Earlier quoted context omitted.
Chaps. I think it's time we just admitted that everything we type/tap/say into any device, regardless of how it's being wrapped up in transit, is absolutely and irrepairably insecure and we're not going to be able to fix that anytime soon. Even with really smart crypto or some slick app; what makes you think that your messages aren't just being read by your os? Would you really notice? Why would you assume that the a…
> I think it's time we just admitted that everything we type/tap/say into any device, regardless of how it's being wrapped up in transit, is absolutely and irrepairably insecure and we're not going to be able to fix that anytime soon. We dont have to set the bar that high. Just lower it slightly and we can achieve great success. Can we make the job of NSA and CIA harder? Not necessarily impossible, just to increase t…
There are too many places, even on a phone, where anything at all can be hiding and we don't really have any way of ever knowing what's there without stepping through the binaries.. That's even more difficult when we've got dalvik and VM's involved. How many people alive do you think could work out exactly what your mobile does in any one second within say, 6 months? ..
For all we know the thompson compiler backdoor really happens, and so how can you even trust the binaries you're producing?
Do you know anyone who built, for instance the openssl.so on their phone personally? Did that person build it on a machine they trust? How can they trust that machine? A single lib with a nefarious function on the few GB of binaries which ship with your phone is enough to completely negate any 'security' these sorts of apps could provide; even if they were trustworthy to begin with which they're obviously not.
It's a charade, assume everything you do is completely observed, regardless of crypto/apps you use.
Even if you have a fully audited and trustworthy (in your view) OS -- then what about IME? Who says that the CA that issued the certs you trust and talk to isn't also feeding them out to the gov or whatever? Who says your HDD isn't talking to the zigbee thermostat in your house and sending your rsa keys to the pentagon? Who says yo home wifi point isn't acting as a decrypting proxy?
We cant tell, and that's the point. There is no way to ever observe these levels complexity and verify security and we don't admit it.
We will never know if the code we are running on our various devices is doing anything extra or not, and so rationally, we should never trust it at all.
Not to say all sec is pointless, you don't want to be low hanging fruit, but above 'insta-pwn' levels of stupid there isn't much more available, even if you're told there is and we keep pretending like we have any control over what's going on anymore...