Live data from Hacker News

How the Textsecure Protocol Works

alexkyte.me

81–87 of 87 posts

Re: How the Textsecure Protocol Works

#81
post #58

Let me paint you idiots a picture. I am Alice. I want to talk to Bob, securely. I call Bob into my Safe Space (we have those now, in C21). I lock the tinfoil. I encover the blankets. I intimately verify that Bob is indeed the Bob we all now and love. Bob and I are ready to communicate and we do so. Enthusiastically. Bob leaves (without even a cuddle!), but I have more messages I want to give to Bob. Bob is too cute t…

> Let me paint you idiots a picture.

> If you can't see it by now then good luck with your life.

> Fuckinghellmykidunderstandsthisbullshit.

Please leave these out of comments on Hacker News, it's simply not OK.

Re: How the Textsecure Protocol Works

#82
post #52

Earlier quoted context omitted.

If you suspect yourself to be a selected recipient (e.g. you're Edward Snowden) I reckon you should compile your own binaries. Or read 'Reflections on Trusting Trust'.

Now you are the selected recipient of modified source code.

Get it from multiple sources, and do a diff.

Re: How the Textsecure Protocol Works

#83
post #66

Earlier quoted context omitted.

Of course tone is relevant. Tone is how one has a civil conversation with another person, even if they disagree.

Ah, thanks for displaying your civility with a down vote, downvoter. Some people are rougher around the edges than others. I thought this place was a sjw heaven but clearly some people want this place to be a monoculture as well.

> Please resist commenting about being downvoted. It never does any good, and it makes boring reading.

https://news.ycombinator.com/newsguidelines.html

Re: How the Textsecure Protocol Works

#84
post #19

This post doesn't explain the protocol all that well. This is a great explainer: https://vimeo.com/117532499 I can't seem to find the PDF of the slides of this talk anymore. These are also very useful for understanding: https://whispersystems.org/blog/advanced-ratcheting/ https://whispersystems.org/blog/private-groups/ https://github.com/trevp/double_ratchet/wiki

PDF of the talk can be found here:

https://deepsec.net/docs/Slides/2014/TextSecure_and_RedPhone...

Re: How the Textsecure Protocol Works

#85
post #81
post #58

Let me paint you idiots a picture. I am Alice. I want to talk to Bob, securely. I call Bob into my Safe Space (we have those now, in C21). I lock the tinfoil. I encover the blankets. I intimately verify that Bob is indeed the Bob we all now and love. Bob and I are ready to communicate and we do so. Enthusiastically. Bob leaves (without even a cuddle!), but I have more messages I want to give to Bob. Bob is too cute t…

> Let me paint you idiots a picture. > If you can't see it by now then good luck with your life. > Fuckinghellmykidunderstandsthisbullshit. Please leave these out of comments on Hacker News, it's simply not OK.

You're absolutely right - this place is not OK and it's shepherding its community down the same toilet as the rest of them.

Re: How the Textsecure Protocol Works

#87
post #57

Earlier quoted context omitted.

So if they implemented a small extra procedure to copy text and send on a side-channel when a flag was set externally, if such a thing was done then this would be obvious to many people despite it being closed source? Aren't these apps developed modularly? Or indeed if it were a patch that could be initiated as forced update at will from the server-side, again that would be clear to "people" based on the client side…

That's not really what "side channel" means. You mean "covert channel", a related but different concept.

I was thinking something like using the SMS channel which, IIUC, was originally for carrying solely control information and ergo is a side-channel; more in the telecoms sense than the crypto sense. Yes, perhaps "covert channel" would be better.

Do you have any response to the substantive point or just quibbles on the semantics.

Post reply on HN