Live data from Hacker News

Please Stop Writing Secure Messaging Tools (2015)

dymaxion.org

51–60 of 73 posts

Re: Please Stop Writing Secure Messaging Tools (2015)

#52
post #7
post #5

I totally agree with this guy, but who is he in the industry? Someone famous for something? Just curious.

> I totally agree with this guy, but who is he in the industry? This "guy" is a security professional; her linkedIn profile shows her working in serious security roles for over a decade.

Yes, you can see Eleanor speaking at a conference at https://m.youtube.com/watch?v=zqnQ0Mvi-as.

Re: Please Stop Writing Secure Messaging Tools (2015)

#53
post #5

I totally agree with this guy, but who is he in the industry? Someone famous for something? Just curious.

Just a heads up, the author is a woman. I just pulled up her other essays to read, but here is her bio from this site https://dymaxion.org/me.html .

Earlier bio: https://web.archive.org/web/20000816213404/http://dymaxion.o...

Re: Please Stop Writing Secure Messaging Tools (2015)

#54
post #19

That list is pure genius. I'm working with reporters mostly in non-OECD countries, 80% of the stuff on that list are real, largely unmet needs. Signal isn't perfect, but it works fine, thanks. A special place in hell should also be reserved for those in the tech world that mix up security (a real and critical need that people have) and their software politics. If you don't like Microsoft, Google, Adobe, "the Cloud",…

It's a helpful list, but I don't actually agree... Reporting isn't a high-tech job, and most of the suggestions to me seemed unnecessary.

Document-sharing with edits being tracked is the big one, though (like the article raised).

Also, Signal being tied to a phone number is a nightmare.

Re: Please Stop Writing Secure Messaging Tools (2015)

#55
post #10

The essay I wish she had written would have said, "we don't need more 'secure messaging systems' -- we should be making all the following tools secure by design" For example, (and whether you love them or hate them) Apple takes this seriously: your fingerprints don't leave the device and are implemented by a piece of hardware in such a way that even Apple doesn't have access to them. Compare that to the Android imple…

> Apple takes this seriously

Anyone who takes security seriously should open-source the security aspects of the system. Putting them in a proprietary black box is one the worst ways to guarantee security.

Also, fingerprints or few-digit pins should be only used as casual deterrents to people grabbing and doing something with your phone before you can get to it. Those should not be used to encrypt sensitive data. Good security comes from good, high-entropy passwords.

Re: Please Stop Writing Secure Messaging Tools (2015)

#56
post #13
post #5

I totally agree with this guy, but who is he in the industry? Someone famous for something? Just curious.

Note that not everyone on the Internet is a man.

Rule #29: In the internet all girls are men and all kids are undercover FBI agents.

Re: Please Stop Writing Secure Messaging Tools (2015)

#57
post #25

Just use Keybase!

I can't help but get an embrace, extend, extinguish vibe from keybase. It was a nifty key discovery service initially, but more and more feels like a closed platform, and gives me a sense of deja vu akin to XMPP on GTalk.

I have to agree — I was excited about Keybase, but my interest vanished as soon as they became yet another place to have an account rather than being a way to discover and semi-trust existing identities.

Re: Please Stop Writing Secure Messaging Tools (2015)

#58
post #48

Earlier quoted context omitted.

Those are all fair points, I don't disagree. Maybe disingenuous was the wrong word?

It is completely the wrong word since it describes me to be, at best, deceptive. If you don't disagree you can hardly describe claim I was lying!

I think they were trying to deescalate, and your reply is more aggressive than necessary.

FWIW, "disingenuous" carries the connotation of intentional deception, i. e. making an argument in bad faith, because one knows that it's wrong.

In this case, I can understand where the defence of Android's implementation is coming from: the original description amounted to "plain text in the filesystem, but the name ends in .mp3 so nobody will find it", whereas the reality seems to be a slightly less elegant solution that can probably be subverted by a dedicated nation-state, but is unlikely to ever make a difference in most people's lives.

Re: Please Stop Writing Secure Messaging Tools (2015)

#59

Earlier quoted context omitted.

I'm not sure what hsm/gsm stand for. I can only speak for the Android devices I work on.

HSM: https://en.wikipedia.org/wiki/Hardware_security_module GSM: https://en.wikipedia.org/wiki/GSM

By GSM you mean the baseband processor, or what?

Re: Please Stop Writing Secure Messaging Tools (2015)

#60
post #19

That list is pure genius. I'm working with reporters mostly in non-OECD countries, 80% of the stuff on that list are real, largely unmet needs. Signal isn't perfect, but it works fine, thanks. A special place in hell should also be reserved for those in the tech world that mix up security (a real and critical need that people have) and their software politics. If you don't like Microsoft, Google, Adobe, "the Cloud",…

It's a helpful list, but I don't actually agree... Reporting isn't a high-tech job, and most of the suggestions to me seemed unnecessary. Document-sharing with edits being tracked is the big one, though (like the article raised). Also, Signal being tied to a phone number is a nightmare.

Think about the "free" apps we're all using that are on that list, and wonder what Google and Apple are doing with the personal information in there.

Calendaring system: Google Calendar, iCal

Contacts databases: GMail Contacts, Apple Contacts

Location coordination tools: Google Latitude, Find My Friends.

Some of those programs don't exist, as far as I'm aware. A Wiki/Etherpad/Word style change tracking mashup, and Map-based storytelling and analysis systems are two that I'd like to see implemented.

Post reply on HN