Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

91–100 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#91

Earlier quoted context omitted.

I'd like to learn some possible reasons why one should avoid cryptocat, is there any material you could link for further reading? Thank you

I am the original author of the software you refer to. Before its complete rewrite (released two months ago), Cryptocat was based on a codebase that I wrote starting in my early undergrad and that was notorious for containing many high-severity vulnerabilities. The most important was "Decryptocat", documented by Steve Thomas [0] but we also had: * AES-CTR counter-reuse (2012) * Biased Fortuna CSPRNG implementation [1…

For what it's worth, Steve Thomas's vulnerability was not the most important in that code. I think Steve Thomas (fair warning: a friend) might dispute the "full disclosure" comment you made, as well.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#92
post #2

This is fantastic news. The two largest messaging platforms on the Internet will both be using Signal protocol. I could ask for more: E2E could be the default for Allo, and it isn't. That's not great. But the E2E you get when you ask for it will apparently be best-in-class.

The article didn't make it clear. Will the two systems be able to interoperate?

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#94
post #91

Earlier quoted context omitted.

I am the original author of the software you refer to. Before its complete rewrite (released two months ago), Cryptocat was based on a codebase that I wrote starting in my early undergrad and that was notorious for containing many high-severity vulnerabilities. The most important was "Decryptocat", documented by Steve Thomas [0] but we also had: * AES-CTR counter-reuse (2012) * Biased Fortuna CSPRNG implementation [1…

For what it's worth, Steve Thomas's vulnerability was not the most important in that code. I think Steve Thomas (fair warning: a friend) might dispute the "full disclosure" comment you made, as well.

Of course, I was only referring to vulnerabilities I could verify are real.

Steve was paid two separate bug bounties and invited to a Cryptocat hackathon in NYC. I also consider him a friend and never heard a complaint from him regarding the project's disclosure policies.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#95
post #26
post #17

Earlier quoted context omitted.

Moxie's on the record as being opposed to federated services. https://whispersystems.org/blog/the-ecosystem-is-moving/

I don't think I'd characterize his blog post that way. The last sentence captures what I got from reading it: "It may not be as beautiful as federation, but at this point it seems that it will have to do." Also, as djb points out: https://twitter.com/hashbreaker/status/732912508089032706

Moxie's essay is strong and djb's point is not: a "federated network" with a centrally controlled app that updates automatically might as well not be federated at all: at that point having multiple servers hardly matters. Who cares about running your own server if you can't run your own client?

Moxie has put into words what I've been thinking myself for a long time - the old federated protocols from the 1990s have been slowly dying off (with email being the main holdout, unless you count gmail). And the reason is that they just don't evolve. There's no incentive to evolve them, there's no organisational structure to evolve them, creating them takes huge effort AND they suffer from all sort of hidden ideological constraints that would prevent them from e.g. doing a partnership with Uber beause Uber is a corporation and an open protocol isn't. But users don't care about that.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#96
post #6

Earlier quoted context omitted.

Uh, where are you defining Allo as one of the largest messaging platforms on the internet? It literally just launched. It might do well, but it could also easily be a flop (as many other social initiatives from Google have been). Either way it's a long ways from catching up to WeChat, Viber, or even Facebook Messenger.

It's going to end up on a lot of Android phones. If it's any good, it will catch on. Hangouts hasn't caught on that much because, imho, it has bad UI.

Agreed.

Hangouts didn't catch on because it was delivered as a group video calling service that then also did (or perhaps became about?) text, even becoming the default SMS app on Android.

It also hasn't caught on because it is overly complex. With any other video calling service you call a person and they have a conversation with you - of you initiate a group conference and off you go.

Hangout needs you to invite someone, but then what - you're still having this video broadcast by yourself? Actually, is it a broadcast? Can other people just join in? Apparently they could depending on your settings (in the past), but not this seems to have been separated to 'Hangouts On Air'? Who knows, I don't see why I should bother looking into it when there are clearer options available.

I love me some Google, so don't misunderstand me, and Duo is a big step in the right direction for the average users experience compared to Hangouts.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#97

To me it seems like Open Whisper Systems are accepting a lot of concessions in order to have Signal included into products. The trust I once had for moxie is quickly dissipating. * Privacy is only provided in Allo in a secondary mode. Not by default. * Federation of the Signal protocol has been rejected for non-technical reasons. Also, on a personal note, the desktop client requiring chrome is pretty awful.

WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages, no real ability for the servers to do anything smart, no real search functionality, desktop client that requires the phone to be on, etc. An incognito mode allows the default mode to have more functionality, and matches their approach with Chrome. It's not a bad tradeoff.

> WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages

Small clarification: WhatsApp actually does seem to have a backup feature, at least on my Android phone. I was prompted by the application to enable it just this morning.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#98
post #85
post #77

Earlier quoted context omitted.

You kinda repeat yourself here, and it's not really a response to my post here. I found the answer from a sibling post: https://twitter.com/moxie/status/730289041493483520 Moxie should use this incident to prominently make it clear in the protocol documentation that independent implementations are welcome. That's our best bet until there's an IETF RFC based on Axolotol everyone can implement instead.

Since nobody has provided any evidence that OWS ever suggested that using their documentation was improper, you might just as well suggest Moxie use this "incident" as an opportunity to announce that he's stopped beating his wife.

I don't understand the cultural reference and I'll assume it's irrelevant, but the Oracle vs Google saga made me very very cautious when it comes to clean room reimplementations of public bits, and if I were to earn money with such a library, I'm afraid I'd need more than Moxie's tweet.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#99
post #91

Earlier quoted context omitted.

For what it's worth, Steve Thomas's vulnerability was not the most important in that code. I think Steve Thomas (fair warning: a friend) might dispute the "full disclosure" comment you made, as well.

Of course, I was only referring to vulnerabilities I could verify are real. Steve was paid two separate bug bounties and invited to a Cryptocat hackathon in NYC. I also consider him a friend and never heard a complaint from him regarding the project's disclosure policies.

From the Decryptocat post:

The bug that lasted 347 days was the confusion between a string and an array of integers. This made the ECC private keys ridiculously small because they passed a string of decimal digits into a function expecting an array of 17, 15 bit integers. Each character was considered an element in the array. So each of those "15 bit integers" were only the values 0 to 9 (3.32 bits). Also the least significant 3 bits are zeroed giving you a key space of 210^16 (2^54.15).*

When they fixed that bug the commit message was: "Fix private key format to match curve25518-donna. THIS BREAKS COMPATIBILITY WITH PREVIOUS CRYPTOCAT VERSIONS." Even though this does not break compatibility at all. I don't know if they knew what they fixed and just wanted to slide this under the radar or they legitimately believe that. Both are scary one is violating their principles "Cryptocat is developed under a principle of radical transparency" and the other is just incompetence. There is a blog post by them saying this is inaccurate. Apparently they have too many serious bugs to keep straight. That they don't know which one breaks compatibility. The other error in the change log for version 2.0.42 is a bug where the counter in AES-CTR is reused. This means the first 32 bytes of your messages are easy to decipher with no effort at all. Which breaks compatibility, but everywhere they mention compatibility they say key generation.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#100

Earlier quoted context omitted.

It's going to end up on a lot of Android phones. If it's any good, it will catch on. Hangouts hasn't caught on that much because, imho, it has bad UI.

Agreed. Hangouts didn't catch on because it was delivered as a group video calling service that then also did (or perhaps became about?) text, even becoming the default SMS app on Android. It also hasn't caught on because it is overly complex. With any other video calling service you call a person and they have a conversation with you - of you initiate a group conference and off you go. Hangout needs you to invite so…

The Hangouts mobile app is also incredibly buggy.
Post reply on HN