ISIS Has a Smartphone App
fortune.com
fortune.com
Well, there's your obvious solution. Get a copy of the APK, wrap it with some spyware, then propagate the bugged version. If ISIS won't host the source or can't provide an "official" outlet to grab it, you've got no way of knowing whether your version is legit or not.
Who'd have thought the paradigms of shady Russian download sites could one day save the world?
It reminds me of a time when I wanted to get in touch with an HN user... they had their pgp key in their user page... I tried sending the email but it didn't work (formatting issues). Finally I reached this user and asked what was up with it... and he responded by saying, "Oh, noone in the past 10 years has made use of this!" And this is a pretty smart security guy.
I think there are very, very few people who actually take the trouble of verifying checksums and everything. I used to do it /sometimes/ years ago, but it gets to be a hassle pretty quickly and you start taking shortcuts everywhere. A lot of us sort of plan to start doing it, but never actually do it. Kind of like exercising or eating healthy or whatever. :)
Anyway, as for this news about ISIS having their own encrypted chat app - I'm happy to hear it. If they made it on their own, it's bound to have a good dozen holes that NSA will have no trouble poking through. :)
It's very hard to think someone would get to the trouble of creating and using a secure chat application, but then fail to secure its distribution.
I've tested many applications which claim to be secure, designed for security/privacy sensitive tasks, yet are very easy to compromise (simple OWASP top 10 stuff).
Even if the app developers are great and know their stuff, I can still see them slipping up on the distribution. It's normally handled for most developers and is outside the realm of any secure development guidelines they might be following.
If both you and I have an shared app, then we have some shared data and protocols we can use to protect our communications and maintain security, but when you download an app you do not yet have any protection unless that protection is provided by an app store (and such app store protections disappear at the first court order).
Bootstrapping security over insecure channels against nation state threats is close to impossible, maintaining security you have already achieved over a brief window of time is still hard but achieve given existing technologies. I see no evidence ISIS is capable of doing either. As further evidence observe that the US just blew up their super secret cash reserve.
Obviously, the problem is that it is not being used this narrowly and that the power to do a global sweep is a negatively skewed power imbalance.
That said, I wonder who Is going to fund the A round.
If these were drug dealers, though, and not terrorists, HN would be in an uproar.
https://www.lawfareblog.com/what-ben-franklin-really-said
And maybe it doesn't matter so much what Franklin was actually trying to say because the quotation means so much to us in terms of the tension between government power and individual liberties. But I do think it is worth remembering what he was actually trying to say because the actual context is much more sensitive to the problems of real governance than the flip quotation's use is, often.
http://www.npr.org/2015/03/02/390245038/ben-franklins-famous...
>Far from being a pro-privacy quotation, if anything, it's a pro-taxation and pro-defense spending quotation.
>It is a quotation that defends the authority of a legislature to govern in the interests of collective security.
And since we're talking about mass surveillance... I guess carpet bombing?
EDIT For example the mere knowledge of surveillance changes how people interact. This has a chilling effect upon speech that is not compatible with a robust democracy.
Mainly, a dragnet gathering intelligence on the entire citizen population is scary and terrible. Sigint targeting pseudo-state terrorists? Who has a problem with that?
1. it is ineffective compared with other techniques,
2. it is government graft to favored contractors,
3. mass surveillance databases and collection points provide an excellent target for foreign intelligence agencies and others,
4. it is harmful to privacy and liberty,
5. it is rife for government abuse and blackmail,
6. it undermines the rule of law.
I have yet to see anyone argue against lawful and warranted targeted surveillance of known terrorists. I claim that none of the above objections hold in the targeted surveillance case.
Logical isn't it? At least according to our lovely politicians.
(The first paragraph is sarcasm by the way.)
Nothing like rolling your own encryption.
What are the chances it was created by one of the intelligence agencies?
I came to the comment section to say that exact same thing. If I were one of those intelligence agencies it would be tempting to use the information right away but for it to be truly effective, you'd need to let it propagate pretty far. What a field day for intelligence agencies even if wasn't planned by them -- just one thing to bust and they have everything.
Is this story even serious?
Using modern smart phones for "business" at all doesn't seem like a good idea if you are in the cross hairs of a modern military force.
It will encourage potential criminals to communicate through a system that's just a honey trap, instead of using other more secure options.
What are the chances if it is encrypted that they didn't actually roll their own encryption but used an open source implementation like PGP and made a wrapper around it? No reason to assume they're entirely dumb until the app has been dis-assembled and proven to be buggy (though I'd not make such a proof public, just let them continue to use it).
This is a silly question for the Android side (and possibly the iOS side as well). That would be a monumental effort that would seem easily thwarted by simply installing your own version of the OS.
Similarly car manufacturers should stop making models that are used as getaway vehicles for bank robberies...
It sounds silly now I put this like that doesn't it.
This is exactly what jailbreaking fixes. By default, iOS does not allow you to install apps that are not published in the App Store.
At least the article does not mention "chat" at all. More like a news app for propaganda videos.
Just imagine all the side channels they have access to if they get access to the cell network. Doesn't really matter if messages are encrypted on the wire if all phones in a certain area is backdoored through a trusted network.
It's not hard to locate a cell tower from a safe distance.
Here's the real story, the app is a mediocre app that you can download from an archive.org link from a news website supporting ISIS, I don't have time to try the app but I assume that it get RSS from the said website (one of those enter RSS link here and we give you an app probably). Well by a website I mean something.wordpress.com, yeah that's real hard to shut down I know...
Would be interesting to know how good the fighting parties are with that...
This is another potential vulnerability. If the app does not check a good signature, then it may be vulnerable to malicious update delivery.
There is very very little knowledge of Arabic language (with slang and such) in western intelligence agencies. As far as I now, there is less than 2,500 Americans are studying Arabic at colleges across the country right now. And 80% of them will be kicked out from country by "Trumps" as terrorists :-)
http://news.investors.com/ibd-editorials/091213-670830-cia-j...