Earlier quoted context omitted.
His answer to "should I use this to fight my impressive regime" was the same for all the tools, just with different wording.
My answer to that question was the same everywhere, because I think you'd be crazy to use these tools to fight an oppressive regime. Just different levels of crazy.
Here come the encryption apps
51–58 of 58 posts
Re: Here come the encryption apps
#52Earlier quoted context omitted.
I don't understand why you'd concede security to your competition; it is a genuine distinction. Most security people I know, and all the crypto people I know would choose your designs over those of the other designers in this review, not because of the quality of your application but because you're clearly a capable designer. I worry about the message we send with this "the competition is insecure apps" stuff. Some o…
What I really want is for everyone to be using secure communication tools all the time. Not just because it'd obviously be great if everyone were communicating securely day to day, but because in extreme events, people tend to use the tools they already have and are familiar with. For the London riots, that was BlackBerry Messenger. For the Egypt riots, that was Facebook and Twitter. Maybe the next explosive event wi…
http://www.mightbeevil.com/contacts/
using something like
Re: Here come the encryption apps
#53Earlier quoted context omitted.
I don't think the average user feels it is at the bottom of the list, rather the average user trusts webservices for various reasons without realizing how much insecurity and lack of privacy results from using common webservices. I think that is slowly changing though.
The problem I've experienced is that whenever I talk about software security with non technical people I get a lot of "I thought this dude was normal until he put on the tinfoil hat" looks and overall lack of interest. The only time people become more aware of security is once they've suffered the consequences of a lack of security. To be fair, the only reason it concerns me is because I've been exposed to so many st…
Re: Here come the encryption apps
#54> While Cryptocat is written in Javascript (aaggh!) Is there something inherently insecure about using JavaScript or is this not meant to actually be relevant?
If it's served from a webpage, then it's insecure. Either the publishing server can replace it with a malicious version, or another server might inject javascript that modifies or replaces it with a malicious version. This particular point hilariously broke a crypto protocol project of mine, so I guess I'm touchy about it. Shipping as a browser module is more secure.
Re: Here come the encryption apps
#55Earlier quoted context omitted.
If it's served from a webpage, then it's insecure. Either the publishing server can replace it with a malicious version, or another server might inject javascript that modifies or replaces it with a malicious version. This particular point hilariously broke a crypto protocol project of mine, so I guess I'm touchy about it. Shipping as a browser module is more secure.
That's not really a problem with the language.
Re: Here come the encryption apps
#56A minor point of curiosity: one of the captions says "Using SilentCircle on a Huawei complete negates the point of using SilentCircle." I appreciate that it may be somewhat tongue in cheek, but is that a riff on the US accusing Huawei of being a national security threat[0], or do Huawei phones have a track record of known security vulnerabilities? [0] http://www.nytimes.com/2012/10/09/us/us-panel-calls-huawei-a...
At some point it is hard to say a system is secure if you cannot control the hardware. That is when secure systems are certified it is not just a software library, it has to be full hardware + software solution. If anything can insert itself in between boot and loading the OS then it could read the memory and just scan the memory for a key (by say emulating the memory inside a VM). A phone manufacturer could very sim…
Re: Here come the encryption apps
#57These apps remind of the guy who bought the first fax machine, nice but you need a friend with one too for it to be of any use.
C.f., today's social networks.
Re: Here come the encryption apps
#58A minor point of curiosity: one of the captions says "Using SilentCircle on a Huawei complete negates the point of using SilentCircle." I appreciate that it may be somewhat tongue in cheek, but is that a riff on the US accusing Huawei of being a national security threat[0], or do Huawei phones have a track record of known security vulnerabilities? [0] http://www.nytimes.com/2012/10/09/us/us-panel-calls-huawei-a...
http://www.zdnet.com/backdoor-found-in-zte-android-phones-13...