Live data from Hacker News

The Coder Who Encrypted Your Texts

wsj.com

161–170 of 191 posts

Re: The Coder Who Encrypted Your Texts

#161
It's awesome seeing so many privacy and secure messaging apps spring up. The tough part is getting people to use them. I've been using Wickr (I know the black box arguments, but they have a reasonable bounty in place) and it doesn't require number, contact info or addy. The phone call feature of Signal sounds interesting so I'll check it out.

Re: The Coder Who Encrypted Your Texts

#162

Earlier quoted context omitted.

Even if it's open source, we should say that unless the binary can be reproduced exactly by end user, you can never trust what you are using is actually what you think it is.

Is thst possible, in general? If someone published an open source app to Play, could I compare the Play downloaded app to a local build, and set config appropriately, and get a match?

The tor browser bundle and bitcoin use bitcoin's gitian deterministic reproducible build system:

https://github.com/bitcoin/bitcoin/blob/master/doc/gitian-bu...

https://trac.torproject.org/projects/tor/wiki/doc/TorBrowser...

https://blog.torproject.org/blog/deterministic-builds-part-t...

Re: The Coder Who Encrypted Your Texts

#163
post #5

I get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.

And for people who are interested in Open Whisper Systems and want to get involved, we're hiring!

https://whispersystems.org/workworkwork/

Re: The Coder Who Encrypted Your Texts

#164

Interesting quotes: > President Barack Obama called [protected-messaging apps] “a problem.” but > Encrypted messaging was viewed [by the U.S. State Department] as a way for dissidents to get around repressive regimes. With help from Mr. Schuler, Radio Free Asia’s Open Technology Fund, which is funded by the government and has a relationship with the State Department, granted Mr. Marlinspike more than $1.3 million bet…

[deleted]

Re: The Coder Who Encrypted Your Texts

#165
post #113

I still can't get over Moxie wanting Google and Apple and Microsoft to be gatekeepers of what you can and can't do with your device and calling sideloading "that old broken desktop security model". I admire your work Moxie, but sadly we stand on different sides of war on general purpose computing. I can't help but be saddened that "the other side" got someone so talented and dedicated.

For context, I assume you're referring to this [0]? I think it's a bit more nuanced than you're letting on here.

[0] https://github.com/WhisperSystems/TextSecure/issues/127

Re: The Coder Who Encrypted Your Texts

#166
post #83

Interesting article and interesting guy. I like the work he and his team does on these apps. Unfortunately, they typically run on the type of endpoints that everyone from script kiddies with money to High Strength Attackers can hit. Usually alongside apps not as strong as theirs on TCB's that can at best be described as insecure foundations. I recommend against such apps and platforms for anything other than stopping…

We don't have time to wait for widespread TCB, even if we could when the NSA is actively trying to undermine all methods for it.

There's quite a few that's been developed in both business and academia with some deployed. NSA didn't do shit except maybe backdoor the closed ones. Genode.org is one of better-structured one's that's FOSS and usable today. Build on it.

You can also negotiate source from one of the separation kernel vendors, compile it on target of your choice, and port L4Linux (user-mode Linux) to it to keep legacy apps. CHERI processor and CheriBSD are open source. EROS source was published and could be extended. JX Operating System has almost everything under JVM's safety protections with relatively small TCB. Cool tools like Softbound and Astree knock out bugs in what's left.

There's many tools to start with to get smaller, strong TCB's. They're just the only one's the open-source community doesn't work on. Tiny, tiny set of exceptions. People not wanting to worry about it can just build on Tinfoil Chat: largely eliminated TCB with clever use of data diodes and physical separation. A Moxie-coded version of that portable to arbitrary embedded systems could be made NSA-proof. So, there's options for anyone wanting to get started.

Meanwhile, I'll keep using GPG on airgapped machines with diverse hardware and interface protection. Only thing that works per Snowden leaks. For now...

Re: The Coder Who Encrypted Your Texts

#167
post #5

I get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.

Glad to see the effort getting attention in any regard. Thanks to you and the whole team for working so hard on all of this. Keep up the good work.

Re: The Coder Who Encrypted Your Texts

#168
post #113

I still can't get over Moxie wanting Google and Apple and Microsoft to be gatekeepers of what you can and can't do with your device and calling sideloading "that old broken desktop security model". I admire your work Moxie, but sadly we stand on different sides of war on general purpose computing. I can't help but be saddened that "the other side" got someone so talented and dedicated.

There is no war on general purpose computing. Who even came up with the idea?

Sorry, either you don't understand the concept or you haven't been paying attention. The whole movement by big manufacturers has been towards closed ecosystems, with the end user unable to exercise much control over their hardware, to the point where many people consider devices leased rather than owned. You can't even change the battery on Apple devices now without voiding the warranty. The same is happening with cars, TVs, you name it. If it's something that can be repaired or otherwise messed around with, the companies don't want you to be able to do it.

Re: The Coder Who Encrypted Your Texts

#169

Earlier quoted context omitted.

"Think of the childern" is a common refrain of the coward who values safety over freedom.

I wonder how many of the people on that think of the children side were either affected as kids, had children who had some awful experience, or are of close relation to someone who was or had kids who did. Because I could easily see something like an awful event happening to a child really warping a persons world view in a strong way. On the other hand, I wonder how many privacy advocates have never experienced anyth…

> And then I wonder for the motivations of the people for whom child touchers are hearsay but are really opposed to privacy. Their motives must include things like drug dealers, terrorists, a belief in their own clean slate, money. It's pretty interesting to think about what goes on behind the scenes of any argument that gains popular traction.

If I had an ulterior motive for arguing against a particular technology, spinning it as "think of the kids" would be something easy and safe to do. Anybody arguing against you could be painted as horrible horrible people who don't think of the kids.

Re: The Coder Who Encrypted Your Texts

#170
post #5

I get a lot of credit for the stuff that Open Whisper Systems does, but it's not all me by a long shot. Trevor Perrin, Frederic Jacobs, Christine Corbett, Tyler Reinhard, Lilia Kai, Jake McGinty, and Rhodey Orbits are the crew that really made all this work happen.

Moxie, the progress on TextSecure/Signal integration seems to have slowed down quite a bit (at least as seen from the outside). I think it's been almost a year since Signal for iOS came out - yet still no word on Signal for Android. What is taking so long, if you don't mind me asking? Is there some sort of Signal 3.0 overhaul planned for all the platforms along with a big launch? Also, I think you've been quite retre…

>yet still no word on Signal for Android.

Just in case you're not aware. RedPhone for android does encrypted calling, and TextSecure for android does encrypted messaging, so there doesn't seem to be a reason for Signal on Android aside from the brand unification.

Post reply on HN