Live data from Hacker News

ISIS Has a Smartphone App

fortune.com

51–60 of 80 posts

Re: ISIS Has a Smartphone App

#51
post #38
post #18

Earlier quoted context omitted.

I'd doubt users of an encryption app not using a simple checksum to verify its legitimacy before using it.

Probably not true. E.g., do you think the average user of Tor takes this precaution? Thinking back to the times I have downloaded Tor, I never did that. It reminds me of a time when I wanted to get in touch with an HN user... they had their pgp key in their user page... I tried sending the email but it didn't work (formatting issues). Finally I reached this user and asked what was up with it... and he responded by sa…

Well, differently from you and your friend, ISIS does have somebody out to get them.

It's very hard to think someone would get to the trouble of creating and using a secure chat application, but then fail to secure its distribution.

Re: ISIS Has a Smartphone App

#52
post #44

I thought they can chat in Arabic and western intelligence agencies will have no clue what is going on. There is very very little knowledge of Arabic language (with slang and such) in western intelligence agencies. As far as I now, there is less than 2,500 Americans are studying Arabic at colleges across the country right now. And 80% of them will be kicked out from country by "Trumps" as terrorists :-)

You can't possibly be serious.

Re: ISIS Has a Smartphone App

#54
Where does the article say this is an encrypted chat app? The description of the app says that it features news and videos, and the only discussion of chat that I can find is about using third-party encrypted services like Telegram (which gets three separate mentions) to communicate.

Re: ISIS Has a Smartphone App

#55
post #41

This is really stupid, surely? Even if it's not distributed via Google Play, Android will look at the package names of all installed apps. Therefore it's not difficult to find all the users with a subpoena to Google for these records.

That assumes a phone-home feature that cannot be turned off.

Strictly speaking I guess a phone-home feature that isn't turned off would do just fine.

Would be interesting to know how good the fighting parties are with that...

Re: ISIS Has a Smartphone App

#56

Surely it can't be that hard to create a chat app with end to end encryption these days with all the open source libraries freely available for all kinds of applications...this is why I've always said banning encryption on major platforms like iOS/Android/Windows will get you nowhere when terrorists can just make their own encrypted chat apps if they really want to.

you could just fork signal[1], change the icon, and im sure the average ISIS soilder wouldnt know the difference

[1] https://github.com/WhisperSystems/Signal-iOS

Re: ISIS Has a Smartphone App

#57
post #39
post #34

Earlier quoted context omitted.

Well sometimes you cannot tell...

So if it were bombs instead of surveillance you would bomb the target when you're uncertain about its enemy status? And since we're talking about mass surveillance... I guess carpet bombing?

... this is an obviously terrible argument. If you surveil someone secretly and then decide not to act on the intelligence, they aren't harmed in any way. They don't even know. The mistakenly assassinated are still dead.

Re: ISIS Has a Smartphone App

#58
post #38

Earlier quoted context omitted.

Probably not true. E.g., do you think the average user of Tor takes this precaution? Thinking back to the times I have downloaded Tor, I never did that. It reminds me of a time when I wanted to get in touch with an HN user... they had their pgp key in their user page... I tried sending the email but it didn't work (formatting issues). Finally I reached this user and asked what was up with it... and he responded by sa…

Well, differently from you and your friend, ISIS does have somebody out to get them. It's very hard to think someone would get to the trouble of creating and using a secure chat application, but then fail to secure its distribution.

As someone who works in infosec, this doesn't surprise me at all.

I've tested many applications which claim to be secure, designed for security/privacy sensitive tasks, yet are very easy to compromise (simple OWASP top 10 stuff).

Even if the app developers are great and know their stuff, I can still see them slipping up on the distribution. It's normally handled for most developers and is outside the realm of any secure development guidelines they might be following.

Re: ISIS Has a Smartphone App

#59

Alrawi can’t be downloaded from Google Play. Instead it must be installed from shady back alleys of the Internet. Well, there's your obvious solution. Get a copy of the APK, wrap it with some spyware, then propagate the bugged version. If ISIS won't host the source or can't provide an "official" outlet to grab it, you've got no way of knowing whether your version is legit or not. Who'd have thought the paradigms of s…

No, the obvious solution is to prevent people on Android from installing their own apps and then forcing Google (a private company) to play police for the whole world according to USA law. We shall then continue by discontinuing production of all cars that ISIS drives and demanding that they have killswitches enabled so Toyota can be forced to disable them when they detect a terrorist driving. Windows and OS X will need to have terrorist killswitch ("kill laptop if arabic word bomb is entered by keyboard into any textview") built in as well.

Logical isn't it? At least according to our lovely politicians.

(The first paragraph is sarcasm by the way.)

Re: ISIS Has a Smartphone App

#60
post #5

Which I am sure the intelligence agencies are having a field day with. Nothing like rolling your own encryption. What are the chances it was created by one of the intelligence agencies?

> What are the chances it was created by one of the intelligence agencies? I came to the comment section to say that exact same thing. If I were one of those intelligence agencies it would be tempting to use the information right away but for it to be truly effective, you'd need to let it propagate pretty far. What a field day for intelligence agencies even if wasn't planned by them -- just one thing to bust and they…

> Is this story even serious?

It will encourage potential criminals to communicate through a system that's just a honey trap, instead of using other more secure options.

Post reply on HN