Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…
CryptoCat iOS Application Penetration Test [pdf]
21–30 of 137 posts
Re: CryptoCat iOS Application Penetration Test [pdf]
#22Does anyone know how much these audits typically cost, if you're not being subsidized?
Re: CryptoCat iOS Application Penetration Test [pdf]
#23Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…
[deleted]
The reason we commissioned this audit is to make sure our prototype was audited before release on the App Store. We're very happy to have benefited from this audit, but linking to this PDF alone de-contextualizes the effort and makes it seem like it's an audit of the production version of Cryptocat for iPhone, whereas the version we provided was an early prototype. The audit did find some issues with the (already-released) desktop version and server configuration, and those were also fixed and documented in our blog post.
I sincerely appreciate you taking the time to read our blog post on the matter and thank you for your understanding.
Re: CryptoCat iOS Application Penetration Test [pdf]
#24Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…
[deleted]
Addendum(3/15/14): The iOS application was in development code that at time of testing was available only in a preproduction form on GitHub and not distributed via the AppStore. The CryptoCat team had time to review the vulnerabilities prior to publication in the AppStore and claims to have addressed them; however, iSEC has not validated any fixes and cannot make any claims to the current status of any vulnerabilities
Re: CryptoCat iOS Application Penetration Test [pdf]
#25Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…
> Everything is encrypted before it leaves your computer. Even the Cryptocat network itself can't read your messages.
You're seriously misleading users regarding the security of crypto -- the web is an environment that has ZERO controls on code updates. Given this remarkably self-serving and ill-conceived stance, it's difficult to imagine how your crypto could ever be considered trustworthy.
Web-based distribution simply is not, in its current form, a viable model for distributing code that must survive the compromise of the original distributing party. None of the technical (off-server code signing) or social (review of update notices) tools available in non-web distribution methods are available.
The damage that you and other projects cause to public awareness and comprehension of crypto issues is potential staggering.
When you factor in the real risks people take when relying on crypto to communicate in hostile situations, you're doing more than just making nerds grumpy -- you have the potential to significantly harm people's lives.
Crypto is not an amateur's game. Some things are too important to be left to experimentation by unqualified engineers.
Re: CryptoCat iOS Application Penetration Test [pdf]
#26Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…
OTF, again (smartly) using US taxpayer dollars, funds audits of a variety of privacy technologies.
For instance, they also funded a good-sized chunk of the Truecrypt audit.
Re: CryptoCat iOS Application Penetration Test [pdf]
#27Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…
I don't know if this is news to some people, or what, but it is usual, when having a product professionally tested, to have the testers test it in earnest, as if it were ready for release. They won't avoid telling you about some obvious hole just because it was obviously accidentally left in and would be a 10 second fix (or whatever - that is just a random example).
If you've never been through this before then, presented with a big pile of bugs, it can seem like the project has been proven a total fuckup, and its authors obvious failures, and so on. But in fact, once you've got this concrete list of all the ways in which your program has so far proven itself hopelessly unsuitable for release, it's actually quite surprising how quickly they all get fixed...
(Edit - This is more of a general comment than anything specifically about cryptocat)
Re: CryptoCat iOS Application Penetration Test [pdf]
#28Earlier quoted context omitted.
[deleted]
Page 7/35 of the report: Addendum(3/15/14): The iOS application was in development code that at time of testing was available only in a preproduction form on GitHub and not distributed via the AppStore. The CryptoCat team had time to review the vulnerabilities prior to publication in the AppStore and claims to have addressed them; however, iSEC has not validated any fixes and cannot make any claims to the current sta…
Re: CryptoCat iOS Application Penetration Test [pdf]
#29When I saw one of the main CryptoCat developers present in 2012, I came away with the impression that nobody on the core team understood crypto, security, or software engineering. This audit is another rock on the mountain of evidence I've seen supporting this impression in the following years. A really nice job by iSec, though.
It is also important to always remember that a crypto app isn't like other apps. If the protesters in Turkey rely on shoddy crypto today, it might cost them their lives a few months from now. I sincerely hope it doesn't come to that but it is a realistic example. Always be sure of what you are doing, rely on external review and never, I repeat, _never_ overstate the security of your crypto system.
Re: CryptoCat iOS Application Penetration Test [pdf]
#30Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…
You're doing crypto in the browser , while claiming on your home page: > Everything is encrypted before it leaves your computer. Even the Cryptocat network itself can't read your messages. You're seriously misleading users regarding the security of crypto -- the web is an environment that has ZERO controls on code updates. Given this remarkably self-serving and ill-conceived stance, it's difficult to imagine how your…
edit for sub-comment: A traditional web app updates every time you hit the URL. In a browser extension your code is not necessarily tied to any remote origin, including the Chrome/Firefox stores. It is a user's choice to automatically receive updates from the vendor and this is the same choice that you make if you use apt-get vs manual download/checksum/sig check/audit.