John McAfee releases secure anti-surveillance messaging app ‘Chadder’
chadder.im
chadder.im
- a protocol based off the highly vetted and trusted Off-The-Record protocol
- perfect forward secrecy, a very important thing in cryptography as you can drastically reduce the number of possible attacks in certain scenarios
- real cryptographers doing implementation and review of the software
- a good open source implementation of this cryptography
Don't get me wrong, I have a few irks about TextSecure with regards to the way the open source project is managed (see: their conflicts with F-Droid and such), but I really have to question why anyone would use some piece of crap cranked out for publicity (such as this or Heml.is) when there are solid options available which clearly offer superior security.
- This uses an external service 'scrambls' (https://scrambls.com/) which seems to do per-message symmetric key management. Therefore, the owners of this service can read all your messages.
- The thing which seems to be sent along with the ciphertext is an 'XID' which is sent to scrambls and exchanged for the raw AES message encryption key. There doesn't seem to be any binding to the recipient in this step(?)
- The encryption of messages is AES-CBC with PKCS#5 padding. There is no message integrity, so therefore this provides no confidentiality under CCA2.
In conclusion, this is the sort of thing you should expect from a secure messaging app. (TextSecure excepted.)
In the video, they say that "the key and message can only be read by Sally."
Or look at this one, where they even visualize it: http://siliconangle.com/blog/2014/05/03/the-design-behind-ch...
The architecture of the product features a unique web-based exchange of key transfer capabilities to facilitate completely encrypted messaging.
When people hear us complaining about it, they often think we want to avoid paying money for it. This is false, and a bad impression to give. That is the purpose behind making this distinction.
According to the free software definition [1], it's one of the essential freedoms:
>The freedom to study how the program works, and change it so it does your computing as you wish. Access to the source code is a precondition for this.
Access to compilable code can happen in more ways than fully libre release though.
I think that is what the parent post to yours meant.
Awaiting the inevitable HN thread about how Chadder is flawed.
Remember the thousands of "pixel ad" sites following the Million Dollar Homepage?
Remember the thousands of Flappy Bird clones?
Prepare for more chat apps, because WhatsApp scored big.
Toxic doesn't even begin to describe it, he's the IT world equivalent of a rogue.
[1] http://en.wikipedia.org/wiki/National_security_letter [2] http://en.wikipedia.org/wiki/Patriot_act
If anything this application helps surveillance by filtering out the communication from "regular" communication.
We have had encrypted messaging for ages now. I cannot tell what's new here.
I'd imagine a system that's completely a p2p mesh network. "Oh, hello, peer. I have 17 blocks for delivery on the network." Those 17 blocks might be pieces of messages for said peer; they might be destined for other nodes anywhere in the network; maybe they're noise. And don't forget to hand those blocks off to other nodes as well, because maliciously dumping blocks could be a thing...
The ambiguity in the way the video explained it makes me a bit suspicious.
I guess it's something like:
For messages: AES
Key exchange: RSA
Alice and Bob both generates their own RSA keypair (the server do not have their private keys). Alice generates the AES key to be used with Bob, encrypts it using Bobs public RSA key and then sends it to him.. done
- How is the problem of key distribution solved? How does Bob know that the key is in fact Alices and not Mallorys?
- The scheme you propose does not provide forward secrecy.
- (How) is authentication performed? Are signatures used; if so, are they non-repudiable or deniable?
Secure instant messaging is not a solved problem (at least not in the form of a practical, usable implementation).
Encryption:
* Messages are encrypted with AES 128 CBC
* Random key for each message
* The AES key is sent to the server, and exchanged for some key-id
* They key id is prepended to the message
Decryption: * Split message into key id and encrypted part
* Download key from server
* Decrypt message
Edit: Decompile it to see for yourselfhttps://developer.scrambls.com/bin/view/Main/P4ComponentInte...
Otherwise, I'm going to assume you are still leaky as hell, make mistakes and have not cleaned up your code, etc.
And no, claiming you are 'open source' doesn't cover it (And I Don't even have to refer to Heartbleed here)
[0] http://www.macrumors.com/2014/05/05/ios-7-email-attachment-e...
Sorry if this question sounds ignorant, the details and best practices of encryption are way over my head.
https://developer.scrambls.com/bin/view/Main/P4ComponentInte...
For example: You cannot be sure the links are valid. The javascript- and/or youtube iframe might be modified/malicious.
We are also very excited to announce our partnership
with John Mcafee and Future Tense Central!Also, no iOS?
But I wouldn't touch a security product he offers with a 20 foot pole. Literally I wouldn't even visit the site, let alone hover my mouse over the download link.
And no, not because of McAfee Antivirus, but despite it.