How the Textsecure Protocol Works
41–50 of 87 posts
Re: How the Textsecure Protocol Works
#42Earlier quoted context omitted.
Perhaps people are responding to your unwarranted, toxic tone, your rudeness elsewhere in the comments, and your inability to give even a modicum of respect to the developers who've not only designed and openly published groundbreaking advances in secure private messaging protocols, and not only implemented them and freely distributed those implementations, but have also worked to have those designs incorporated into…
It lacks the most basic, fundamental property of a secure system: A demonstration (actual proof can wait!) that it can be trusted without handwavium. I don't care if it's the dog's bollocks or the bee's knees. If I can't trust it, it's useless for secure communication. I don't give the tiniest shit how many hours some twat on the internet, or well-paid collection of highly-trained twats, has poured into its creation…
Re: How the Textsecure Protocol Works
#43Earlier quoted context omitted.
No. If the section beginning "Protocol" is what you refer to as the "actual protocol description" then no, the server role does not seem clearly described in any level of detail. To cut a long story short: Alice gives the cache, aka Mallory, a set of secret data which are implied but not proven to be able to be used by Bob to create cryptographic text which Alice can decrypt but this magic cache, aka Mallory , cannot…
The cache contains ephemeral _PUBLIC_ keys, that would otherwise be transmitted to anyone who requests them by the message recipient (perhaps through some encrypted channel, but without meaningful authentication). In essence it's the same thing as PGP's encryption subkeys, which are completely published, but the cache contains more of them as the keys are preferably only used once (there is one difference in that the…
I know that doesn't sound quite so impressive, but that's because it isn't.
Re: How the Textsecure Protocol Works
#44Re: How the Textsecure Protocol Works
#45Earlier quoted context omitted.
I just love reading post-optimisation machine code.
The point was you don't, but plenty of people do. And those people haven't sounded the alarm on any red flags.
Re: How the Textsecure Protocol Works
#46> Instead, copies of the server's role in the key negotiation are stored by a centralized server for potential clients to fetch and use. This "centralised" and "server" are just about the worst words you want to hear in the description of a system like this and yet they are just thrown in there in a flippant comment at the end of a section? I think a more detailed description of this glorified cache is warranted.
Oh it's not warranted is it? Does whichever butthurt shill clicked that button want to suggest why we don't need more detail on which central server stores what in this self-proclaimed "secure" system?
Re: How the Textsecure Protocol Works
#47Earlier quoted context omitted.
Pretty much everyone who's job involves using IDA Pro does this every day.
People who use disassemblers for a living enjoy reading machine code? Holy! Fuck! Just call me Watson, Sherlock!