Live data from Hacker News

CryptoCat iOS Application Penetration Test [pdf]

isecpartners.github.io

41–50 of 137 posts

Re: CryptoCat iOS Application Penetration Test [pdf]

#41
post #17

Earlier quoted context omitted.

I wish I knew how to find my way into security as a hobby. Such a fun topic.

Long-time HN member tptacek's company has a challenge set that many praise highly: http://www.matasano.com/articles/crypto-challenges/

Are the Matasano crypto challenges currently stuck in some way, like with a grading backlog? I signed up some months ago, sent my first set of answers just after the new year, and have never heard back about the second challenge set.

Re: CryptoCat iOS Application Penetration Test [pdf]

#42
post #21

Earlier quoted context omitted.

[deleted]

We commissioned this audit in late December and iSec began working on it in January. They audited a pre-release prototype that we provided. This is noted in the audit document, but it's hard to spot unfortunately. The reason we commissioned this audit is to make sure our prototype was audited before release on the App Store. We're very happy to have benefited from this audit, but linking to this PDF alone de-contextu…

How was this a "pre-release prototype" audit of Cryptocat if the app was for iOS was rejected from the Apple app store in December.... and the audit took place after that in mid January? Seems dubious to say it was all about some extra debug logging when there are some serious flaws here found weeks after it almost was approved on the Apple store.

http://www.theverge.com/2013/12/27/5249402/encrypted-chat-se...

Re: CryptoCat iOS Application Penetration Test [pdf]

#43
post #26

Earlier quoted context omitted.

Was it commissioned by you? The audit I saw had the Open Technology Fund's logo on it. OTF is a US Government effort driven by Radio Free Asia and the Broadcast Board of Governors. OTF, again (smartly) using US taxpayer dollars, funds audits of a variety of privacy technologies. For instance, they also funded a good-sized chunk of the Truecrypt audit.

I can't tell if you actually don't know who commissioned it or if this is your way of suggesting that the parent comment is a lie. It seems like information you would have access to, considering your connection with iSEC, no? (I'm not trying to stir up shit, just genuinely curious.)

Whoah! I'm not saying anyone is being dishonest. I know approximately as much as anyone who can read the linked PDF knows, modulo that I also know a bit about how OTF works because I worked with Matthew Green on coordinating the Truecrypt audit.

I was asking for clarification, but my writing style is dry and blunt, so I'm not surprised if I managed to convey something different. I apologize in advance if so.

More than anything else, I wrote the comment as a (hopefully mild) F-U to the sentiment that the USG is hellbent on destroying privacy on the Internet. Big parts of it are, sure, but there are good people working inside of it too. :)

Re: CryptoCat iOS Application Penetration Test [pdf]

#44
post #26

Earlier quoted context omitted.

Was it commissioned by you? The audit I saw had the Open Technology Fund's logo on it. OTF is a US Government effort driven by Radio Free Asia and the Broadcast Board of Governors. OTF, again (smartly) using US taxpayer dollars, funds audits of a variety of privacy technologies. For instance, they also funded a good-sized chunk of the Truecrypt audit.

I can't tell if you actually don't know who commissioned it or if this is your way of suggesting that the parent comment is a lie. It seems like information you would have access to, considering your connection with iSEC, no? (I'm not trying to stir up shit, just genuinely curious.)

I do not work for isec or matasano and I had the same question tptacek posted. The lead developer says that audit was commissioned by "us" and yet page 7 of the audit states:

  The Open Technology Fund (OTF) engaged iSEC Partners to perform a source-code
  assisted security review of the CryptoCat iOS application.

Re: CryptoCat iOS Application Penetration Test [pdf]

#45
post #26

Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…

Was it commissioned by you? The audit I saw had the Open Technology Fund's logo on it. OTF is a US Government effort driven by Radio Free Asia and the Broadcast Board of Governors. OTF, again (smartly) using US taxpayer dollars, funds audits of a variety of privacy technologies. For instance, they also funded a good-sized chunk of the Truecrypt audit.

they(cryptocat) commissioned it or were at least involved. https://news.ycombinator.com/item?id=7519431

Re: CryptoCat iOS Application Penetration Test [pdf]

#46
post #26

Hi, I'm the lead developer for Cryptocat. I strongly urge you all to please read our blog post regarding this audit: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... This audit document alone does not give enough context. This audit was commissioned by us and concerns a pre-release version of Cryptocat for iPhone. Many of the bugs it found are due to the fact that it was reviewing a prototype with debu…

Was it commissioned by you? The audit I saw had the Open Technology Fund's logo on it. OTF is a US Government effort driven by Radio Free Asia and the Broadcast Board of Governors. OTF, again (smartly) using US taxpayer dollars, funds audits of a variety of privacy technologies. For instance, they also funded a good-sized chunk of the Truecrypt audit.

It is nice that OTF is funding audits and releasing the reports. It is too bad we can not find out more info on the mythic SJCL audit.

Re: CryptoCat iOS Application Penetration Test [pdf]

#47
post #5

Also of interest is their blog post about how they plan to handle the issues described in this report: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp... Reading that, I still am not sure why anyone would use CryptoCat especially with things like TextSecure on the market that seem to take crypto far more seriously. The only reason I can see for that is that they have clients on more platforms, but if thi…

Has anyone done the same level of analysis on TextSecure ? I feel like their model/seriousness is better but there might be flaws in the implementation (or protocol) and being audited might highlight some of them.

I don't believe they've had an independent security audit. I think their team however is comprised of more respected cryptographers like Moxie Marlinspike, who introduced the concept of SSL stripping, one of the issues that was found in the CryptoCat app. I mean no disrespect to CryptoCat, and more eyes can always find something someone overlooked, but I think the Open Whisper Systems (TextSecure) team is stronger and using better cryptographic techniques.

Re: CryptoCat iOS Application Penetration Test [pdf]

#48

Huh, this was apparently submitted by Alex Stamos, a co-founder of iSec partners (who did this audit). And he editorialized the title, "Brutal Professional Audit of CryptoCat Published." Your former company did an audit for a customer, then you posted it to HN calling it "Brutal"? Really?

[deleted]

Re: CryptoCat iOS Application Penetration Test [pdf]

#49

Earlier quoted context omitted.

Has anyone done the same level of analysis on TextSecure ? I feel like their model/seriousness is better but there might be flaws in the implementation (or protocol) and being audited might highlight some of them.

I don't believe they've had an independent security audit. I think their team however is comprised of more respected cryptographers like Moxie Marlinspike, who introduced the concept of SSL stripping, one of the issues that was found in the CryptoCat app. I mean no disrespect to CryptoCat, and more eyes can always find something someone overlooked, but I think the Open Whisper Systems (TextSecure) team is stronger an…

TextSecure also has design contributions from Trevor Perrin, who is also amazing.

Re: CryptoCat iOS Application Penetration Test [pdf]

#50
post #35

Earlier quoted context omitted.

I wish I knew how to find my way into security as a hobby. Such a fun topic.

Why find your way in as a hobby? Are you a professional developer now? Do you like low-level code? Are you OK with jumping directly into the deep end of the pool and maybe drowning a little bit? Why not reach out and talk to us about working on a professional security team? We have gotten very, very good at taking low-level devs and turning them into terrifying killing machines, and if you don't mind having all your…

And try their crypto challenges :)
Post reply on HN