How secure is TextSecure?
moderncrypto.org
moderncrypto.org
Your carrier can install arbitrary code, without your knowledge, on both your baseband and your SIM card, and depending on your phones implementation, have direct (as in DMA) access to your entire application processor and whatever OS and userland is running on it.
There is no way around this. If it's a mobile phone, it cannot possible be secure and cannot in any way be considered your device.
That treats "secure" as a binary condition where something is either 100% secure, or it's just "insecure." It's somewhat like dividing Supreme Court judgments into those that are 9-0 and those that aren't, treating 8-1 decisions the same as 5-4. It's not wrong, it just throws out a lot of useful information.
"Secure" is an analog value for data just like "secure" is an analog value for physical objects. If you have a precious object, locking it up and hiring a security guard to protect it makes it more secure than leaving it on the front seat of your unlocked car. It's not very useful, when discussing various types of safe deposit box locks, to say "a safe deposit box can't possibly be secure since a bank robber can come and steal it." Things can be made more and more secure, but even Fort Knox has vulnerabilities.
I leave my phone on my desk, Bob grabs it while I'm in the bathroom, turns on Unknown Sources, installs an apk from a known URL which implements an accessibility service that forwards all TextView contents over to his nefarious logging servers.
Once he installs this service (rooting and USB connection not required, just physical access to a non-PIN-locked phone and takes about 5-10 seconds to do if you've already posted an apk ready to install to some public url) it will always be running and come up on startup whenever the phone is rebooted and never show me any indication that it is running (unless the service ANRs or crashes or I go to the Accessibility settings page in the OS settings which I am unlikely to do as a user who doesn't require any special accessibility features).
Bob then puts my phone back and I begin to use it unawares. All of my data that is displayed to the UI at all is leaking regardless of how secure the network protocol is.
Take-aways:
If you are an Android user and care about things like secure chat being actually secure, PIN protect your phone or glue the phone to your skin so nobody can install an APK without your knowledge.
If you create an ostensibly secure Android app consider querying AccessibilityManager occasionally to take a look and see if any accessibility services are running and if they are indicate this to the user in some visible fashion that explains the risks, this allows people who have legitimate accessibility issues to use the app but mitigates the possibility of a data leak that the user is completely unaware of. Or alternately use an accessibility delegate on all your TextViews and other leaky widgets and have a setting in your app where when this filtering is disabled it is obvious to the user.
There's a huge difference between "enemy has your device and virtually infinite time to muck with it as he pleases" and "software that can be installed in a matter of seconds with no privilege escalation can subvert the security of nearly every app on your phone".
Are there any good secure messengers out there that truly works cross platform (iOS, Android and Web/Win/OSX)? It's a shame that something like Telegram seems to be the best right now, considering its dodgy security model.
Also, if they were nation-states you probably shouldn't post about it in a public forum either.
I'd only worry if you were a Google competitor using Google Chant/Hangouts. :p
Also, wasn't telegram demonstrated to have awful crypto? Like basically pointless to use from an encryption standpoint?
I'm keeping an eye on the forthcoming Hemlis messenger which should have good crypto and launch on iOS/android and from the demo videos it has an awesome ui. However they're taking forever to launch the thing so who knows when it'll be out. Also it will need to be open sourced and audited before I trust it.
Since it's only on Android I can't use it as the single app for all messaging. I certainly type much faster on my desktop keyboard than I do on my cell phone, so I need something with desktop support too. A lot of my friends also have iOS, which also is an issue.
Telegram's crypto is pretty weird, and potentially insecure - no doubt. However, it's the only messaging app I've found with good clients (superb in fact) on all platforms that has some level of encryption. I don't "need" (although I would certainly prefer) to be protected from targeted attacks, I need to be protected from mass surveillance.
For what it's worth, TextSecure also has delivery receipts now, so the sender can see what's happening with their message.
I recently started using TextSecure on my janky, crappy old Android phone and it is a _dream_. So far it has been strictly better that the native Android text app in every respect. The user experience is so different it's like night and day. Faster, lighter, quicker to load, better at sending messages while I'm in the subway with low signal, lets me keep typing the next text reliably while the old one is starting to send, etc. I could go on and on. I would use it just for the UX alone, even absent crypto.
I'm not in any way affiliated with TextSecure and frankly disagree quite strongly with some of Moxie's politics, but credit where credit is due. +1 very satisfied user.
Also, yeah I am desperately waiting on a secure messaging app that is has good crypto, ios/android, AND desktop support. So far there isn't one that fills all those, so for now I'll settle for good crypto rather than platform support. From what I understand, multiple logins from devices using the same identity is really hard for good crypto? I'm not sure but that'd explain why all the top secure messaging apps don't do it. yet.
Being open source and audited also matters a lot to me.
If you are not using "secret chats", their default chats are not end-to-end encrypted, so are not comparable to TextSecure.
messaging is expected to be rolled into the Signal iOS app quite soon, as I understand it
I've had all sorts of issues with the push messaging causing some crazy infuriating problems... had to disable it on my end and on friends phones too. Also had some oddness where two friends with identical handsets - one couldn't set TextSecure as the incoming SMS client even though the other could...
It's great, I rave about it and try and talk everyone I know into using it, but there are some odd issues occasionally...
I think "basically pointless" is when there's a known vulnerability that renders the encryption pointless. I think Telegram's more like "bad-smelling and while no exact vulnerabilities are known (since no one cared to audit), it's probably dangerous."
Just trying to be fair.
And here's a thorough trashing of their crypto: http://www.cryptofails.com/post/70546720222/telegrams-crypta...
I'm not a cryptographer either, so I can't comment on how accurate that last link is, but I tend to trust moxie, and if he thinks it stinks, well.....
Genuinely interested, never had issues with it so far.
Non-related to TextSecure, I've tried to use GCM to send notifications about faulty servers and found it quite unreliable. It seem to work fine when the phone's on and has a good WiFi connection, but seem to lose messages in real-life conditions. Not to the extent to completely stop working, just a packet loss, though.
I shall watch out for new issues as the iOS version gains functionality.
[2] https://threema.ch/press-files/cryptography_whitepaper.pdf
XMPP+OTR has been supported on major platforms for years (and for decades without OTR). It offers all the features the above Telegram/TextSecure/etc offer, and is descentralized, so you don't rely on some arbitrary third-party.
For any practical security scheme, you do have to make some assumptions about the limitations of your adversary's capabilities. In the extreme case of "attacker has ability to read contents from memory on the end user's machine at will," I'm not aware of any secure cryptographic solution short of memorizing the key and performing all encryption/decryption by hand.
"Secure" just means that no one has figured out how to break it yet, or that you don't care if the people who can break it do so.
But they're insanely hard to implement perfectly.
Pro tip: to use TextSecure and RedPhone with Google Voice, enter your Google Voice number, let the SMS validation time out and then retry the validation by phone call.
Also, I hope in the long run it'll be decentralized like XMPP. I'd prefer to run my own server to make it harder to gather metadata on a large scale.
It's a pity... I'd be willing to pay for an iOS port, if only to be able to push my friend circle to switch away from WhatsApp.
You even seem to be aware of the existance of XMPP, so why do you choose this new, inferior alternative?
TextSecure can use the mobile OS's built in push notifications, which gives you realtime message receipt without killing your battery.
XMPP may be superior when it comes to security/technology but TextSecure is superior when it comes to usability and practicality on mobile devices.