Live data from Hacker News

The Coder Who Encrypted Your Texts

wsj.com

91–100 of 191 posts

Re: The Coder Who Encrypted Your Texts

#91
post #57

Earlier quoted context omitted.

People have sniffed the wire for the WhatApp client (on Android, towards another Android) and seen that it is encrypted. But your point stands - there's no UI to indicate if it was secure or not and the code isn't open so you can't know for sure.

I'm ignorant. How can you prove that it's encrypted in any meaningful fashion vs, say rot13?

We can disprove the existence of strong encryption with a wireshark, but cannot prove it.

Entropy of a rot13 message would be much lower than that of a properly encrypted channel. High entropy is not proof of "meaningful encryption", mind you, since a compressed rot13 or plaintext message would have high entropy too.

Re: The Coder Who Encrypted Your Texts

#92
post #5

I get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.

Thank you for http://www.youtube.com/watch?v=unZZCykRa5w . Your notion of 'bundling' was one of my top three most mulled ideas in the past five years. Once I started looking, I see it everywhere.

Thanks, one of the best talks I have seen for awhile

Re: The Coder Who Encrypted Your Texts

#93

Earlier quoted context omitted.

"Think of the childern" is a common refrain of the coward who values safety over freedom.

I wonder how many of the people on that think of the children side were either affected as kids, had children who had some awful experience, or are of close relation to someone who was or had kids who did. Because I could easily see something like an awful event happening to a child really warping a persons world view in a strong way. On the other hand, I wonder how many privacy advocates have never experienced anyth…

I heard several survivors that were appalled of the "Think of the children" approach because it is too often used to push an agenda that doesn't help children at all.

For example, internet blocking of child abuse media (hot topic in Germany a couple of years ago) doesn't help children (who aren't abused 'over the internet' but in real life) because it routes resources away from public education on the matter (such as encouraging victims to speak up), social and health support (so victims that spoke up don't fall into a void) and regular police work (so that the perpetrator gets busted).

I guess child abuse on the internet is a popular topic with policy makers because "protecting children" is an easy way to score points in public and "on the internet" hides the fact that this abuse happens somewhere - and closer to any single person than they may be comfortable with. "internet" became a code word for "somewhere else".

That's a great platform to win an election.

Now, pick any company with > 10000 employees. Just by running the numbers it likely employs a child abuser. You work for such a company? It's likely that one of your coworkers, maybe even somebody you deal with every day, is a child abuser.

That's not a great platform to win an election.

Re: The Coder Who Encrypted Your Texts

#94

Earlier quoted context omitted.

Many countries have laws against reverse engineering programs. Whilst I think these laws are stupid I would prefer to just use the open source program than mess around with the closed source alternative.

According to Wikipedia[0], reverse engineering is generally legal in the US: In the United States even if an artifact or process is protected by trade secrets, reverse-engineering the artifact or process is often lawful as long as it has been legitimately obtained. [0] https://en.wikipedia.org/wiki/Reverse_engineering#United_Sta...

And that is one country out of ~200.

Re: The Coder Who Encrypted Your Texts

#95
post #50

Earlier quoted context omitted.

even if an Android application would communicate with others 100% securely, Google has wireless administrator privileges and can be served secret letters that can order Google to do anything, so technically they could log the data before it's encrypted.

Only if you have google services installed.

Without which TextSecure does not work.

Re: The Coder Who Encrypted Your Texts

#96
post #18

There is not any evidence of encryption on WhatsApp, source code is closed so you can never be safe.

People have sniffed the wire for the WhatApp client (on Android, towards another Android) and seen that it is encrypted. But your point stands - there's no UI to indicate if it was secure or not and the code isn't open so you can't know for sure.

Encryption on the transport != end-to-end encryption if you consider the users as the ends. The encryption might very well just be from your device to WhatsApp.

Re: The Coder Who Encrypted Your Texts

#97
post #43
post #14

Earlier quoted context omitted.

For a sandboxed baseband check out the Neo900 project.

It seems interesting. But they want an address just to create an account. At least they don't demand a mobile number ;) And the only payment options are bank wire and PayPal. I don't see that they accept Bitcoin. Also, I see no option for anonymous fulfillment.

Response from IRC:

http://irclog.whitequark.org/neo900/2015-07-10

Re: The Coder Who Encrypted Your Texts

#98
I was a great fan of TextSecure until a few days ago. I had encouraged a bunch of friends to install it. One of them couldn't get rid of a notification from TextSecure about an unread message despite there being none, and eventually they uninstalled it. Then, for the next 4 months TextSecure blackholed every message I sent this friend without warning either them or me. They never received a single message from me. After discovering that I uninstalled it.

Re: The Coder Who Encrypted Your Texts

#99
post #43
post #14

Earlier quoted context omitted.

For a sandboxed baseband check out the Neo900 project.

It seems interesting. But they want an address just to create an account. At least they don't demand a mobile number ;) And the only payment options are bank wire and PayPal. I don't see that they accept Bitcoin. Also, I see no option for anonymous fulfillment.

[deleted]

Re: The Coder Who Encrypted Your Texts

#100
post #43

Earlier quoted context omitted.

It seems interesting. But they want an address just to create an account. At least they don't demand a mobile number ;) And the only payment options are bank wire and PayPal. I don't see that they accept Bitcoin. Also, I see no option for anonymous fulfillment.

Response from IRC: http://irclog.whitequark.org/neo900/2015-07-10

Thanks, programmernews3 :)

DocScrutinizer05 says on IRC that neo900 will accept cash by mail and Bitcoin. And "anonymous fulfillment" (on-site pickup, I presume) for wholesale (N>50) orders. Cool. Someone could sell them for cash at conferences, etc.

Post reply on HN