Live data from Hacker News

The Coder Who Encrypted Your Texts

wsj.com

51–60 of 191 posts

Re: The Coder Who Encrypted Your Texts

#51
post #5

I get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.

Thank you for http://www.youtube.com/watch?v=unZZCykRa5w. Your notion of 'bundling' was one of my top three most mulled ideas in the past five years. Once I started looking, I see it everywhere.

Re: The Coder Who Encrypted Your Texts

#52
post #37
post #13

Not that I really want to steal any of Moxie's thunder, but if you're reading this comment thread you might also be interested in SC4: https://github.com/Spark-Innovations/SC4 Strong encryption that runs in a browser. Recently completed its first security audit.

I've been looking for something to replace PGP-JS for a while. Cheers.

Any feedback you have on SC4 would be much appreciated.

Re: The Coder Who Encrypted Your Texts

#53
post #5

I get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.

True hacker.

Re: The Coder Who Encrypted Your Texts

#54
post #5

I get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.

I just want to take a moment and say "thank you" to youself and the entire team at Open Whisper. I appreciate your efforts.

Sadly, the march to "Safety Fascism" continues unabated.

Re: The Coder Who Encrypted Your Texts

#56

>Unfortunately, if Mr. Marlinspike’s encryption scheme can be applied to imagery, then childporn collectors thank him too. And there we go, highest voted comment on the article: a strawman about child pornography. Think of the keeeds

"Think of the childern" is a common refrain of the coward who values safety over freedom.

Re: The Coder Who Encrypted Your Texts

#57
post #18

There is not any evidence of encryption on WhatsApp, source code is closed so you can never be safe.

People have sniffed the wire for the WhatApp client (on Android, towards another Android) and seen that it is encrypted. But your point stands - there's no UI to indicate if it was secure or not and the code isn't open so you can't know for sure.

I'm ignorant. How can you prove that it's encrypted in any meaningful fashion vs, say rot13?

Re: The Coder Who Encrypted Your Texts

#59
post #50
post #20

Earlier quoted context omitted.

Given that we have the man himself onboard - can I urge you to ask the WSJ to remove the comment at the start of the article about WhatsApp implementing your encryption schema? Unless I've missed something, there's absolutely no way for an end-user to determine if their messages are being encrypted (with whatsapp). Or how they're being encrypted for that matter. I feel like WhatsApp latched onto your groundwork (pote…

even if an Android application would communicate with others 100% securely, Google has wireless administrator privileges and can be served secret letters that can order Google to do anything, so technically they could log the data before it's encrypted.

Only if you have google services installed.

Re: The Coder Who Encrypted Your Texts

#60
post #45
post #20

Earlier quoted context omitted.

Given that we have the man himself onboard - can I urge you to ask the WSJ to remove the comment at the start of the article about WhatsApp implementing your encryption schema? Unless I've missed something, there's absolutely no way for an end-user to determine if their messages are being encrypted (with whatsapp). Or how they're being encrypted for that matter. I feel like WhatsApp latched onto your groundwork (pote…

"Absolutely no way"? I'm sorry to be impolite about it, but that's a bit of an exaggeration: one could jailbreak their phone, pull the binary into their computer, decompile it, and inspect it for implementation structures that would be coherent with how the two or three most popular encryption algorithms are commonly implemented. The expertise to be able to accomplish it doesn't come cheap, but it's certainly in the…

So you've probably just broken the law by doing so. And you have to do this everytime the app gets updates. And you have to be sure that the encryption is actually getting used on every message. And that the key is strong and not known to Whatsapp. And also that the recipients copy of the app is behaving the same as yours. So I guess the question is, if you had something to hide would you bet your life on it?

Whereas with Textsecure. Well it just works...

Post reply on HN