Live data from Hacker News

MEGAChat now includes end-to-end encryption

mega.nz

11–20 of 98 posts

Re: MEGAChat now includes end-to-end encryption

#11
post #4

It sounds reasonable? If anything this highlights the problem with all the new encrypted communications options, even highly technical people can't really know how good it is from a cursory look. Just because it says end to end encryption and uses some nice ciphers it doesn't mean the implementation is not critically flawed. I use Signal right now (from Moxie Marlinspike/Whisper Systems) and would only really conside…

Is there any information on the guaranties Moxie Marlinspike/Whisper Systems provide on the Apps downloaded from the App-Store? I get that their source is open and reviewed and trusted but what is this worth when there is no way to tell if users are actually using their version/builds when installed from App-Stores. Same holds true for the necessary servers they maintain.

Don't get this wrong please: this is still probably THE best solution right now, which simply as well has its security limitations, right?

Is there any work ongoing on a kind of "verification process" for Apps like these? How can an end-user tell if the binaries running on their device are untempered with?

/sorry for hijacking ;)

Re: MEGAChat now includes end-to-end encryption

#13
post #4

It sounds reasonable? If anything this highlights the problem with all the new encrypted communications options, even highly technical people can't really know how good it is from a cursory look. Just because it says end to end encryption and uses some nice ciphers it doesn't mean the implementation is not critically flawed. I use Signal right now (from Moxie Marlinspike/Whisper Systems) and would only really conside…

While you can't know without looking at the code, my first-pass test is asking how keys are handled and if the code handling those keys is coming from an untrusted source (in this case the server as JS)(for the sake of this discussion I will admit I implicitly trust Debian and the gpg folks). If there isn't a good answer to key management, or my key is handled by JS, then it's a no-go for me. If there is a half-way d…

Probably the best key handling method is employed by Biocoded app. It uses the same encryption protocol as signal (Axolotl ratchet) and it only stores half of the decryption key locally. The other half is on the server.

Re: MEGAChat now includes end-to-end encryption

#14
post #4

It sounds reasonable? If anything this highlights the problem with all the new encrypted communications options, even highly technical people can't really know how good it is from a cursory look. Just because it says end to end encryption and uses some nice ciphers it doesn't mean the implementation is not critically flawed. I use Signal right now (from Moxie Marlinspike/Whisper Systems) and would only really conside…

Is there any information on the guaranties Moxie Marlinspike/Whisper Systems provide on the Apps downloaded from the App-Store? I get that their source is open and reviewed and trusted but what is this worth when there is no way to tell if users are actually using their version/builds when installed from App-Stores. Same holds true for the necessary servers they maintain. Don't get this wrong please: this is still pr…

The solution is called reproducible builds. I'm aware f-droid is working on these, but most of the work is currently happening more in the Linux distribution space (Debian is leading that cause). I hope in the future we will be able to say "if it doesn't have a reproducible build process it's not to be considered trustworthy".

(Also: I think this question is mostly independent from the disagreements between moxie and f-droid - they were regarding other issues.)

Re: MEGAChat now includes end-to-end encryption

#15
post #12
post #3

Didn't Kim Dotcom say you can't trust Mega anymore? http://www.wired.co.uk/news/archive/2015-07/31/kim-dotcom-me...

If Kim Dotcom says you can't trust something does that mean you can? https://de.wikipedia.org/wiki/Kim_Dotcom#Werdegang

Nice! For those that don't know, Kim Schmitz / Kimble(now Dotcom), sold out his fellow warez peers to the copyright lawyer Günter Freiherr von Gravenreuth. Like the wild West he was supposedly paid per head.

http://www.forbes.com/sites/andygreenberg/2013/04/17/where-k...

Not mentioned in the article is his involvement in the AT&T calling card fraud conspiracy (estimated losses $20 million) in the early '90's. It is that case that put him on the US Secret Service's radar and he's been on it ever since.

Re: MEGAChat now includes end-to-end encryption

#16
post #8
post #4

It sounds reasonable? If anything this highlights the problem with all the new encrypted communications options, even highly technical people can't really know how good it is from a cursory look. Just because it says end to end encryption and uses some nice ciphers it doesn't mean the implementation is not critically flawed. I use Signal right now (from Moxie Marlinspike/Whisper Systems) and would only really conside…

It is great that Whisper Systems/Signal implement cryptography properly. However, the NEWER versions of Signal requires access to your contact to work. For many users that is a show stopper. Implement a way for user to search by User ID and allow user to find each other by ID in addition to phone number.

Not on iOS. It's not Signal's fault that Android permissions are a mess. Google has no interest in providing good privacy to their customers. They only want to appear to provide privacy. In reality, they want to know everything there is to know about everything and everyone. To improve their service, of course...

Re: MEGAChat now includes end-to-end encryption

#17
post #8
post #4

It sounds reasonable? If anything this highlights the problem with all the new encrypted communications options, even highly technical people can't really know how good it is from a cursory look. Just because it says end to end encryption and uses some nice ciphers it doesn't mean the implementation is not critically flawed. I use Signal right now (from Moxie Marlinspike/Whisper Systems) and would only really conside…

It is great that Whisper Systems/Signal implement cryptography properly. However, the NEWER versions of Signal requires access to your contact to work. For many users that is a show stopper. Implement a way for user to search by User ID and allow user to find each other by ID in addition to phone number.

The requirement of a phone number is strange and disconcerting from a privacy standpoint. It is a red flag for me.

A well-designed encrypted chat-protocol should work on any modern networked computing device, not just smartphones or computing devices linked to a smartphone.

Re: MEGAChat now includes end-to-end encryption

#19
It's great that there is such a strong interest in secure communication, but all of the solutions that keep getting placed in the limelight in recent years are either centralised or exclusively available for use with a smartphone (because of the phone number requirement), often both!

I'm sure that these solutions are a lot more secure than completely unprotected alternatives, but am I wrong in assuming that if you want secure and private communications, the following principles must be met at the least?

* The protocol used must be open, standardized and implementable by others

* Widely endorsed by cryptography experts

* An implementation must be available and developed as free and open source software

* End-to-end encryption is used for the contents of the conversations, private keys do not leave the user's computing device

* The protocol must not have any technological barriers that prevent an implementation from working on any modern operating system (i.e., a phone number is not required)

* The protocol must allow for a complete communications network (clients and servers) to be implemented without the need for centralised third-party services

(The last point probably implies federation.)

For e-mail, OpenPGP meets these requirements. For chat, XMPP has Off-The-Record messaging.

Some of the above points are hostile towards any party that creates secure communications tools with the intent of growing a large user base for economic purposes. Call me a sceptic, but this is probably why use of these protocols and principals is limited to security experts and software developers who understand these principles — for anyone betting on creating the next WhatsApp in one of the mobile walled gardens embracing the whole list means risking losing your potential advertising eyeballs to alternatives.

Of course, there is also the matter of infrastructure. A lot of people expect to be able to use these tools for free, but that implies that someone is paying for the hosting of (relay) servers.

Re: MEGAChat now includes end-to-end encryption

#20
post #15
post #12

Earlier quoted context omitted.

If Kim Dotcom says you can't trust something does that mean you can? https://de.wikipedia.org/wiki/Kim_Dotcom#Werdegang

Nice! For those that don't know, Kim Schmitz / Kimble(now Dotcom), sold out his fellow warez peers to the copyright lawyer Günter Freiherr von Gravenreuth. Like the wild West he was supposedly paid per head. http://www.forbes.com/sites/andygreenberg/2013/04/17/where-k... Not mentioned in the article is his involvement in the AT&T calling card fraud conspiracy (estimated losses $20 million) in the early '90's. It is t…

not to mention having made most of his cash with insider trading in Germany.
Post reply on HN