Live data from Hacker News

Please Stop Writing Secure Messaging Tools (2015)

dymaxion.org

61–70 of 73 posts

Re: Please Stop Writing Secure Messaging Tools (2015)

#61
post #19

That list is pure genius. I'm working with reporters mostly in non-OECD countries, 80% of the stuff on that list are real, largely unmet needs. Signal isn't perfect, but it works fine, thanks. A special place in hell should also be reserved for those in the tech world that mix up security (a real and critical need that people have) and their software politics. If you don't like Microsoft, Google, Adobe, "the Cloud",…

It's a helpful list, but I don't actually agree... Reporting isn't a high-tech job, and most of the suggestions to me seemed unnecessary. Document-sharing with edits being tracked is the big one, though (like the article raised). Also, Signal being tied to a phone number is a nightmare.

> Reporting isn't a high-tech job

I disagree. Sitting on a phone and sweet-talking sources isn't high-tech, and neither is bundling up five tweets to make a clickbait.

But as soon as you're talking about doing public records research, tracking the activities and ownership of a multi-national company, working in a team with people from 30 countries on a single story, try to manage your confidential evidence across five years, it becomes quite technical.

Re: Please Stop Writing Secure Messaging Tools (2015)

#62
post #10

The essay I wish she had written would have said, "we don't need more 'secure messaging systems' -- we should be making all the following tools secure by design" For example, (and whether you love them or hate them) Apple takes this seriously: your fingerprints don't leave the device and are implemented by a piece of hardware in such a way that even Apple doesn't have access to them. Compare that to the Android imple…

Fingerprints are insecure. They can be optained by police. They can force you to tuch to your smart phone's fingerprint sensor phisically. Best security is passprase with a TPM chip.

> They can force you to tuch to your smart phone's fingerprint sensor phisically.

Not to mention your fingerprints are all over the device!

Re: Please Stop Writing Secure Messaging Tools (2015)

#63

Earlier quoted context omitted.

HSM: https://en.wikipedia.org/wiki/Hardware_security_module GSM: https://en.wikipedia.org/wiki/GSM

By GSM you mean the baseband processor, or what?

Every standard (GSM network) phone has a Sim card that is doing some encryption with hardware protected keys. A Sim card for the GSM network.

Trying to use it for general encryption might have problems and is more often discussed than done.

Re: Please Stop Writing Secure Messaging Tools (2015)

#64
post #7
post #5

I totally agree with this guy, but who is he in the industry? Someone famous for something? Just curious.

> I totally agree with this guy, but who is he in the industry? This "guy" is a security professional; her linkedIn profile shows her working in serious security roles for over a decade.

> This "guy" is a security professional; her

This might be something more colloquial to Australians than [wherever you "guys" are posting from], but to me when I see someone referring to 'guys' (as in, "hey guys!", or, "you know, those guys") it isn't always gender specific. You can go up to a group of women and say "hi guys!".

I'm going to gloss over the part where OP then referred to the author as "he", but I just feel that the word "guy" is more and more moving away from meaning "men" and instead just "people".

I'll leave that two cent coin on the table for you guys

Re: Please Stop Writing Secure Messaging Tools (2015)

#65
post #10

The essay I wish she had written would have said, "we don't need more 'secure messaging systems' -- we should be making all the following tools secure by design" For example, (and whether you love them or hate them) Apple takes this seriously: your fingerprints don't leave the device and are implemented by a piece of hardware in such a way that even Apple doesn't have access to them. Compare that to the Android imple…

Fingerprints are insecure. They can be optained by police. They can force you to tuch to your smart phone's fingerprint sensor phisically. Best security is passprase with a TPM chip.

But fingerprints are so convenient. I'm using iPhone 4S and fingerprint sensor is a huge reason I want to upgrade, always typing PIN-code is boring. And always typing a passphrase — I'm not sure anyone would do that.

Depends on your adversaries, of course. I fear that if police might want to open my phone, they'll beat me until I'll unlock it and whether it's a passphrase or fingerprint — it doesn't matter.

Re: Please Stop Writing Secure Messaging Tools (2015)

#66
post #63

Earlier quoted context omitted.

By GSM you mean the baseband processor, or what?

Every standard (GSM network) phone has a Sim card that is doing some encryption with hardware protected keys. A Sim card for the GSM network. Trying to use it for general encryption might have problems and is more often discussed than done.

Ahh, just say SIM. GSM is the network, SIM is the module.

SIMs are basically just javacards, so having custom crypto applications on them is no big deal, but you need some control of the SIMs your users will want to use in your device for it to be practical.

Re: Please Stop Writing Secure Messaging Tools (2015)

#67
post #55
post #10

The essay I wish she had written would have said, "we don't need more 'secure messaging systems' -- we should be making all the following tools secure by design" For example, (and whether you love them or hate them) Apple takes this seriously: your fingerprints don't leave the device and are implemented by a piece of hardware in such a way that even Apple doesn't have access to them. Compare that to the Android imple…

> Apple takes this seriously Anyone who takes security seriously should open-source the security aspects of the system. Putting them in a proprietary black box is one the worst ways to guarantee security. Also, fingerprints or few-digit pins should be only used as casual deterrents to people grabbing and doing something with your phone before you can get to it. Those should not be used to encrypt sensitive data. Good…

Apple does take security quite seriously: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

The iOS 11 version and detailed FaceID details should be coming out soon as well.

Re: Please Stop Writing Secure Messaging Tools (2015)

#68
post #63

Earlier quoted context omitted.

Every standard (GSM network) phone has a Sim card that is doing some encryption with hardware protected keys. A Sim card for the GSM network. Trying to use it for general encryption might have problems and is more often discussed than done.

Ahh, just say SIM. GSM is the network, SIM is the module. SIMs are basically just javacards, so having custom crypto applications on them is no big deal, but you need some control of the SIMs your users will want to use in your device for it to be practical.

Google is US focused so they presumably still deal with non GSM networks and the possibility of running a fingerprint without a gsm standard SIM.

* I.e. there are a lot of issues for Google generalizing encryption via some user provided sim as datails come up. So maybe he is referring to an entirely different crypto module.

Re: Please Stop Writing Secure Messaging Tools (2015)

#69
post #7

Earlier quoted context omitted.

> I totally agree with this guy, but who is he in the industry? This "guy" is a security professional; her linkedIn profile shows her working in serious security roles for over a decade.

> This "guy" is a security professional; her This might be something more colloquial to Australians than [wherever you "guys" are posting from], but to me when I see someone referring to 'guys' (as in, "hey guys!", or, "you know, those guys") it isn't always gender specific. You can go up to a group of women and say "hi guys!". I'm going to gloss over the part where OP then referred to the author as "he", but I just…

Sure, that’s often the case, and I would even have given the usage the benefit of the doubt but then, as you noted, OP said “he”.

But in fact “guy” means “man or woman” the way “he” can mean “man or woman” or how someone will say “ethnic” to mean “non-white. It doesn’t mean the sayer is a sexis/racist/jerk/etc, but it does subtly and casually reinforce a way of looking at the world. So worth correcting without making a huge thing of it.

And yes I’m an Aussie (...and as I was continually reminded as a kid, and sometime still am, I’m a wog too)

Re: Please Stop Writing Secure Messaging Tools (2015)

#70

Earlier quoted context omitted.

Fingerprints are insecure. They can be optained by police. They can force you to tuch to your smart phone's fingerprint sensor phisically. Best security is passprase with a TPM chip.

But fingerprints are so convenient. I'm using iPhone 4S and fingerprint sensor is a huge reason I want to upgrade, always typing PIN-code is boring. And always typing a passphrase — I'm not sure anyone would do that. Depends on your adversaries, of course. I fear that if police might want to open my phone, they'll beat me until I'll unlock it and whether it's a passphrase or fingerprint — it doesn't matter.

Pasprase with TPM works only when you boot your computer (smart phone).

It is okay to use fingerprint to open the screen. But there should be shut-down finger.

Post reply on HN