using defective crypto products is much riskier than not using any crypto at all and exercising caution. cryptocat has always seemed a poorly disguised honeypot to me.
using defective crypto products is much riskier than not using any crypto at all and exercising caution. cryptocat has always seemed a poorly disguised honeypot to me.
I am trying to protect myself and my open source project, which, by the way, has been audited countless times and has progressed greatly towards security. If you have a problem with me, then call me up and discuss it instead of stressing me out even more when I just discovered that the government is building a case against me.
If you don't like my work, file a bug report. Check out our documentation. Review our OTR implementation. Submit a pull request. Hack some code. Just don't say hurtful and untrue things like that in public. You can do better.
That being said, I think it's a cool project and it seems to be pissing off all the right people, so keep it up. And I'm not a lawyer but I don't think that the gov't has a case against you (or am I missing something). In fact, it would appear that this might be warrantless wiretapping so you might have a case against them, but I'm not sure if that is something you want to pursue.
this is so spot on. secure comms have no place in a web browser, which is a complex beast with a large set of underlying dependencies. webkit vulnerabilities leading to comms being blown is a crappy architecture.
people who care about comms use a standalone client and a separate server. if you care about the integrity of the server, you run some disk crypto, DDR3 memory, secure it physically, etc.
That is not the case. DDR3 memory will not help you.
Especially if you're bit-flipping sensitive stuff, there's probably a good hope for protection from recovery at normal temperature after what, 30-60 seconds? So reset is an issue, but "keep sensitive things in RAM vs. on disk" is still a reasonable security precaution.
CPU registers are the safest place against this attack (hence stuff like TRESOR where AES keys are held in CPU registers), but are by necessity limited (especially on x86; SPARC was better, and some of the new extensions to x86 help (SSE, etc.)
Most of this has been mitigated to some extent by periodic inversion of sensitive strings in main memory (keys, usually) -- this has been implemented in ~all crypto libraries.
SRAM's huge advantage is you can clear it faster than DRAM, but that doesn't help if you can somehow prevent the clearing from happening.
This is the Hushmail attack, and it seems like Cryptocat is vulnerable to it.
I swear upon my father's grave I will never do something so dishonest and evil towards everyone who has supported Cryptocat, the most meaningful thing I have made with my life.
1. I'm not a lawyer, but I'd be surprised if this were legal.
Some people are fanatics who will never believe. Perhaps there wasn't enough hacking in terminals with falling green letters or he doesn't think crypto software can possibly be easy for non-security professionals.
Again, you are doing the right thing. I'm only sorry the only thing I can give you is my support.
you are clearly very talented with marketing yourself and the project, so cryptocat getting lots of media coverage led to an essentially crowdsourced design for cryptocat 2, very similar to mega. sure enough, this design has held up relatively well and gotten through audits without too many serious issues. as someone who cares a lot about secure comms, i have seen and continue to see no reason to use cryptocat.
i find it particularly ridiculous that a supposed proponent of free speech suggest i am not entitled to my (negative) opinion of your project. i see no point in filing bug reports for software i will never use. i believe in people doing their own homework, it is not my job to improve your project.
if i assume that your govt troubles are indeed legitimate, there are a couple things that seem inconsistent to me:
- you seem very concerned about the negative ramifications of angering your local govt, and all this is linked to (1) your dev work and (2) your prominence in the media. if you are so truly concerned about govt action against you, why are you publicizing the harrassment you have experienced? it only serves to promote your dev work and elevate your media presence, which i would expect to further aggravate your local govt.
- the govt likely knows that actions like this, properly publicized, only lead to an increase in the reach and use of your product, in direct contradiction to your suggestion that they don't want to have your product circulate. it seems that "cui bono" in the context of your story is that you and your project directly benefit by getting lots of publicity.
i found it a bit difficult to fish out details on the ciphers and modes you use with cryptocat 2, which doesn't exactly inspire confidence. i am not a fan of using a stream cipher (AES-CTR) to protect non-streaming comms due to the nonce re-use issues your audit found. ssh using AES-CTR makes sense to me, an IM protocol, not so much.
Cryptocat has been fairly well reviewed by a number of fairly smart people. While flaws have certainly been found, they've mostly been addressed, AFAIK.
"Snake oil" has been a popular term to throw around ever since the original PGP user's guide, but simply labeling something "snake oil" without any actual proof is a dangerous thing to do (especially when it's an open source product, and you should be able to point to any defects specifically).
Edit: I realize the term 'snake oil' predates PGP, I was referring to the crypto community's penchant for it.
What aspect seems "fantastic" to you? Have you yourself been involved in activism?
The whole thing sounds like a bad b-movie or someone playing a practical joke, rather than a genuine attempt.
Then again, who knows, idiots manage to get hired everywhere.
Do you mean trailing people and surveillance?