Live data from Hacker News

What the CIA WikiLeaks Dump Tells Us: Encryption Works

nytimes.com

51–60 of 270 posts

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#51

Earlier quoted context omitted.

That's something we can't do anything about though.

We can't do anything about the phone number requirement?

Actually magic link sent to your email would be MUCH better. Also central authority but Gmail >>> any telecom

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#52

The article mentions WhatsApp multiple times as a service that successfully made the transition to end-to-end encryption, but it always seemed to me that this claim is rather meaningless when we don't have the possibility of auditing their source code.

There are no secure smartphones (devever.net)

https://news.ycombinator.com/item?id=10905643

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#53
post #23
post #9

Earlier quoted context omitted.

How can you personally verify that any 3rd party service is doing what it claims? Unless you're a security expert with plenty of time to comb through someone else's code, you're still relying on others to be truthful and competent. Even then you're relying on layers upon layers of software and hardware. Far too much for an individual to verify.

You rely on a net of diverse independent reviewers instead of a single entity with a particular interest. A peer reviewed distributed trust net is much more trustworthy.

There's no such net, nobody is signing the binaries.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#54
post #51

Earlier quoted context omitted.

We can't do anything about the phone number requirement?

Actually magic link sent to your email would be MUCH better. Also central authority but Gmail >>> any telecom

It also doesn't have to be a central authority, since "anyone" (meaning: anyone who can afford to operate a mailserver, which is actually a surprisingly-high number) can be such an authority for one's own mail.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#55
post #41

Earlier quoted context omitted.

https://source.android.com/ The source code for Android is open under the Apache 2.0 license. Of course, iOS and Windows are closed source.

You're ignoring that most drivers for android phones are proprietary, the baseband is entirely proprietary (required by law), the Google services are proprietary (which many apps use) and most apps are proprietary (including Google's replacements for the AOSP apps). If you want a completely free software smartphone experience, it is simply not possible at the moment. Even Replicant[1] still hasn't cracked the baseban…

Basebands fall under exactly which entities juristiction such that they can regulate a baseband to be 'entirely proprietary' ? I mean, BB + superhet. mixer => IF => carrier wave envelope containing your data. How do you even regulate a concept of physics? If you're paying the proper fees as a subscriber to $provider_foo you could even design your own receiver off the public standards documents.. (used to be a popular project for 4th year undergrads to do on FPGAs for the CE's who wanted to get closer to the silicon but MOSIS project space was reserved for only the EEs).

If you want a completely 'free' (as in GPL) cell phone experience, you can setup a OpenBTS transmitter and transmit at the 900mhz range which is commons property. To stay legal in the US, your antenna has to put out less than a watt, but the setup allows you to even use off-the-shelf phones and trunk into normal phone lines via standard POTS software. Your device would have to be something a-la http://alumni.media.mit.edu/~mellis/cellphone/ (just a janky setup, but just a proof-of-concept -- you can patch together components from DigiKey pretty easily these days; if you want free-silicon, I think the closest you're going to get is https://en.wikipedia.org/wiki/OsmocomBB or maybe some soft cores, but if you're actually going to take that soft core to tape-out, you're probably going to be running 6 figures just for masks...)

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#56

The article mentions WhatsApp multiple times as a service that successfully made the transition to end-to-end encryption, but it always seemed to me that this claim is rather meaningless when we don't have the possibility of auditing their source code.

Puff and bluff. Assume that they are trying to save their asses only.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#57

The article mentions WhatsApp multiple times as a service that successfully made the transition to end-to-end encryption, but it always seemed to me that this claim is rather meaningless when we don't have the possibility of auditing their source code.

> this claim is rather meaningless when we don't have the possibility of auditing their source code

Open source is required not just for apps, but also for:

- operating systems

- drivers

- firmware

Then we can start to talk about privacy.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#59
post #51

Earlier quoted context omitted.

Actually magic link sent to your email would be MUCH better. Also central authority but Gmail >>> any telecom

It also doesn't have to be a central authority, since "anyone" (meaning: anyone who can afford to operate a mailserver, which is actually a surprisingly-high number) can be such an authority for one's own mail.

Practically nobody is running own mail server these days. Email is extremely centralized

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#60

The article mentions WhatsApp multiple times as a service that successfully made the transition to end-to-end encryption, but it always seemed to me that this claim is rather meaningless when we don't have the possibility of auditing their source code.

if the cia has to bypass it by hacking users phones it seems to apply the encryption itself is solid.

no. it means there are far easier ways to spy stuff, thats all.
Post reply on HN