Live data from Hacker News

Moxie Marlinspike has a plan to reclaim our privacy

newyorker.com

231–237 of 237 posts

Re: Moxie Marlinspike has a plan to reclaim our privacy

#231

I don't know enough about Moxie Marlinspike or Signal to really have an opinion, and was hoping to maybe learn something by reading this but I'm afraid this is more hagiography than profile.

What is it about cryptography that creates a tendency toward hagiographies?

During the Snowden Leaks the same thing happened with Jacob Appelbaum and Julian Assange. There was no critical analysis on what they were actually doing or a lot of the advice they were giving people.

It's almost like the field somehow requires a defacto head who conveniently fits the media stereotype.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#232

Earlier quoted context omitted.

Bug bounties alone don't prove anything. https://www.schneier.com/blog/archives/2005/12/bug_bounties_...

Directly from the first three sentences of your link: > Paying people rewards for finding security flaws is not the same as hiring your own analysts and testers. It’s a reasonable addition to a software security program, but no substitute. Sounds like a reasonable addition to me!

Where are the audits of MTProto2 then?

Re: Moxie Marlinspike has a plan to reclaim our privacy

#233
post #211

Earlier quoted context omitted.

You claimed that the reason to trust MTProto 2 because it is based on standard primitives and because no security research had yet found a bug. I was responding to that, and only that, because it an invalid security argument, and irrelevant to the ‘admonishment’ of the other commenter. The 100k bounty is a somewhat better argument. It would have been far more helpful to lead with that.

Now you're putting words in my mouth. I did indeed say MTProto 2 was based on standard primitives and no one has publicly claimed it insecure or vulnerable. I did not say to trust MTProto 2 any more than you would trust the Signal Protocol: that is given the information we have on known vulnerabilities one appears about as good as the other.

You said exactly what I claim you are saying:

“You are welcome to develop your argument and point out where in MTProto 2 you find fault or why using standard crypto primitives isn't enough and what you'd like to see from MTProto 2 to secure it in your mind.”

The only person putting words in someone’s mouth is you - I never compared MTProto 2 to signal. You keep claiming that you never said MTProto 2 is more secure than signal. I never said you did.

The idea that being based on standard primitives is enough is a commonly held but dangerous piece of cryptographic reasoning.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#234
post #233

Earlier quoted context omitted.

Now you're putting words in my mouth. I did indeed say MTProto 2 was based on standard primitives and no one has publicly claimed it insecure or vulnerable. I did not say to trust MTProto 2 any more than you would trust the Signal Protocol: that is given the information we have on known vulnerabilities one appears about as good as the other.

You said exactly what I claim you are saying: “You are welcome to develop your argument and point out where in MTProto 2 you find fault or why using standard crypto primitives isn't enough and what you'd like to see from MTProto 2 to secure it in your mind.” The only person putting words in someone’s mouth is you - I never compared MTProto 2 to signal. You keep claiming that you never said MTProto 2 is more secure th…

> You claimed that the reason to trust MTProto 2 because it is based on standard primitives and because no security research had yet found a bug.

Those are the words you put in my mouth. I don't trust MTProto 2. When did I say that I trusted MTProto 2?

This whole argument was me putting bad research to shame and then challenging another user not you to develop their argument.

But you wanted to back them up with something about concentrated efforts from serious adversaries which is an impossible argument to refute because neither of us has the insider knowledge to know what these protocols have endured and survived since only knowledge of their successful exploitation would be on the menu for public consumption.

So please, do bring something of greater meat to the table if you have something to share.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#235
post #233

Earlier quoted context omitted.

You said exactly what I claim you are saying: “You are welcome to develop your argument and point out where in MTProto 2 you find fault or why using standard crypto primitives isn't enough and what you'd like to see from MTProto 2 to secure it in your mind.” The only person putting words in someone’s mouth is you - I never compared MTProto 2 to signal. You keep claiming that you never said MTProto 2 is more secure th…

> You claimed that the reason to trust MTProto 2 because it is based on standard primitives and because no security research had yet found a bug. Those are the words you put in my mouth. I don't trust MTProto 2. When did I say that I trusted MTProto 2? This whole argument was me putting bad research to shame and then challenging another user not you to develop their argument. But you wanted to back them up with somet…

“...why using standard crypto primitives isn't enough

Enough for what? Sure looks like an assertion of trust.

Note that I’m not saying it isn’t trustworthy, just that your argument that using standard primitives is enough, is not a reason to trust it.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#236
post #215
post #69

Earlier quoted context omitted.

On Android, Signal sets the flag on the text entry box that disables IME personalization, the same way that the text entry box works in Chrome's incognito mode. Whether or not Google respects it is not clear, but it does show a little incognito mode icon on the keyboard.

Where do you see this icon? I don't think I have an incognito icon on my signal keyboard

In older versions of Android it'll look like this (https://www.androidpolice.com/2017/07/14/gboard-6-4-brings-i...), while newer versions of Android will have an icon on the top left of the keyboard, before the stickers, gif, clipboard, and cog buttons.

This is with the default Google keyboard (gboard), your mileage may vary with other keyboards.

Post reply on HN