The good thing about CryptoCat is that everyone wants to trash it, so it's becoming better.
Kudos to Nadim and OTF for releasing the info and starting these discussions, as inevitably arduous as they are.
131–137 of 137 posts
The good thing about CryptoCat is that everyone wants to trash it, so it's becoming better.
Kudos to Nadim and OTF for releasing the info and starting these discussions, as inevitably arduous as they are.
Huh, this was apparently submitted by Alex Stamos, a co-founder of iSec partners (who did this audit). And he editorialized the title, "Brutal Professional Audit of CryptoCat Published." Your former company did an audit for a customer, then you posted it to HN calling it "Brutal"? Really?
I also do wish that the original post had pointed at CryptoCat's blog post - aside from CryptoCat's context about problems and resolutions, people should also be aware of the separate report by Zooko's team.
Earlier quoted context omitted.
I read the blog post reacting to this batch of audit results quite carefully, in point of fact. In general, when I read vendor responses to such devastating findings, I'm looking for a concrete plan to improve the threat modeling and development practices deficiencies which are inevitably the root cause of the class of issues uncovered by the iSec and Least Authority audits. Without such changes, saying that you're g…
I disagree; I don't think your summary is accurate. This is an audit of a pre-release prototype. All the bugs were fixed before release, and our blog post at https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... does not discuss mere band-aids. It discusses, at length, real solutions to complex problems that many encryption apps face. It resolves pitfalls that even companies like Apple commit on a much wide…
I appreciate your willingness to continue this discussion, dropped you an email.
Earlier quoted context omitted.
Actually I strongly suggest reading these in conjunction with iSec's issues 12 through 16, because each team spotted some details that the other missed.
Are you sure that's not because the different teams had different scopes? The iSEC audit was specifically tied to the iOS application.
Earlier quoted context omitted.
I don't believe they've had an independent security audit. I think their team however is comprised of more respected cryptographers like Moxie Marlinspike, who introduced the concept of SSL stripping, one of the issues that was found in the CryptoCat app. I mean no disrespect to CryptoCat, and more eyes can always find something someone overlooked, but I think the Open Whisper Systems (TextSecure) team is stronger an…
TextSecure also has design contributions from Trevor Perrin, who is also amazing.
mandalar12 asks about "the same level of analysis on TextSecure". Since our (Least Authority's) audit and the iSEC audit are public, random people on the internet can know what that level is, without having to know or rely on Least Authority or iSEC to be non-malicious.
With enough eyes all bugs are shallow, but to whom? We need to communicate transparently to achieve this ideal.
Disclaimers: I worked on the Least Authority audit of Cryptocat; I've worked at iSEC in the past; I've met Moxie Marlinspike and Trevor Perrin and greatly respect their expertise and motivations; I also don't know if they've been infected by malicious puppetmaster aliens since I last saw them.
Earlier quoted context omitted.
TextSecure also has design contributions from Trevor Perrin, who is also amazing.
natdempk and tptacek have both asserted that TextSecure is trustworthy and solid by dint of being implemented and designed by reliable experts. This pretty much boils down to argument by authority. mandalar12 asks about "the same level of analysis on TextSecure". Since our (Least Authority's) audit and the iSEC audit are public, random people on the internet can know what that level is , without having to know or rel…
My own opinion is that both strong cryptographic and security engineering expertise on the part of designers and implementors, and multiple independent published security audits, are necessary to consider an app trustworthy -- but still not sufficient, given the poor state of platform security and the lack of support most current platforms (operating systems, browsers, etc.) give for isolation between apps.
Disclaimer: I worked on the Least Authority audit of Cryptocat, and in general get paid for similar auditing. I'm also designing a programming language (Noether) that is intended to facilitate security reviews.
Earlier quoted context omitted.
Go read http://tobtu.com/decryptocat.php and earlier sources before deciding he's being extremist.
I have, and I still believe he's being extremist. No one is in this space unscathed. For no other product have I seen the same level of vitriol and hate being spit at Cryptocat, despite it being absolutely not the only entrant.
That's both not true, and misleading; even comparing it to applications that have had serious published flaws, this one has vulnerabilities of a number and magnitude that distinguish it.