How Secure is TextSecure?
eprint.iacr.org
eprint.iacr.org
>In conclusion, TEXTSECURE only achieves deniability theoretically. Content deniability is provided due to our security proof but we can not prove that no delivery request will be recorded at the TEXTSECURE server.
"Your honor, the defendant is clearly not Moxie Marlinspike. She said these things." "Objection! My grandmother can use Axylnotly to forge previous discussion and she is also not Moxie Marlinspike." " ... sustained."
> Date: received 31 Oct 2014, last revised 5 Apr 2016
> This type of score card drastically simplifies the problem domain, and leads one to question what the tradeoffs are when installing an application from the list. While the advocacy of privacy based communication is something we love to see reach a mainstream audience, we believe the scorecard misses many considerations and metrics that are critical to the discussion.
To quote myself:
> The EFF score card is an embarrassment which is essentially equivalent to one of those "comparison table of our competitors" on a SaaS website. That's a good analogy for it, because it uses the same questionable metrics and even more questionable ranking system that one of those tables would use. The score card gives Signal the same ranking as Cryptocat - that's an instant negative result for its usefulness.
Curious, what do you think of the worth of a LibreSSL-style effort to clean up GPG's proven code and build better interfaces for integrating it into other apps? Of course, to be done in parallel with development of things like Signal that will get more adoption.
Here is an older post where the authors of the protocol explain why not OTR: https://whispersystems.org/blog/advanced-ratcheting/
The main takeaway: text messaging, unlike traditional instant messaging, is primarily asynchronous with long-lived sessions, where traditional instant messaging is primarily synchronous with short-lived sessions.