Live data from Hacker News

The Next Front in the New Crypto Wars: WhatsApp

eff.org

51–60 of 215 posts

Re: The Next Front in the New Crypto Wars: WhatsApp

#51
post #8

Earlier quoted context omitted.

Looks like it means that the encryption cannot be reverse-engineered: http://help.penzu.com/pro/what-is-one-way-encryption/

> One way encryption is a mathematical function that takes a variable-length input string and converts it into a fixed-length binary sequence. So, a hash function and not encryption? Got it. Sarcasm aside, we really need to start using the correct terms. https://paragonie.com/blog/2015/08/you-wouldnt-base64-a-pass... Cryptography ||\ | \`- Hash Functions | `- Secret-Key Cryptography | |\ | \`- Secret-Key Encryption |…

If you have good hashing, you can build encryption, though.

Re: The Next Front in the New Crypto Wars: WhatsApp

#52
No one can stop me and my peers from sending meaningless garbage data to each other.

So, if it simply looks encrypted, but acctually contains randomized meaningless shit, how can anyone prevent me from bahaving in this manner, and claim that I've done harm?

I've paid for the service, and I can spam it with trash as I see fit.

Re: The Next Front in the New Crypto Wars: WhatsApp

#54

No one can stop me and my peers from sending meaningless garbage data to each other. So, if it simply looks encrypted, but acctually contains randomized meaningless shit, how can anyone prevent me from bahaving in this manner, and claim that I've done harm? I've paid for the service, and I can spam it with trash as I see fit.

Until in jail :/

Re: The Next Front in the New Crypto Wars: WhatsApp

#55
post #51

Earlier quoted context omitted.

> One way encryption is a mathematical function that takes a variable-length input string and converts it into a fixed-length binary sequence. So, a hash function and not encryption? Got it. Sarcasm aside, we really need to start using the correct terms. https://paragonie.com/blog/2015/08/you-wouldnt-base64-a-pass... Cryptography ||\ | \`- Hash Functions | `- Secret-Key Cryptography | |\ | \`- Secret-Key Encryption |…

If you have good hashing, you can build encryption, though.

And if you have a good block cipher you can build a hash function.

Encryption is a reversible, keyed transformation of a message. If you cannot reverse it, it is not encryption. Calling it encryption just introduces confusion.

Re: The Next Front in the New Crypto Wars: WhatsApp

#56

If the government wins any of these court battles, it's only a matter of time until one-way encryption is outlawed. It follows logically that if criminals/terrorists can't use iPhones to securely communicate, then they'll just move on to the next convenient encryption app. The government will continue to order companies to break their one-way encryption until the government realizes they're playing musical chairs and…

Would there be a first amendment (freedom of speech) argument against such an outlawing? If you are not allowed to say things which the government doesn't understand, then your speech isn't free.

Re: The Next Front in the New Crypto Wars: WhatsApp

#57

Here the local drug dealers encourage use of a app called Wickr. Does anyone know how the encryption compares to WhatsApp?

https://github.com/nylira/prism-break/issues/249#issuecommen... https://www.reddit.com/r/australia/comments/32hexp/a_secret_... Don't use Wickr. Proprietary crypto + an interesting target for NSA because of its popularity among ISIS = probably snake oil and at the very least makes you a target "Career criminals recommend it" isn't a good indicator of security. Two things to consider: 1. Confidential informants exist…

Thanks a lot for the detailed answer.

I will be sure the take the discussion on RSA encryption with PKCS1v1.5 padding the next time I see those guys. Probably without mentioning ISIS..

Re: The Next Front in the New Crypto Wars: WhatsApp

#58
post #43

Earlier quoted context omitted.

The right to "keep and bear arms" pretty clearly implies the right to use arms (guns) in the way they were intended to be used, which means access to the ammunition as well. No one in their right mind believes the Second Amendment was written with the idea that militiamen would use their guns primarily as clubs. It's not done partly because the "anti-gun lobby" knows it would be a fruitless endeavor, and partly becau…

I was under the impression that certain types of ammunition are able to be banned without any constitutional issues arising [1]. If you wanted to be really clever you could still allow ammunition, but limit the materials the bullet could be made from or limit the powder load. Attacking ammunition has got to be a more workable strategy than trying to restrict gun ownership without consitutional change. 1. https://en.w…

Sure, but I think a strategy like that only avoids constitutional issues because it's not a general attack on the efficacy of firearms. Anything that has the effect of making guns less effective en masse would probably run afoul of the Second Amendment.

Re: The Next Front in the New Crypto Wars: WhatsApp

#59

http://www.nytimes.com/2016/03/13/us/politics/whatsapp-encry... > The Justice Department and WhatsApp declined to comment. The government officials and others who discussed the dispute did so on condition of anonymity because the wiretap order and all the information associated with it were under seal. The nature of the case was not clear, except that officials said it was not a terrorism investigation. The location…

GnuPG is great, but it is not for real-time messaging. Real-time messaging protocol should have forward secrecy, which OpenPGP can't have because it is not an interactive protocol. Related: http://www.thoughtcrime.org/blog/gpg-and-me/

I'm aware but I don't need real time messaging for secure communication. It is really limited to things like security flaws, financial information, and things of that nature.
Post reply on HN