Your Android phone, now with NSA-grade security
venturebeat.com
venturebeat.com
The strength of the encryption is and was never a problem.
One of the biggest hurdles for widespread adoption in the private sector is that encryption is perceived to cause friction between users [...] With that in mind, Vitru has managed to keep friction to a minimum.
Key management is indeed the main problem but the article has nothing to say how they attacked the problem.
Virtru’s Android encryption enables users to control access to email messages and files and can be “revoked” at any time. Users can also set expiration dates for sensitive email.
No, that does not work. Screenshot. Revoking may work within a specific client but to become really successful you will most likely have to open the protocol to alternative clients and that's the definite end of revoking or expiring messages.
I'm guessing the system works by sending the encrypted item out-of-band. Revocation could be done by the key server. Though there's nothing to prevent designing a client that automatically grabbed the key material when an encrypted message was sent.
"…is so easy to install and use that anyone, regardless of technical sophistication or ability can use. There is no need to understand PGP or exchange keys with the people you’re sharing information with."
I get that PGP is hard, and keyex is a huge UX problem, but that's because it breaks immediately as soon as you try to simplify it. In the case of Virtru, they're requiring you to rely on a trusted third-party.
About the only charitable thing that could be said about this is there might be a practical improvement in security, provided the key and document are sent separately.
http://blog.virtru.com/2014/01/virtrus-open-source-strategy/
Assuming they do eventually release these components, are they enough for the software to be trusted? Why wait to release the source anyways? I'm not comfortable (at all) with installing closed-source software developed by "ex-NSA employees".
The way the system is described, you encrypt a file on your device, upload both the key and the file to the cloud, then the receiver downloads both the file and the key.
Look at the diagrams here: https://www.virtru.com/how-virtru-works
The "encryption key storage" is central to how the whole thing works. It's also a dumb idea. The only thing I can think is that it allows a file to be delivered out-of-band, but the inescapable fact is that decryption material is available to at least one other party.
Each email or file has its own unique key, which is stored
in and protected by a keystore in my butt. By default,
the Virtru keystore is used, but advanced users will be
able to operate their own key stores.The number one reason why we allow for symmetric message keys is to allow you to send an encrypted message to anyone, even if they don't have public keys somewhere. Distributing and using private/public keys in a trusted AND easy to use way is a problem we're currently working to solve, and will add as soon as we get that done in a way that doesn't make our software so hard to use that people stop using it.
Now, I'm not saying it's an easy problem; kudos to you for tackling it. It's just that
- if you have the keys to the payload
- if you don't provide open-source client code
then no one can honestly trust your service. Don't forget that what you're primarily doing with is trust.
We're being as aggressive as we can be about getting code up to snuff for open release, and in the mean time if you are interested in checking out our source, please ping me at will@virtru.com. We're working with a few folks in the community and looking for others to help get these out there as soon as possible, particularly or latest release, our android client, which is built on K-9 and we think belongs back in the open community it was built upon.
In the mean time we are wrapping up work on an initial release of our TDF.js code, on the heels of an audit from iSec partners of our broader browser extension code. We believe that when it is released it really ought to come with good docs and Getting Started tutorials. We are supporting a very large number of platforms with a small team and we're trying hard to prioritize right.
-Will
1.) Former NSA analyst does not mean "NSA-grade security."
2.) Didn't the NSA have their most secret documents leaked? I think "NSA-Proof" security would be more impressive.
Which of the two alternatives does this mean? One, proof against all foreign intercepts, 'coz it uses NSA-strong safeguards, or two, all your comms are automagically pwned, 'coz it uses NSA-approved addons?
I could go with either, I just want to know what I'm buyin'.
everyone is trying to cash in the fact that they can offer 'former NSA' employees in hopes that clients think "hey, he knows the stuff NSA does, he will help me protect against it"... which is total bullshit.