Live data from Hacker News

ISIS Has a Smartphone App

fortune.com

11–20 of 80 posts

Re: ISIS Has a Smartphone App

#11
post #4

> Apple and Google could easily kick apps used to organize violence out of their official app stores. But would they be willing to build further barriers to usage directly into their mobile operating systems? This is a silly question for the Android side (and possibly the iOS side as well). That would be a monumental effort that would seem easily thwarted by simply installing your own version of the OS.

> Apple and Google could easily kick apps used to organize violence out of their official app stores. But would they be willing to build further barriers to usage directly into their mobile operating systems?

Similarly car manufacturers should stop making models that are used as getaway vehicles for bank robberies...

It sounds silly now I put this like that doesn't it.

Re: ISIS Has a Smartphone App

#13
post #5

Which I am sure the intelligence agencies are having a field day with. Nothing like rolling your own encryption. What are the chances it was created by one of the intelligence agencies?

> What are the chances it was created by one of the intelligence agencies?

I came to the comment section to say that exact same thing. If I were one of those intelligence agencies it would be tempting to use the information right away but for it to be truly effective, you'd need to let it propagate pretty far. What a field day for intelligence agencies even if wasn't planned by them -- just one thing to bust and they have everything.

Is this story even serious?

Using modern smart phones for "business" at all doesn't seem like a good idea if you are in the cross hairs of a modern military force.

Re: ISIS Has a Smartphone App

#14
post #2

[deleted]

Is it productive for anyone here to track down the apk and look at it (and disclose findings)? This seems like an instance where the infosec community shouldn't shine a light on bad crypto. Let ISIS use (potentially) bad crypto if they want. Leave it to government(s) to identify and exploit weaknesses.

Re: ISIS Has a Smartphone App

#15
Surely it can't be that hard to create a chat app with end to end encryption these days with all the open source libraries freely available for all kinds of applications...this is why I've always said banning encryption on major platforms like iOS/Android/Windows will get you nowhere when terrorists can just make their own encrypted chat apps if they really want to.

Re: ISIS Has a Smartphone App

#16
post #4

> Apple and Google could easily kick apps used to organize violence out of their official app stores. But would they be willing to build further barriers to usage directly into their mobile operating systems? This is a silly question for the Android side (and possibly the iOS side as well). That would be a monumental effort that would seem easily thwarted by simply installing your own version of the OS.

You wouldn't even need to install your own OS. You can just side-load

they are talking about restricting the OS from running third party or side loaded apps

Re: ISIS Has a Smartphone App

#17
post #2

[deleted]

Is it productive for anyone here to track down the apk and look at it (and disclose findings)? This seems like an instance where the infosec community shouldn't shine a light on bad crypto. Let ISIS use (potentially) bad crypto if they want. Leave it to government(s) to identify and exploit weaknesses.

That is a good point...

Re: ISIS Has a Smartphone App

#18

Alrawi can’t be downloaded from Google Play. Instead it must be installed from shady back alleys of the Internet. Well, there's your obvious solution. Get a copy of the APK, wrap it with some spyware, then propagate the bugged version. If ISIS won't host the source or can't provide an "official" outlet to grab it, you've got no way of knowing whether your version is legit or not. Who'd have thought the paradigms of s…

I'd doubt users of an encryption app not using a simple checksum to verify its legitimacy before using it.

Re: ISIS Has a Smartphone App

#19

Alrawi can’t be downloaded from Google Play. Instead it must be installed from shady back alleys of the Internet. Well, there's your obvious solution. Get a copy of the APK, wrap it with some spyware, then propagate the bugged version. If ISIS won't host the source or can't provide an "official" outlet to grab it, you've got no way of knowing whether your version is legit or not. Who'd have thought the paradigms of s…

But that's government surveillance, and HN comments are supposed to say that it's always bad and much worse than ISIS, right?

Re: ISIS Has a Smartphone App

#20

Earlier quoted context omitted.

Is it productive for anyone here to track down the apk and look at it (and disclose findings)? This seems like an instance where the infosec community shouldn't shine a light on bad crypto. Let ISIS use (potentially) bad crypto if they want. Leave it to government(s) to identify and exploit weaknesses.

That is a good point...

...so I deleted the top comment.
Post reply on HN