Live data from Hacker News

Cryptocat for iPhone and Android – Call for Review

blog.crypto.cat

1–10 of 84 posts

Re: Cryptocat for iPhone and Android – Call for Review

#4
post #3

And why the hell should i use a app that is written by know poeple that prooven they have no clue about crypto? Why shouldn't i use one of the many apps that support OTR?

Cryptocat's private chat uses OTR. Our group chat function uses an open and studied multiparty protocol. Generally, our security bugs have been implementation errors much more than protocol design errors.

Surely, the best we can do as a community project is open up our code for more volunteers and experts to help and take a look. :-)

Re: Cryptocat for iPhone and Android – Call for Review

#5
Glad that they're taking security seriously. It's a sharp difference from how they used to do things[1]. However, I'd still like to see either an explicit bug bounty (there's one implied here) or a paid audit.

[1]: http://blog.cryptographyengineering.com/2013/03/here-come-en...

Re: Cryptocat for iPhone and Android – Call for Review

#6
can you give some screenshots or videos of the fingerprint showing mechanism?

My biggest concern with cryptocat is that this info is kind of hidden and not bubbled up to the user.

In the web version, the way its handled makes it possible for the server operator to replace who you are talking to mid-conversation without warning unless you click a fingerprint button before and after every message you send which nobody is going to do

I know there is an issue for this on the web version ( https://github.com/cryptocat/cryptocat/issues/463 ), just wondering if the mobile ones take a different approach.

Re: Cryptocat for iPhone and Android – Call for Review

#7
post #5

Glad that they're taking security seriously. It's a sharp difference from how they used to do things[1]. However, I'd still like to see either an explicit bug bounty (there's one implied here) or a paid audit. [1]: http://blog.cryptographyengineering.com/2013/03/here-come-en...

From my perspective, we've been taking security seriously a year+. Our first commissioned audit was in November 2012, and we've had a bug bounty since then as well: https://crypto.cat/bughunt/

This isn't, of course, to say that there haven't been vulnerabilities. But I have to stand behind our mitigation and disclosure policy as being very highly responsible and transparent.

So far, we've had three paid audits, with two more lined up, and regularly reward community bug-finders. We're planning more competitions for Cryptocat Mobile in March and April, with prizes such as iPhones and Nexus Phones. :-)

Re: Cryptocat for iPhone and Android – Call for Review

#9
post #4
post #3

And why the hell should i use a app that is written by know poeple that prooven they have no clue about crypto? Why shouldn't i use one of the many apps that support OTR?

Cryptocat's private chat uses OTR. Our group chat function uses an open and studied multiparty protocol. Generally, our security bugs have been implementation errors much more than protocol design errors. Surely, the best we can do as a community project is open up our code for more volunteers and experts to help and take a look. :-)

Great to hear that you switched to older and audited code. Could you explain what relationship this app has to the javascript version?

Re: Cryptocat for iPhone and Android – Call for Review

#10

I will say from skimming over the source tree the amount of code in CryptoCat(android) is surprisingly light. This is very refreshing compared to other chat applications which are unnecessarily huge. Will be definitely going over this later.

Cryptocat for Android is particularly unfinished so far. I would be surprised if you don't find bugs inside. Cryptocat for iPhone is currently a lot more mature, but similarly still needs peer review.

We have a commissioned audit for both apps, but it won't be starting for another two weeks. Thanks SO MUCH for your interest. We rely on security enthusiasts for comments and advice.

Post reply on HN