Live data from Hacker News

MEGAChat now includes end-to-end encryption

mega.nz

81–90 of 98 posts

Re: MEGAChat now includes end-to-end encryption

#81
post #80
post #74

Earlier quoted context omitted.

If you want to have a one-off conversation without worrying about someone intercepting and storing your conversation, use Google's IM protocol. You won't have to install anything. If you want to protect your communications from the kinds of adversaries who can defeat Google's security, you're talking about a class of adversary that is largely government sponsored, and all of them are likely to be able to compromise a…

> all of them are likely to be able to compromise a messaging application that boots from a web page. All of them are likely to be able to compromise your OS, the Intel Management Engine ( http://hackaday.com/2016/01/22/the-trouble-with-intels-manag... ), your flash drives, the baseband on your blackphone... There's so much code, so many layers of abstraction involved in doing even the most basic things and so many t…

That's what people who supported Cryptocat said. It's also what people who supported Telegram said.

Not interested in this argument, sorry.

Re: MEGAChat now includes end-to-end encryption

#82
post #81
post #80

Earlier quoted context omitted.

> all of them are likely to be able to compromise a messaging application that boots from a web page. All of them are likely to be able to compromise your OS, the Intel Management Engine ( http://hackaday.com/2016/01/22/the-trouble-with-intels-manag... ), your flash drives, the baseband on your blackphone... There's so much code, so many layers of abstraction involved in doing even the most basic things and so many t…

That's what people who supported Cryptocat said. It's also what people who supported Telegram said. Not interested in this argument, sorry.

> That's what people who supported Cryptocat said. It's also what people who supported Telegram said.

> Not interested in this argument, sorry.

You shouldn't have started it then.

Re: MEGAChat now includes end-to-end encryption

#83
post #74
post #64

Earlier quoted context omitted.

There are plenty of casual users who want the capability to have one-off conversations without worrying about who might be intercepting and storing the conversations, let alone without having to install anything new and try to convince their friends to use it too. This is made with them in mind. I see where you're coming from with the added attack surface argument, though I'd counter that browser sandboxing actually…

If you want to have a one-off conversation without worrying about someone intercepting and storing your conversation, use Google's IM protocol. You won't have to install anything. If you want to protect your communications from the kinds of adversaries who can defeat Google's security, you're talking about a class of adversary that is largely government sponsored, and all of them are likely to be able to compromise a…

all of them are likely to be able to compromise a messaging application that boots from a web page

So this is really the fundamental disagreement. What makes you think that running a WebSigned app in a browser is significantly more exploitable than a native app?

The way I see it, the worst thing that can be said about WebSign is that it breaks the chain of trust — i.e. that first download is implicitly trusted without any validation from a root certificate preloaded on the OS, whereas an app installed through a well designed package manager wouldn't have that problem. However, downloading a regular old executable through HTTPS is no different, and I don't see you calling that out in the same way.

Beyond that issue, I would argue that the browser sandbox offers a more sophisticated and well vetted layer of protection than you would see in just about any native app framework, which leaves XSS as the primary risk (and Cyph has never had a known XSS bug anyway).

Re: MEGAChat now includes end-to-end encryption

#84
post #83
post #74

Earlier quoted context omitted.

If you want to have a one-off conversation without worrying about someone intercepting and storing your conversation, use Google's IM protocol. You won't have to install anything. If you want to protect your communications from the kinds of adversaries who can defeat Google's security, you're talking about a class of adversary that is largely government sponsored, and all of them are likely to be able to compromise a…

all of them are likely to be able to compromise a messaging application that boots from a web page So this is really the fundamental disagreement. What makes you think that running a WebSigned app in a browser is significantly more exploitable than a native app? The way I see it, the worst thing that can be said about WebSign is that it breaks the chain of trust — i.e. that first download is implicitly trusted withou…

Zero is the number of software security researchers who would agree with you that a program booted from a web page via content-controlled Javascript code running in a browser tab is as secure as a native application.

Beyond that, I'm sorry, I'm just not going to go into further details in an HN thread. I don't think many people here think I'm just making stuff up, but in case you're worried about me saying "I told you so" down the road when someone else publishes, here's a fingerprint:

b2b90c80626b1ba036bd87abc0741e1c69d2f6da398018de00b52a3cb9fe2121

Re: MEGAChat now includes end-to-end encryption

#85
post #84
post #83

Earlier quoted context omitted.

all of them are likely to be able to compromise a messaging application that boots from a web page So this is really the fundamental disagreement. What makes you think that running a WebSigned app in a browser is significantly more exploitable than a native app? The way I see it, the worst thing that can be said about WebSign is that it breaks the chain of trust — i.e. that first download is implicitly trusted withou…

Zero is the number of software security researchers who would agree with you that a program booted from a web page via content-controlled Javascript code running in a browser tab is as secure as a native application. Beyond that, I'm sorry, I'm just not going to go into further details in an HN thread. I don't think many people here think I'm just making stuff up, but in case you're worried about me saying "I told yo…

Sure, "zero", except the researchers who actually audited it and concluded exactly that: http://pastebin.com/HcL5bneg

Every reply you've made here seems to have been either an appeal to your own authority or a claim based on a browsing environment circa 2005. You haven't pointed to a single specific flaw in WebSign's architecture, so I can only assume you won't go into further detail because there is no further detail.

This conversation was certainly enlightening (if nothing else, at least on our technical messaging). Thank you for the feedback.

Re: MEGAChat now includes end-to-end encryption

#86
post #85
post #84

Earlier quoted context omitted.

Zero is the number of software security researchers who would agree with you that a program booted from a web page via content-controlled Javascript code running in a browser tab is as secure as a native application. Beyond that, I'm sorry, I'm just not going to go into further details in an HN thread. I don't think many people here think I'm just making stuff up, but in case you're worried about me saying "I told yo…

Sure, "zero", except the researchers who actually audited it and concluded exactly that: http://pastebin.com/HcL5bneg Every reply you've made here seems to have been either an appeal to your own authority or a claim based on a browsing environment circa 2005. You haven't pointed to a single specific flaw in WebSign's architecture, so I can only assume you won't go into further detail because there is no further detai…

That's not what that message says, but maybe you could email your auditors and ask if they'd stand by the assertion you're making that native apps aren't safer for cryptography than browser apps.

As for the rest of it: I'm sorry you feel that way, but I've reached a point in my message-boarding career where, after many, many years of fighting the good (then marginal then tedious then bad) fight, I'm just not going to litigate this issue anymore. What you're doing is now is a bad idea, and for the sake of your users I think you should port to a browser extension (and, eventually, to a native mobile app) as soon as you possibly can. Maybe you can improve your security before your popularity gets out of hand and avoid the fate Telegram seems to be falling into.

When new web standards make browser crypto viable, I'll acknowledge them. Unfortunately, the 10 years since 2005 have made browsers less hospitable to cryptography.

Re: MEGAChat now includes end-to-end encryption

#87
post #82
post #81

Earlier quoted context omitted.

That's what people who supported Cryptocat said. It's also what people who supported Telegram said. Not interested in this argument, sorry.

> That's what people who supported Cryptocat said. It's also what people who supported Telegram said. > Not interested in this argument, sorry. You shouldn't have started it then.

I didn't. I was mentioned upthread.

Re: MEGAChat now includes end-to-end encryption

#88
post #86
post #85

Earlier quoted context omitted.

Sure, "zero", except the researchers who actually audited it and concluded exactly that: http://pastebin.com/HcL5bneg Every reply you've made here seems to have been either an appeal to your own authority or a claim based on a browsing environment circa 2005. You haven't pointed to a single specific flaw in WebSign's architecture, so I can only assume you won't go into further detail because there is no further detai…

That's not what that message says, but maybe you could email your auditors and ask if they'd stand by the assertion you're making that native apps aren't safer for cryptography than browser apps. As for the rest of it: I'm sorry you feel that way, but I've reached a point in my message-boarding career where, after many, many years of fighting the good (then marginal then tedious then bad) fight, I'm just not going to…

> I think you should port to a browser extension

Chrome extensions are HTML5/JS... which wouldn't stand to your own argument.

> Unfortunately, the 10 years since 2005 have made browsers less hospitable to cryptography.

You're saying IE6 and Firefox 1.0 were better for cryptography than our environment today? We've got effective standards like CSP and CSP2 for restricting code execution client side, SRI for validating resources hosted beyond trust boundaries, HPKP and HSTS for ensuring trust on TLS connections, and we have cooperation between major browser vendors to implement patterns like HSTS preloading and even certificate preloading for certain sites such as Twitter, environment sandboxing introduced as early as 2007, and your assertion is that the browser environment now is less hospitable to cryptography than in 2005?

You were right a few comments ago; there's no point debating this any further. I have to do some shoveling anyway.

Re: MEGAChat now includes end-to-end encryption

#89
post #86
post #85

Earlier quoted context omitted.

Sure, "zero", except the researchers who actually audited it and concluded exactly that: http://pastebin.com/HcL5bneg Every reply you've made here seems to have been either an appeal to your own authority or a claim based on a browsing environment circa 2005. You haven't pointed to a single specific flaw in WebSign's architecture, so I can only assume you won't go into further detail because there is no further detai…

That's not what that message says, but maybe you could email your auditors and ask if they'd stand by the assertion you're making that native apps aren't safer for cryptography than browser apps. As for the rest of it: I'm sorry you feel that way, but I've reached a point in my message-boarding career where, after many, many years of fighting the good (then marginal then tedious then bad) fight, I'm just not going to…

I'm just not sure how you expect me to take your position seriously and blindly follow it, when your reaction to the information I've presented is to pretend that there's literally no difference between WebSign/Cyph and something like MEGAChat. I felt that the "HPKP suicide" hack (which is something enabled only by recent Web standards) was a stroke of genius on Cure53's part; in the very least generous interpretation, it obviously still isn't equivalent to the security of a vanilla Web application, which you seem to be suggesting.

As far as Mario's statement, while you're correct that it doesn't explicitly compare WebSign with installing a native app, it was made in the context of a threat model that assumed that level of security. This is why the one WebSign bypass exploit they found[1] was flagged as High — in any other Web app it would simply be a given that the server can serve new code.

re: browser extensions, what WebSign provides is comparable, except without sacrificing the security benefits of the restricted privilege set of a standard Web context. (i.e. A vuln in Cyph wouldn't put more than just your browser tab at risk.)

---

1: This was immediately fixed, and then the HPKP rotation scheme Cure53 came up with was soon added on top of that fix.

Post reply on HN