As far as the audit, I feel like 13 days is surprisingly short. I base this on my experience getting new jobs and familiarizing myself with new code bases. Maybe I'm slow.
Darknet Messenger Briar Releases Beta, Passes Security Audit
41–50 of 90 posts
Re: Darknet Messenger Briar Releases Beta, Passes Security Audit
#42"passes security audit". Is security audit an exam? What does passing mean?
Purely naively I would guess that it means during whatever audit they ran, no signs of insecurity were observed. Maybe it would be better to say that it didn't "fail" the audit?
That was one of the most heavily audited components too.
Re: Darknet Messenger Briar Releases Beta, Passes Security Audit
#43Re: Darknet Messenger Briar Releases Beta, Passes Security Audit
#44It's ironic that this update plays up how Briar "hides metadata" when the audit found that the application deanonymizes its users by exposing DNS lookups during RSS updates.
Re: Darknet Messenger Briar Releases Beta, Passes Security Audit
#45Re: Darknet Messenger Briar Releases Beta, Passes Security Audit
#46This looks interesting, but I wonder how safe it is in the stated use case of journalists, activists in an authoritarian country. It can use Tor, which hides whom you are communicating with, but the fact that you are using Tor sticks out like a red thumb. The authorities probably just have to flip a switch to put you under closer surveillance if they see you use Tor. Or they'll just send someone to your registered ad…
Re: Darknet Messenger Briar Releases Beta, Passes Security Audit
#47Re: Darknet Messenger Briar Releases Beta, Passes Security Audit
#48Re: Darknet Messenger Briar Releases Beta, Passes Security Audit
#49Re: Darknet Messenger Briar Releases Beta, Passes Security Audit
#50Why not develop tox instead, which is open source, end to end encrypted, on more platforms, and seemingly further along in general?
I'm not a crypto expert, but I also personally wouldn't put much stock in the security of their protocol or implementation.