Android Market. This isn't hand-waving, there are m…

> ...it must be noted that this isn't a guarantee of security. Yes, and if a nation-state is after you , you almost certainly don't have the OPSEC discipline required to keep your computing devices secure. Security isn't binary, it's a gradient. Ever more secure devices require ever higher costs, whether they be monetary costs, lost time, or procedural complications. > A quick search of 'Google Play malware' returns…

It's also important to remember that anyone who can compromise your Google account or put legal pressure on Google can remotely install software on your device without interaction from you, and that there have been attacks in the past that have hijacked credentials in suck a way that the attacker doesn't even need to do that.

Re: Moxie Marlinspike Makes Encryption for Everyone

#68
post #17

Earlier quoted context omitted.

I don't buy his arguments. It's one thing to say we have to be on Google Play Store or we have to use phone numbers despite the privacy implications because that is what people use. But ignoring much of the developing countries (see whatsapp), China or the people who are your strongest user base by saying "you can just" isn't pragmatic at all. Nor is it actually reasonable that we should expect to or rely on a few pe…

> But ignoring much of the developing countries (see whatsapp), China Moxie says Signal works fine in China: https://github.com/LibreSignal/LibreSignal/issues/37#issueco...

Signal itself works, but since Google is blocked no phones are sold with Google Play Store and even if you hack it onto your phone (which will break when it wants to update play services) it will drain your battery trying to connect to blocked services. Unless you use vpn (which will drain battery by itself and also eventually be blocked), but notifications probably still won't work because of the phones original firmware. So yes it works if you hack it onto your phone and then remove play services and checks the application manually. Until it wants to update the app that is, which is often.

Point. It doesn't really work because it only supports the Google Play Store, even as most Chinese phones can load apps directly (because of the fragmented ecosystem). So at least it doesn't work in the "prevent mass surveillance" way.

I guess maybe it works from the Apple App Store? (which isn't blocked)

Re: Moxie Marlinspike Makes Encryption for Everyone

#69

Earlier quoted context omitted.

I think we're missing some information here. The supplied link says that the applications have been renamed due to legal threats. This seems completely reasonable to me. The names of the apps are trademarks and for a security product, who builds it is important to the integrity of the mark. I'm trying to remember how Android works, but I seem to recall that you need to sign the packages differently on Play and Fdroid…

> He decided not to. That's completely his right. He doesn't go into a lot of detail about why he has decided this, but it's completely up to him. He doesn't like how F-Droid uses centralized signing keys which are stored online: https://github.com/WhisperSystems/Signal-Android/issues/127#...

Thanks for that link. It is much more informative than the other one. I can see where he's coming from. Some of the things he wants as a developer are things that I don't personally want as a user (automated updates), but then I can build and install the thing myself, as he says.

Re: Moxie Marlinspike Makes Encryption for Everyone

#70
post #24
post #9

Earlier quoted context omitted.

Here is moxie's reply in that matter https://news.ycombinator.com/item?id=10665520

>1) Make mass surveillance impossible. By giving NSA the only thing what they want: metadata from Google >2) Stop targeted attacks against crypto nerds. Who don't have google services on their devices and don't use google chrome... yeah. Thanks for helping me so much. The Senate is considering reauthorizing the law the NSA says authorizes it to collect hundreds of millions of online communications from providers like…

> By giving NSA the only thing what they want: metadata from Google

What metadata does Google get from Signal messages? The time/date you received a message, the size of the message... Is there anything else?

Post reply on HN