Live data from Hacker News

iOS 10 Security White Paper [pdf]

apple.com

91–99 of 99 posts

Re: iOS 10 Security White Paper [pdf]

#91
post #32

Earlier quoted context omitted.

> Anyone here on an Android phone ever been hacked? You must be new, but here's some resources I suggest you review before you go on a crusade in future Apple articles: https://en.wikipedia.org/wiki/Stagefright_(bug) https://arstechnica.com/security/2016/06/godless-apps-some-f... https://arstechnica.com/security/2016/10/android-phones-root... http://blog.elevenpaths.com/2016/07/another-month-another-ne... Also, keep…

I suggest you read the Android Security 2016 Year in Review before posting any further links to blog sites whose primary goal is to post scaremongering articles for click bait. According to Adrian Ludwig there has not been one known successful StageFright exploit in the wild. https://static.googleusercontent.com/media/source.android.co...

FWIW, the Wii U jailbreak is via stagefright. I realize it's not android, but worth noting it has been used in the wild in some capacity.

Re: iOS 10 Security White Paper [pdf]

#92
post #88

Earlier quoted context omitted.

https://www.jwz.org/blog/2017/03/signal-leaks-your-phone-num...

Be careful about jwz links on HN. He detects the referrer and redirects to a prank image.

Whoops. And it's too late now to edit the link to point at a referrer-stripper, too.

Re: iOS 10 Security White Paper [pdf]

#93
post #72

Earlier quoted context omitted.

You picked a bad example, as Uber car ordering does work with location services disabled. Any better examples come to mind of apps that refuse to run unless hey have an unreasonable feature granted?

Signal won't run without access to your contacts (at least on iOS). Whether that's considered "unreasonable" is being actively argued on Twitter at the moment...

Personally, I don't consider using a phone number as reasonable. Usernames should be allowed for those who don't have or don't want phones.

Re: iOS 10 Security White Paper [pdf]

#95
post #88

Earlier quoted context omitted.

Be careful about jwz links on HN. He detects the referrer and redirects to a prank image.

Whoops. And it's too late now to edit the link to point at a referrer-stripper, too.

Yeah - but if you're interested/curious, copy-paste the link into your browser. Moxie weighs in in the comments on jwz's blog there.

The "interesting" bit (to me) of Moxie's explanation of what happens is that Signal sends "truncated sha256 hashes" to the Signal servers so it can compute the intersection of all the numbers it scrapes from your contact list with everyone elses.

Seems to me there's just not enough entropy in phone numbers to make that nation-state secure.

If Moxie gets served a warrant (and a NSL) it wont take _too_ much effort to reverse out all those truncated SHA intersections into a social graph...

But then Moxie's POV seems to be "those people would get that same info from your telco records if you use SMS, and at least that's the _only_ metadata we leak, your telco probaby hands that over without a warrant along with at least the date/time of every SMS you've ever sent or received and quite probaby the contents as well...

I lean a lot towards jwz's argument that they're _way_ overselling the privacy-preserving nature of Signal. Especially if one of your adversaries is someone who knows your mobile number and would benefit from knowing you choose to use encrypted communication (like, say, everybody in the UK right now...)

Re: iOS 10 Security White Paper [pdf]

#96
post #93
post #72

Earlier quoted context omitted.

Signal won't run without access to your contacts (at least on iOS). Whether that's considered "unreasonable" is being actively argued on Twitter at the moment...

Personally, I don't consider using a phone number as reasonable. Usernames should be allowed for those who don't have or don't want phones.

I dunno. It's hard.

If you allow user-generated usernames, what's to stop me signing up as Linus Torvalds or Hillary Clinton, and creating drama for the lulz?

Using the phone number as a unique and verifiable identifier seems like a pragmatic - if not perfect choice. By using the SMS confirmation it makes it much more difficult for me to impersonate Linus or Hilary - because I'd need to impersonate their phone number _and_ respond to an SMS sent to it. Not nation state secure, but better than nothing...

The other problem Moxie's trying to solve is the discoverability problem - which jwz _doesn't_ want solved (nor do people with abusive exes or other categories of users Signal if often very vocally advocated for "Use TOR. Use Signal. Use a VPN!!!"). Moxie wants to be able to calculate the intersection of your contact list with every other Signal user's contact list, so it can prompt you to let you know you can use Signal to communicate with them which you'd otherwise probaby no know. And as he says, to be most valuable, e2e encrypted messaging needs to become the default messaging channel under normal use, so it'll not need to be installed/setup/learned under stress when it's need becomes critical.

I think Signal's got the "soundbite message" of what they do very carefully crafted and it's very enticing, but by nature soundbite sized or elevator pitch sized message inevitably leave out the complexity of edge cases.

I'm 99.99% sure Moxie isn't lying about what we could all read in the sourcecode if we cared enough to spend the time reading it - all the people jwz is concerned about sending him Signal messages already had his phone number in their contact list so could have already been sending him text messages. Moxie's view is jwz is better off having all those people know they can _also_ contact him using e2e encrypted messaging as well. jwz doesn't agree, and doesn't think letting all those people know he has installed an encrypted messaging app is "privacy protecting". There's certainly merit in both points of view.

Re: iOS 10 Security White Paper [pdf]

#98

Earlier quoted context omitted.

I suggest you read the Android Security 2016 Year in Review before posting any further links to blog sites whose primary goal is to post scaremongering articles for click bait. According to Adrian Ludwig there has not been one known successful StageFright exploit in the wild. https://static.googleusercontent.com/media/source.android.co...

FWIW, the Wii U jailbreak is via stagefright. I realize it's not android, but worth noting it has been used in the wild in some capacity.

Interesting. I didn't know the Wii U used Stagefright code. The Switch also uses Android code and was recently hacked using WebKit exploits.

Re: iOS 10 Security White Paper [pdf]

#99
post #32

Earlier quoted context omitted.

> Anyone here on an Android phone ever been hacked? You must be new, but here's some resources I suggest you review before you go on a crusade in future Apple articles: https://en.wikipedia.org/wiki/Stagefright_(bug) https://arstechnica.com/security/2016/06/godless-apps-some-f... https://arstechnica.com/security/2016/10/android-phones-root... http://blog.elevenpaths.com/2016/07/another-month-another-ne... Also, keep…

I suggest you read the Android Security 2016 Year in Review before posting any further links to blog sites whose primary goal is to post scaremongering articles for click bait. According to Adrian Ludwig there has not been one known successful StageFright exploit in the wild. https://static.googleusercontent.com/media/source.android.co...

> I suggest you read the Android Security 2016 Year in Review

Oh I have, and I am well aware of the links I chose and their accuracy, regardless of you having a different "primary goal" in mind.

Thank you though, but I've got it from here.

Post reply on HN