Live data from Hacker News

CryptoCat iOS Application Penetration Test [pdf]

isecpartners.github.io

31–40 of 137 posts

Re: CryptoCat iOS Application Penetration Test [pdf]

#31

Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…

Hi, read the blog post. According to both the blog post and ISEC, you had a pathetically easy man-in-the-middle attack against all of your code, including deployed code in real world use, not just the "buggy" IOS client. Care to explain how that can be taken "out of context?" Even if the rest of the audit was a complete lie, that would still be "brutal."

From the ISEC REPORT:

"CryptoCat's OTR implementation on all platforms allows a chat peer to change their OTR key during a chat session without user notification. An attacker performing a man-in-the-middle attack against the client's XMPP or HTTPS stream can inject their own OTR key in the discussion after a user has authenticated their peer's OTR fingerprint. This permits the attacker to decrypt all messages that follow, and no user would have reason to suspect the compromise. Group multi-party discussions do not seem to suffer from the same vulnerability." (emphasis mine)

Your response in the blog:

"... This is a problem that can be exploited in some real-world scenarios and needs to be addressed with appropriate authentication warnings. Thanks to these audits, this issue was caught in Cryptocat for iPhone before it was released. Therefore, unlike the desktop version, Cryptocat for iPhone was never affected by this issue."

Re: CryptoCat iOS Application Penetration Test [pdf]

#32

Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…

Rest assured of my utmost respect and support, Nadim.

Re: CryptoCat iOS Application Penetration Test [pdf]

#33
Huh, this was apparently submitted by Alex Stamos, a co-founder of iSec partners (who did this audit). And he editorialized the title, "Brutal Professional Audit of CryptoCat Published."

Your former company did an audit for a customer, then you posted it to HN calling it "Brutal"? Really?

Re: CryptoCat iOS Application Penetration Test [pdf]

#34

Earlier quoted context omitted.

I wasn't going to post this, but I had the same feeling at a conference. Also, if I remember correctly, the first version that got audited turned out to be extremely insecure as well, with their own custom crypto protocols? I haven't recommended CryptoCat to anyone since, and still wouldn't. This audit report is another fascinating read to see all the mistakes I would probably have made as well. Secure crypto is so i…

It's important to note that this audit concerned a pre-release, debugging version of Cryptocat for iPhone. The audit document alone doesn't give enough context; I strongly urge reading our blog post: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp...

Are you saying that it's good news because it means that no actual users were exposed to the flaws? To the extent that those flaws apply only to the iOS version, I agree: that's good news.

Are you saying that it's good news because they tested something that you weren't ever going to release in that state? That's a tougher row to hoe, unless you're going to claim that your team inevitably would have found the same set of vulnerabilities that Scott, David, Alban, and Zooko's team found.

For a typical application --- yours isn't typical for any number of reasons --- prerelease or not, the state the application is in when a pentest team gets it is, from the perspective of security, the application customers would have received.

Re: CryptoCat iOS Application Penetration Test [pdf]

#35

There is a "many ways to skin a cat" joke here somewhere. It is actually terrible - the hmac timing attack requires around 3 minutes of google searching to avoid and is basic public domain knowledge. The other are much worse.

I wish I knew how to find my way into security as a hobby. Such a fun topic.

Why find your way in as a hobby? Are you a professional developer now? Do you like low-level code? Are you OK with jumping directly into the deep end of the pool and maybe drowning a little bit? Why not reach out and talk to us about working on a professional security team?

We have gotten very, very good at taking low-level devs and turning them into terrifying killing machines, and if you don't mind having all your flesh removed and your skeletal musculature replaced by pistons and servomotors, we'd be happy to do the same to you.

http://matasano.com/careers

Re: CryptoCat iOS Application Penetration Test [pdf]

#36
post #35

Earlier quoted context omitted.

I wish I knew how to find my way into security as a hobby. Such a fun topic.

Why find your way in as a hobby? Are you a professional developer now? Do you like low-level code? Are you OK with jumping directly into the deep end of the pool and maybe drowning a little bit? Why not reach out and talk to us about working on a professional security team? We have gotten very, very good at taking low-level devs and turning them into terrifying killing machines, and if you don't mind having all your…

Coding is a purely ancillary function to my day job; I am not a developer.

Re: CryptoCat iOS Application Penetration Test [pdf]

#37
post #35

Earlier quoted context omitted.

Why find your way in as a hobby? Are you a professional developer now? Do you like low-level code? Are you OK with jumping directly into the deep end of the pool and maybe drowning a little bit? Why not reach out and talk to us about working on a professional security team? We have gotten very, very good at taking low-level devs and turning them into terrifying killing machines, and if you don't mind having all your…

Coding is a purely ancillary function to my day job; I am not a developer.

"I hate coding" would be a problem for us, but "I ship software every day", not so much.

Re: CryptoCat iOS Application Penetration Test [pdf]

#39
post #26

Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…

Was it commissioned by you? The audit I saw had the Open Technology Fund's logo on it. OTF is a US Government effort driven by Radio Free Asia and the Broadcast Board of Governors. OTF, again (smartly) using US taxpayer dollars, funds audits of a variety of privacy technologies. For instance, they also funded a good-sized chunk of the Truecrypt audit.

I can't tell if you actually don't know who commissioned it or if this is your way of suggesting that the parent comment is a lie. It seems like information you would have access to, considering your connection with iSEC, no? (I'm not trying to stir up shit, just genuinely curious.)

Re: CryptoCat iOS Application Penetration Test [pdf]

#40

Earlier quoted context omitted.

You're doing crypto in the browser , while claiming on your home page: > Everything is encrypted before it leaves your computer. Even the Cryptocat network itself can't read your messages. You're seriously misleading users regarding the security of crypto -- the web is an environment that has ZERO controls on code updates. Given this remarkably self-serving and ill-conceived stance, it's difficult to imagine how your…

I don't think CryptoCat has been distributed as a traditional web app for at least a year (probably more). The browser code is distributed as an extension, which does not have the properties you describe. edit for sub-comment: A traditional web app updates every time you hit the URL. In a browser extension your code is not necessarily tied to any remote origin, including the Chrome/Firefox stores. It is a user's choi…

> The browser code is distributed as an extension, which does not have the properties you describe.

Actually, browser extensions have the exact same properties except for being code signed. That's not enough: http://arstechnica.com/security/2014/01/malware-vendors-buy-...

> I don't think CryptoCat has been distributed as a traditional web app for at least a year (probably more).

That they ever shipped in-browser crypto demonstrates that they shouldn't be shipping crypto.

Post reply on HN