Live data from Hacker News

Free, Worldwide, Encrypted Phone Calls for iPhone

whispersystems.org

151–160 of 211 posts

Re: Free, Worldwide, Encrypted Phone Calls for iPhone

#151

Please authenticate with something that's not a phone number! I guess that's the simplest for most people (look at WhatsApp), but the reason why I use things like Signal is because I despise cell carriers. I'd like to use this on a (cheaper) non-cellular device (for myself and family members). The Holy Grail of Secure Communications: Group Encrypted Text, Voice, and Video. Right now, Skype gives you the unholy grail,…

To my knowledge, Jitsi fulfills your Holy Grail of Secure Communications requirements. It certainly much more trustworthy than Skype.

Needs to be quality on mobile too.

Re: Free, Worldwide, Encrypted Phone Calls for iPhone

#152

Please authenticate with something that's not a phone number! I guess that's the simplest for most people (look at WhatsApp), but the reason why I use things like Signal is because I despise cell carriers. I'd like to use this on a (cheaper) non-cellular device (for myself and family members). The Holy Grail of Secure Communications: Group Encrypted Text, Voice, and Video. Right now, Skype gives you the unholy grail,…

You missed the main holy grail requirement: open source. Nothing closed source can be trusted.

Complete transparency from end to end would require more than just open source. You'd have to be able to build and run the software itself, which on an iPhone costs $99 a year to do and poses significant technical challenges. To go further you'd have to transparency at the hardware level as well. Your own device, built by you, with software you compiled yourself. Maybe then you'd achieve the level of security that you're aiming for, assuming you are competent enough to evaluate the software and hardware you are using.

Re: Free, Worldwide, Encrypted Phone Calls for iPhone

#153

I installed it on my iPhone. I'm able to discover and call friends that have RedPhone, but they can't see me. Is that a feature or a bug :P

Hey. Could you please file a bug report at https://github.com/WhisperSystems/Signal-iOS/issues ? We'll try to work with you to fix the the issue. Thanks!

Re: Free, Worldwide, Encrypted Phone Calls for iPhone

#154

Earlier quoted context omitted.

You missed the main holy grail requirement: open source. Nothing closed source can be trusted.

Complete transparency from end to end would require more than just open source. You'd have to be able to build and run the software itself, which on an iPhone costs $99 a year to do and poses significant technical challenges. To go further you'd have to transparency at the hardware level as well. Your own device, built by you, with software you compiled yourself. Maybe then you'd achieve the level of security that yo…

It wouldn't be for iPhone. For Android it might work but you'd need a hardware platform you trust (one where you are sure no radio baseband processor is going to snoop at your memory any time it wants), use AOSP and then an open source app. Then also if there are any registration or routing services those would have to be open source as well.

Re: Free, Worldwide, Encrypted Phone Calls for iPhone

#155

It would be nice if the server software were open source as well. Call routing information, like all metadata, can only be protected legally not cryptographically. So it's not something I trust to people outside Canada, no matter how much esteem I have for them.

"Call routing information, like all metadata, can only be protected legally not cryptographically."

A counter example of this is seen through ImperialViolet's pond(https://pond.imperialviolet.org/). Using pond, neither metadata nor content are leaked, as both are transmitted over tor every set interval.

Re: Free, Worldwide, Encrypted Phone Calls for iPhone

#156
post #89
post #10

Earlier quoted context omitted.

We're going to need verifiable sources for claims like that.

"We're going to need verifiable sources for claims like that." This entire parent+thread argument back and forth is completely absurd. It doesn't matter whether he has sources. It doesn't matter whether that firm does or does not exist. It doesn't matter what you think of their tech or his explanation or who is who or what is what. Your phone has two[1] completely independent, full-featured computers inside of it, to…

Great point -- that is 101 of any serious security equipment validation. It is not that this software package/app or that card and so on are certified. The whole package from ground up (hardware components down to analog bits, EM emission... up to top level application get certified as secure) has to be.

I can't buy some mathematically proven secure software, install it on a Chinese tablet and claim it is secure and expect it to get approved.

This is a funny market as some domestic analog components are hard to find today. Micron, I think, makes some but heck most are sourced from China.

This makes 'secure' hardware ridiculously expensive. As in $50k+ for switches and routers and there is a whole market specializing in it.

Now, one can look at it another way -- some security is better than no security. I can see the argument on both sides. At least if NSA can record my phone calls maybe the local cops can't and so on...

Re: Free, Worldwide, Encrypted Phone Calls for iPhone

#157
post #156
post #89

Earlier quoted context omitted.

"We're going to need verifiable sources for claims like that." This entire parent+thread argument back and forth is completely absurd. It doesn't matter whether he has sources. It doesn't matter whether that firm does or does not exist. It doesn't matter what you think of their tech or his explanation or who is who or what is what. Your phone has two[1] completely independent, full-featured computers inside of it, to…

Great point -- that is 101 of any serious security equipment validation. It is not that this software package/app or that card and so on are certified. The whole package from ground up (hardware components down to analog bits, EM emission... up to top level application get certified as secure) has to be. I can't buy some mathematically proven secure software, install it on a Chinese tablet and claim it is secure and…

Use separate devices: one with SIM/baseband, one without (wifi only).

Only encrypted traffic goes through the mobile device, e.g. cheap Firefox phone. Decryption takes place on wifi-only "media player" device in the form factor of a phone.

This is still exposed to DMA attacks from wifi device, but it's a smaller attack surface. Next level of protection is a hardware IOMMU on Cortex-A15 or x86 VT-d, plus a Type-1 hypervisor to isolate the wifi device.

Re: Free, Worldwide, Encrypted Phone Calls for iPhone

#158

Please authenticate with something that's not a phone number! I guess that's the simplest for most people (look at WhatsApp), but the reason why I use things like Signal is because I despise cell carriers. I'd like to use this on a (cheaper) non-cellular device (for myself and family members). The Holy Grail of Secure Communications: Group Encrypted Text, Voice, and Video. Right now, Skype gives you the unholy grail,…

Why is it so hard to find cross-platform, encrypted group chat? Surely there's a market for it.

Re: Free, Worldwide, Encrypted Phone Calls for iPhone

#159
post #101
post #77

Earlier quoted context omitted.

Donations is not a business model.

You do realize charitable giving represents hundreds of billions of revenue for non-profits every year ? - and that's excluding religious donations which are likely to represent an even larger amount.

And that is still not a business model.
Post reply on HN