Live data from Hacker News

CryptoCat iOS Application Penetration Test [pdf]

isecpartners.github.io

61–70 of 137 posts

Re: CryptoCat iOS Application Penetration Test [pdf]

#61

Earlier quoted context omitted.

Has anyone done the same level of analysis on TextSecure ? I feel like their model/seriousness is better but there might be flaws in the implementation (or protocol) and being audited might highlight some of them.

I don't believe they've had an independent security audit. I think their team however is comprised of more respected cryptographers like Moxie Marlinspike, who introduced the concept of SSL stripping, one of the issues that was found in the CryptoCat app. I mean no disrespect to CryptoCat, and more eyes can always find something someone overlooked, but I think the Open Whisper Systems (TextSecure) team is stronger an…

No need for an of audit TextSecure... just go to their github issues page. Plenty of open bugs and regressions, some of them as serious as some of the ones in the latest CryptoCat app audits. For example, one issue where some messages sent are not being encrypted.

Even with 'amazing' contributors, bugs are still there in TextSecure.

Re: CryptoCat iOS Application Penetration Test [pdf]

#62
post #55
post #41

Earlier quoted context omitted.

Are the Matasano crypto challenges currently stuck in some way, like with a grading backlog? I signed up some months ago, sent my first set of answers just after the new year, and have never heard back about the second challenge set.

We are way. way. way. backlogged. If anyone has any idea on how to help a hapless team of security researchers manage many thousands of people looking to get through the crypto challenges, we'd be t-h-r-i-l-l-e-d. We were able to keep up last summer, but then Microcorruption happened, we got into a hole, and we're only slowly digging ourselves out of it. Alex, Sean, and I are turning the challenges into a book, which…

Have you considered taking people who have passed challenges (and are excited about them) on as volunteer assistants for the challenges?

Re: CryptoCat iOS Application Penetration Test [pdf]

#63
post #61

Earlier quoted context omitted.

I don't believe they've had an independent security audit. I think their team however is comprised of more respected cryptographers like Moxie Marlinspike, who introduced the concept of SSL stripping, one of the issues that was found in the CryptoCat app. I mean no disrespect to CryptoCat, and more eyes can always find something someone overlooked, but I think the Open Whisper Systems (TextSecure) team is stronger an…

No need for an of audit TextSecure... just go to their github issues page. Plenty of open bugs and regressions, some of them as serious as some of the ones in the latest CryptoCat app audits. For example, one issue where some messages sent are not being encrypted. Even with 'amazing' contributors, bugs are still there in TextSecure.

I just reviewed all open and closed bugs in TextSecure's Issues page and didn't see a single crypto protocol bug. Admittedly, I looked quickly and casually. Could you point us to one?

Re: CryptoCat iOS Application Penetration Test [pdf]

#64
post #55

Earlier quoted context omitted.

We are way. way. way. backlogged. If anyone has any idea on how to help a hapless team of security researchers manage many thousands of people looking to get through the crypto challenges, we'd be t-h-r-i-l-l-e-d. We were able to keep up last summer, but then Microcorruption happened, we got into a hole, and we're only slowly digging ourselves out of it. Alex, Sean, and I are turning the challenges into a book, which…

Have you considered taking people who have passed challenges (and are excited about them) on as volunteer assistants for the challenges?

If anyone has ideas on how we could do that, I'm all ears. We'd have to mitigate the privacy issues somehow, because not everyone has given us permission to reveal that they're working through the challenges, and passing submissions to people outside the firm would be that.

Re: CryptoCat iOS Application Penetration Test [pdf]

#65
post #34

Earlier quoted context omitted.

It's important to note that this audit concerned a pre-release, debugging version of Cryptocat for iPhone. The audit document alone doesn't give enough context; I strongly urge reading our blog post: https://blog.crypto.cat/2014/04/recent-audits-and-coming-imp...

Are you saying that it's good news because it means that no actual users were exposed to the flaws? To the extent that those flaws apply only to the iOS version, I agree: that's good news. Are you saying that it's good news because they tested something that you weren't ever going to release in that state? That's a tougher row to hoe, unless you're going to claim that your team inevitably would have found the same se…

Speaking of the vulnerabilities that our team found, here is our blog post about it and a link to our report and the github issue tickets that we opened: Here is our blog post about our audit of Cryptocat, which was also announced today: https://leastauthority.com/blog/

Re: CryptoCat iOS Application Penetration Test [pdf]

#66

This is awesome. I'm sad that CryptoCat is getting slammed for this for being one of the brave few to post this online. I am sure there are an infinite number of "security-critical" apps which would fail an audit like this, but who never even thought to GET an audit -- much less post it online. The software development community is much stronger for being able to see professional stuff like this posted. Does anyone k…

Generally 10-50k is a good starting point for this level. Most firms are full up on work most of the time, but will often try to get interesting new companies or projects even if they're less profitable since 1) they can grow into better stuff 2) good for reputation and for retention of their own employees.

Compliance-only is usually cheaper; you can buy rubber stamps for <$10k.

Re: CryptoCat iOS Application Penetration Test [pdf]

#67
post #26

Earlier quoted context omitted.

Was it commissioned by you? The audit I saw had the Open Technology Fund's logo on it. OTF is a US Government effort driven by Radio Free Asia and the Broadcast Board of Governors. OTF, again (smartly) using US taxpayer dollars, funds audits of a variety of privacy technologies. For instance, they also funded a good-sized chunk of the Truecrypt audit.

I can't tell if you actually don't know who commissioned it or if this is your way of suggesting that the parent comment is a lie. It seems like information you would have access to, considering your connection with iSEC, no? (I'm not trying to stir up shit, just genuinely curious.)

Another option is that OTF approached CryptoCat, from where their options would be:

a) don't do an audit - and the public would ask what they are hiding

b) agree to an audit being done, meaning you 'commissioned' it.

So it is just as important to know who approached who in this situation.

Re: CryptoCat iOS Application Penetration Test [pdf]

#68

Huh, this was apparently submitted by Alex Stamos, a co-founder of iSec partners (who did this audit). And he editorialized the title, "Brutal Professional Audit of CryptoCat Published." Your former company did an audit for a customer, then you posted it to HN calling it "Brutal"? Really?

Former employee adds adjective to HN submission title, film at 11.

Re: CryptoCat iOS Application Penetration Test [pdf]

#69
post #60

Earlier quoted context omitted.

> The browser code is distributed as an extension, which does not have the properties you describe. Actually, browser extensions have the exact same properties except for being code signed. That's not enough: http://arstechnica.com/security/2014/01/malware-vendors-buy-... > I don't think CryptoCat has been distributed as a traditional web app for at least a year (probably more). That they ever shipped in-browser cryp…

Malicious people buying extensions and then malwareing it is as likely or not as malicious people buying the vendor of whatever tool you are using on the desktop once its auto-updating feature is good enough (that would actually be slightly worse, because in the case if the extension you at least get to read what's actually executed). What you are saying is that you don't trust any kind of application to do crypto un…

> ... once its auto-updating feature is good enough ...

This is why it's a very bad idea to implement silent automatic updates, and why they're the wrong thing to copy from the web.

Re: CryptoCat iOS Application Penetration Test [pdf]

#70
post #34

Earlier quoted context omitted.

Are you saying that it's good news because it means that no actual users were exposed to the flaws? To the extent that those flaws apply only to the iOS version, I agree: that's good news. Are you saying that it's good news because they tested something that you weren't ever going to release in that state? That's a tougher row to hoe, unless you're going to claim that your team inevitably would have found the same se…

Speaking of the vulnerabilities that our team found, here is our blog post about it and a link to our report and the github issue tickets that we opened: Here is our blog post about our audit of Cryptocat, which was also announced today: https://leastauthority.com/blog/

There is great stuff in here, including the CTR nonce reuse bug that Nadim wrote about earlier. Ouch.
Post reply on HN