Secure Messaging Scorecard
eff.org
eff.org
Yeah, nah.
https://news.ycombinator.com/item?id=7518761
EDIT: I get that they're choosing more "user-friendly" and "freely available" applications for featured, however this is really only going to get seen by people who don't mind a bit of fiddling around. ChatSecure + Orbot I see as the most reliable on there, yes you'd stick out like a sore thumb (why are you using Tor?) however privacy-wise, you'll be just fine.
That said, the fact that the page gives bright green happy checkmarks across the board for Cryptocat does become misleading for people who may not know a ton about it.
Sorry to the EFF guys reading this, I understand what you wanted to do however the execution wasn't perfect so we're nitpicking. News.YC crowd is a finicky bunch.
I don't like words like "nefarious".
Getting those scores is a sign that those projects are taking the right approach. Lots of codebases have horrific bugs, including OpenSSL, older versions of the SSL and TLS protocol itself. We believe that focusing the community on the task of moving the best projects forward is more constructive than
Testing the tools that are scoring highest for usability, and doing deeper examinations of their designs and codebases, is going to be a future component of this campaign.
For instance: "Encrypted so the provider can’t read it?" on Skype's messaging just isn't true. If a subpoena was issued to Microsoft for conversation data, it'd be available.
I think it'd be better to stand up what does things right, and for everything else say why you're not listing them as effective. Approach is all well and good, but to an anonymous journalist/source being pursued a groups - approach over execution could be the difference between freedom and imprisonment (or worse).
Our aim with this project is to not give advice about what works "right now", because we aren't convinced there are any secure messaging options right now, especially when the usability dimensions of security are taken seriously.
Instead, what we're trying to do is articulate the things that both large companies and open source projects need to be doing to move in the right direction.
Since this is phase 1 of a multi-part campaign, we're going to take a closer look at the usability and further security properties of tools that are doing well on the Scorecard in subsequent phases.
On Skype, before launch it wasn't clear clear to us whether the NSA's reported Skype intercept capability came from breaking or having Microsoft backdoor the crypto (which would mean they loose the second checkmark) or by having Microsoft hand out a false public key for the other party (which is possible due to the lack of a check mark in the third column). We have an ongoing conversation with Microsoft about this and are reviewing Skype's ratings at the moment.
You should provide a simplified rating or some end user friendly explaination that is hard to ignore. It's confusing and misleading to say something is secure but there's no way to e.g. verify keys.
Skype "encrypted so the provider can't read it" even though MS is a known NSA PRISM partner? Recent disclosures quite strongly suggest otherwise.
Also weird that they didn't sort these options by ranking. it took me a while to realize that they weren't displaying everything ranked by default (or the "winners"). to see that, choose 'all tools' from the drop-down.
Try posting a URL on there and watching an anti-malware scanner ping it sometime. I don't know if they're still doing that, but they definitely were.
My understanding of iMessage is end to end encryption. Where the endpoints are the separate certificates on each of your devices.
I would also recommend categories for what metadata is exposed; if messages are encrypted at rest on your device; cross platform ubiquity.
You should include bitmessage, and i2p-bote.
I am glad that this is only the first step but I do think that you shouldn't have done it alphabetically but rather by score and usability.
There's a weird case around iMessage and any tool that is provided by an OS vendor. I think we need to add a note about this, but in those cases that company could inject malware or a backdoor either in the messaging system or somewhere else in the OS. Since we're trying to tackle one hard problem at a time (secure messaging but not secure operating systems and software distribution) there should be an extra caveat about offerings from OS vendors.
The only tool that gives strong metadata protection right now is Pond, and we aren't listing unusable tools that aren't out of beta yet. We considered but haven't yet included bitmessage for the same reason.
The iMessage issue isn't related to iMessage being developed by the same company that handles the OS. It is that Apple holds the decryption keys for your messages; this is security by policy not security by design. http://blog.cryptographyengineering.com/2013/06/can-apple-re...
What fails the mud puddle test is data stored in iCloud backups.
If you don't use iCloud backups, say goodbye to your I messages because they are only stored on the device.
> 2014-11-04 : Snapchat app has audits from an internal security team.
That being enough for the "yes the app is audited" tick, plus CryptoChat looking to any passer by of this site as being A-OK is really concerning.
This Scorecard is phase 1 of our multi-stage campaign for Secure and Usable Crypto. We believe these criteria are necessary for any strong security tool, though meeting them doesn't guarantee that a system is perfect.
Subsequent phases of the project will focus on usability (which is a huge problem for activists and journalists who try to use encryption), metadata protection, openness and federatability of protocols, and much deeper audits of the design and implementation security of the software that is scoring highest.
I also find it interesting that mumble wasn't mentioned in this secure messaging scorecard, but since this is the first step of a multi-phase project, I imagine the EFF will be updating it.
It's open source, easily self-hostable, and both chat and VOIP are encrypted, vis TLS and OCB-AES respectively. The downside is that it is not end-to-end, and a compromised server would compromise communications, which is why I like to self host on something I've hardened myself as opposed to buying the service from somewhere else.
Also, it can also be pushed over TOR if you want...
I highly encourage anyone who uses teamspeak, ventrillo, etc, to switch to mumble. I use it to keep up with friends and family from all over the world.
EDIT: As in, I'd like to know what the details on each analysis is. And I'd also like this to be more like a living document.
Uploading my contacts.
Even TextSecure does it. I'm still looking for something that gets a deserved perfect score and doesn't go near my contacts.
(Why isn't Telegram featured?)
sigh
Anyway, helpful tip: you can chose "All Tools" instead of "Featured tools" on the top left of the beautiful table