Live data from Hacker News

The Coder Who Encrypted Your Texts

wsj.com

81–90 of 191 posts

Re: The Coder Who Encrypted Your Texts

#81
post #20

Earlier quoted context omitted.

Given that we have the man himself onboard - can I urge you to ask the WSJ to remove the comment at the start of the article about WhatsApp implementing your encryption schema? Unless I've missed something, there's absolutely no way for an end-user to determine if their messages are being encrypted (with whatsapp). Or how they're being encrypted for that matter. I feel like WhatsApp latched onto your groundwork (pote…

> there's absolutely no way for an end-user to determine if their messages are being encrypted (with whatsapp) Watch the network traffic with Wireshark?

You cant see into the encrypted traffic to see if it's implemented or not.

Re: The Coder Who Encrypted Your Texts

#82

Earlier quoted context omitted.

So you've probably just broken the law by doing so. And you have to do this everytime the app gets updates. And you have to be sure that the encryption is actually getting used on every message. And that the key is strong and not known to Whatsapp. And also that the recipients copy of the app is behaving the same as yours. So I guess the question is, if you had something to hide would you bet your life on it? Whereas…

>So you've probably just broken the law by doing so. By modifying your own device? I don't think so.

Many countries have laws against reverse engineering programs. Whilst I think these laws are stupid I would prefer to just use the open source program than mess around with the closed source alternative.

Re: The Coder Who Encrypted Your Texts

#83

Interesting article and interesting guy. I like the work he and his team does on these apps. Unfortunately, they typically run on the type of endpoints that everyone from script kiddies with money to High Strength Attackers can hit. Usually alongside apps not as strong as theirs on TCB's that can at best be described as insecure foundations. I recommend against such apps and platforms for anything other than stopping…

We don't have time to wait for widespread TCB, even if we could when the NSA is actively trying to undermine all methods for it.

Re: The Coder Who Encrypted Your Texts

#84
So it looks like I might have understood something wrong regarding TextSecure.

Installed it, used it, uninstalled it.

Years later, a contact asks me that he "saw me in TextSecure", sent me a message.

Obviously, I didn't get that message.

Why - o why - was/is TextSecure pretending to not know about metadata when it does? Why could that happen? Moxie?

Re: The Coder Who Encrypted Your Texts

#85
Moxie and Frederic and Christine and the rest definitely deserve a lot of credit.

Half of me is really happy every time I see Signal getting more popular. The other half is more like OH GOD THE STAKES ARE HIGHER NOW WHAT IF I MADE AN EXPLOITABLE MISTAKE BETTER RE-READ SOME CODE.

But seriously, you should read the code. It's there, open for anyone to audit after all. Maybe start somewhere random in the guts [1][2][3] and check for things like "ereh 2# roodkcab"?

1: https://github.com/WhisperSystems/Signal-iOS/blob/master/Sig...

2: https://github.com/WhisperSystems/Signal-iOS/blob/master/Sig...

3: https://github.com/WhisperSystems/Signal-iOS/blob/master/Sig...

Re: The Coder Who Encrypted Your Texts

#86

Earlier quoted context omitted.

>So you've probably just broken the law by doing so. By modifying your own device? I don't think so.

Many countries have laws against reverse engineering programs. Whilst I think these laws are stupid I would prefer to just use the open source program than mess around with the closed source alternative.

According to Wikipedia[0], reverse engineering is generally legal in the US:

In the United States even if an artifact or process is protected by trade secrets, reverse-engineering the artifact or process is often lawful as long as it has been legitimately obtained.

[0] https://en.wikipedia.org/wiki/Reverse_engineering#United_Sta...

Re: The Coder Who Encrypted Your Texts

#87
post #13

Not that I really want to steal any of Moxie's thunder, but if you're reading this comment thread you might also be interested in SC4: https://github.com/Spark-Innovations/SC4 Strong encryption that runs in a browser. Recently completed its first security audit.

> Not that I really want to steal any of Moxie's thunder,

Not being rude (yep), but you did.

Cool project though.

Re: The Coder Who Encrypted Your Texts

#88

>Unfortunately, if Mr. Marlinspike’s encryption scheme can be applied to imagery, then childporn collectors thank him too. And there we go, highest voted comment on the article: a strawman about child pornography. Think of the keeeds

What infuriates me the most is that is such a blind, selfish, first world argument. It assumes freedom of speech is granted, ubiquitous, and irreversible, so those who want extra protection must be criminals.

In some countries you can be killed for your political views. You can also be killed for what you are -- gay, for example.

Anyway, in most cases the person who said that is a complete hypocrite, like a politician/businessman who wants to ban encryption to be able to spy on their competitors, not to "protect children".

That's even a higher level of blindness. Those people understand how the world works. They know that hackings, theft, revolutions, and coups d'etat exist, and those who once were righteous, legal and legitimate may be prosecuted.

What if there were a revolution and the new government decided that now being a sports fan were illegal? That new government may have access to apparently innocent communications where people discussed sports events. Communications that were legally intercepted and innocent in one scenario may be life-threatening if laws change.

That's why we need encryption, that's why all person-to-person communications must be private (we can discuss the transparency degree for governments communications), and that's why governments must find some other way of fighting crime than just exposing everybody naked to make it easier to pick the bad apples.

Sorry for the rant, but encryption is saving lives of gays, illegitimately prosecuted politicians and such. Banning it with lame excuses is short-sighted and may backfire some day.

Re: The Coder Who Encrypted Your Texts

#89
Address book based social networks are nice to get a bit of bootstrapping, but becomes pretty bad when you want to add someone as a text secure contact, or you want to run a version without using SMS gateways. It gets pretty complicated pretty fast compared to 'what is your username'.

I hope text secure gets usernames one day that you can associate with phone numbers & emails.

The web-browser version is a good development, it shows that desktop and multi-device versions are on the way.

Re: The Coder Who Encrypted Your Texts

#90

>Unfortunately, if Mr. Marlinspike’s encryption scheme can be applied to imagery, then childporn collectors thank him too. And there we go, highest voted comment on the article: a strawman about child pornography. Think of the keeeds

> Science tells us of bad effects that certain kinds of discharges can have on our children, born and unborn, but we don't seem to see the analogy between a perverted individual sexually molesting a child and an industrial discharge affecting the basic sexuality of a child.

The Making of a Conservative Environmentalist, by Gordon K. Durnil, at p. 43

http://www.iupress.indiana.edu/product_info.php?products_id=...

Post reply on HN