Live data from Hacker News

The Coder Who Encrypted Your Texts

wsj.com

121–130 of 191 posts

Re: The Coder Who Encrypted Your Texts

#121

So it looks like I might have understood something wrong regarding TextSecure. Installed it, used it, uninstalled it. Years later, a contact asks me that he "saw me in TextSecure", sent me a message. Obviously, I didn't get that message. Why - o why - was/is TextSecure pretending to not know about metadata when it does? Why could that happen? Moxie?

This problem is not specific to TextSecure, it also exist with iMessage and whatsapp as far as I know.

You can unregister here: https://whispersystems.org/textsecure/unregister

Re: The Coder Who Encrypted Your Texts

#122
post #95

Earlier quoted context omitted.

Only if you have google services installed.

Without which TextSecure does not work.

But what about the fork https://github.com/SMSSecure/SMSSecure which can be installed on via f-droid google-less phone?

Re: The Coder Who Encrypted Your Texts

#123
post #81

Earlier quoted context omitted.

You cant see into the encrypted traffic to see if it's implemented or not.

But in the worst case you'll be able to see that it is plaintext.

I would expect any messaging app these days woud never send pafkets with plain text.

Re: The Coder Who Encrypted Your Texts

#124
post #5

I get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.

Thank you for http://www.youtube.com/watch?v=unZZCykRa5w . Your notion of 'bundling' was one of my top three most mulled ideas in the past five years. Once I started looking, I see it everywhere.

Upon considering that this talk was delivered pre-Snowden, the value and prescience of this talk is even more significant.

This article is now on the front page of WSJ.com!

Re: The Coder Who Encrypted Your Texts

#125
post #5

I get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.

While having Signal is great, one thing I don't like is the use of phone numbers as identifiers. Why can't we have the option of using a random string?

secure transmission of texts is the goal, not providing anonymity of sender and receiver.

Re: The Coder Who Encrypted Your Texts

#126
post #95

Earlier quoted context omitted.

Without which TextSecure does not work.

But what about the fork https://github.com/SMSSecure/SMSSecure which can be installed on via f-droid google-less phone?

The fork only handles SMS/MMS. There are no IM features in it.

Re: The Coder Who Encrypted Your Texts

#127
post #5

I get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.

I would take this opportunity to say a big thank you to the whole team, textsecure is my default messaging software and it's really well done. Thanks to all of you ! :)

Re: The Coder Who Encrypted Your Texts

#128
post #45
post #20

Earlier quoted context omitted.

Given that we have the man himself onboard - can I urge you to ask the WSJ to remove the comment at the start of the article about WhatsApp implementing your encryption schema? Unless I've missed something, there's absolutely no way for an end-user to determine if their messages are being encrypted (with whatsapp). Or how they're being encrypted for that matter. I feel like WhatsApp latched onto your groundwork (pote…

"Absolutely no way"? I'm sorry to be impolite about it, but that's a bit of an exaggeration: one could jailbreak their phone, pull the binary into their computer, decompile it, and inspect it for implementation structures that would be coherent with how the two or three most popular encryption algorithms are commonly implemented. The expertise to be able to accomplish it doesn't come cheap, but it's certainly in the…

At the very least I would want Whatsapp to:

1) add authentication with other users

2) make a public statement about it (believe it or not, that hasn't happened yet. Perhaps it will come when the iOS versions supports it - or perhaps it never will)

3) commit to the new encryption system in their privacy policy (make it at least somewhat legally binding - which could also be used against abusive law enforcement orders)

Re: The Coder Who Encrypted Your Texts

#129
post #113

I still can't get over Moxie wanting Google and Apple and Microsoft to be gatekeepers of what you can and can't do with your device and calling sideloading "that old broken desktop security model". I admire your work Moxie, but sadly we stand on different sides of war on general purpose computing. I can't help but be saddened that "the other side" got someone so talented and dedicated.

There is no war on general purpose computing. Who even came up with the idea?
Post reply on HN