Live data from Hacker News

Three lessons from Threema: Analysis of a secure messenger

breakingthe3ma.app

51–55 of 55 posts

Re: Three lessons from Threema: Analysis of a secure messenger

#51

Threema has responded: https://threema.ch/en/blog/posts/news-alleged-weaknesses-sta... New Paper on Old Threema Protocol

The baffling part of that response is that they could easily have conveyed the same basic message in a much less defensive way instead of making me glad I don't rely on Threema for my messaging security. "Good research, and here's how we've addressed those issues and proactively enhanced our security even further" is a decent story to be able to tell about how you're constantly trying to make your customers safer. Be…

> image is more important than security

It's the company that's promoting its product with "Trust us, we're Swiss", even though it's a stupid argument after Crypto AG (and a few other, similar exploits): https://en.wikipedia.org/wiki/Crypto_AG

Re: Three lessons from Threema: Analysis of a secure messenger

#53
post #48

Earlier quoted context omitted.

The story around Threema feels a tiny bit like Crypto AG repeating: Reputable Swiss company sells homebrew crypto to unsuspecting parties.

Crypto AG was effectively owned and operated by intelligence services. There's no evidence at all this is the case for Threema, if anything, you'd expect intelligence services to hide their tracks far better. 'A functional, secure E2EE instant messenger with broad public appeal/usability' is just a very convoluted, readily bungle-able project.

Threema had 9 years to migrate to something more standard like the Signal protocol, given the findings in the article, that would have been a great idea.

In their defense, they're a comparably tiny company, so a full protocol rewrite might be too much of cost to keep their investors happy.

Re: Three lessons from Threema: Analysis of a secure messenger

#54
post #48

Earlier quoted context omitted.

Crypto AG was effectively owned and operated by intelligence services. There's no evidence at all this is the case for Threema, if anything, you'd expect intelligence services to hide their tracks far better. 'A functional, secure E2EE instant messenger with broad public appeal/usability' is just a very convoluted, readily bungle-able project.

Threema had 9 years to migrate to something more standard like the Signal protocol, given the findings in the article, that would have been a great idea. In their defense, they're a comparably tiny company, so a full protocol rewrite might be too much of cost to keep their investors happy.

migrate to something more standard like the Signal protocol

That helps less than it might seem at first glance because it's just a very convoluted, readily bungle-able project, as per:

https://mjg59.dreamwidth.org/62598.html

with HN discussion here: https://news.ycombinator.com/item?id=33929620

and one of its references, which I don't think has had HN coverage

https://www.usenix.org/conference/usenixsecurity22/presentat...

None of these difficulties imply or require infiltration by intelligence services.

Re: Three lessons from Threema: Analysis of a secure messenger

#55

The problem with messengers: The more secure and privacy centered they are, the less likely it is that any of your friends and relatives use them.

WhatsApp is pretty secure compared to most of the other messengers out there and it's quite popular in some countries. So that's not it. It's marketing and/or being at the right place at the right time.
Post reply on HN