Congrats Moxie and team. You guys are doing a great thing for humanity.
Congrats Moxie and team. You guys are doing a great thing for humanity.
As closed-source, I still couldn't recommend WhatsApp above Signal/TextSecure, but this means that the squillions of WhatsApp users out there right now will hopefully get strong protection and probably won't even notice - and that's fantastic.
Makes me wonder if perhaps other clients for the TextSecure protocol are viable, maybe even possibly standardisable (although please let's not start going design-by-committee on it, don't allow any changes that haven't been security-reviewed). A desktop TextSecure client is something I would like to have right now.
Especially curious what happens if you properly plug together TextSecure, a DHT (or two), and a mixnet like Tor. (Are you listening, Project Tox?)
while i trust textsecure, it is hard to trust any mobile OS and mobile hardware.
[1] - http://www.computerworld.com/article/2509604/data-privacy/mi...
All you can do for now is to connect to Google Hangouts with an XMPP client, which doesn't mean much, doesn't work so well and given that Hangouts is explicit in its lack of support for XMPP, we don't know for how long this will last.
Oh well, it's Google's loss, we've moved to Slack where I work instead.
Anyhow, the only real reason to stay separate would be to compete with each other, with the slim chance to push the competition out of the market (at every services' users expense), and I agree how this has come to be a sad reality
Ironically, in May 2013 at Google I/O it was Larry Page that was expressing his dissatisfaction with the state of the industry for the lack of interoperability with messaging, lambasting Microsoft. But then just after Microsoft announced their support of XMPP in Outlook.com, Google announces Hangouts.
I guess that was provided as an excuse for dropping XMPP support. Well, welcome to the club Google, now you're part of the problem.
I wonder if Google is truly phasing it out, or if it's just an issue with the service I'm using.
I don't mind a healthy distrust in governments either, but it's hard to ignore that WhatsApp, Apple and Google are US companies bound to US laws. In other words, while end-to-end cryptography protects you against dragnet surveillance it certainly doesn't solve any of the other, and arguably much bigger, problems we're facing.
When it comes to respect for WhatsApp I'm still undecided. A huge win for WhatsApp is that they actually have a business model, but on the other side they took a decentralised system (XMPP/Jabber) and centralised it.
Effectively what we have here is XMPP/Jabber with TextSecure on top of it instead of XMPP/Jabber with OTR on top of it, which has been around for quite some time now. Maybe that's not terribly impressive but it's great to see big companies join the privacy-by-design camp.
The TextSecure protocol, based on the Axolotl Rachet, is a significant improvement on OTR, both in terms of cryptographic capability and usability.
Without that, your carrier owns you at a bit by bit level in the memory of "your" computer.
But it needs to be stressed that these kind of things are not the magic fix for mobile phone comms that people think they are.
A lot of use cases in our current world involve state owned telecom entities and Joe-Arab-Spring-Six-Pack should not be confused into thinking this solves that problem.
Handset makers and carriers all have strong financial incentives to harden the basebands against hacks because they don't want people unlocking their phones, which was often being done by exploiting bugs in basebands. Also, they need the airwaves to have integrity and mobile protocols are all based on the assumption of trusted endpoints that don't violate the rules. Now that DIY GSM base stations have become a reality, carriers face a nightmare scenario of someone running a buggy or malicoius "tower" that infects basebands of any phones that enters into range and starts them doing some kind of horrible attack against the carrier infrastructure. E.g. you can imagine an extortion attempt that works this way. It's in their best interests for their devices to behave predictably and be controlled only be themselves.
what reason could you possibly have to suspect that the IOMMUs from a company named "intel" are backdoored? :)
http://theinvisiblethings.blogspot.com/2011/05/following-whi...
Why this isn't just a nit is, if you believe (say) VT-d is backdoored, a lack of IVT research projects isn't evidence of the absence of backdoors. Presumably, if the NSA is serious enough to backdoor Intel chipsets, they'll do it in a manner that a couple of independent security researchers can't black-box.
I haven't heard of any process hardening going on though. Do you have a source for that? I want to learn more about it.
By comparison, application-based encryption of messages addresses a bunch of real threats. The NSA is not the only threat; malicious wifi operators, for example.
Malicious GSM operators as well.
"Fake cell towers" are rampant across America and operate without warrants. Thats why the police are trying to hard [0] to protect their existence. There is a new project today announced to track all the IMSI catchers around America: https://www.indiegogo.com/p/1016404
These tend to be used to track locations of people but they can also be used to intercept SMS and mobile internet traffic.
[0] http://www.baltimoresun.com/news/maryland/baltimore-city/bs-...
With an open baseband you could do much more useful and sophisticated firewalling and ACL of your interaction with the cellular network.
As it stands now, you just camp to the strongest signal and do whatever it tells you - including download and run arbitrary java apps to run on your sim card (probably without your knowledge).
Even on top of that, the concept of not trusting your peripherals is a recent one as well. Ideally, all hardware peripherals would have no more permissions than they need; for instance, no ability to DMA except to specific pre-arranged regions. In practice, most systems don't actually set up that level of security.
https://opensource.srlabs.de/projects/mobile-network-assessm...
(scroll down to the IMSI catcher detection table)
- No encryption after using encryption with the same operator before
- Cell is not advertising any neighbor cells
- Receive a silent text message
- No encryption after using encryption with the same operator before
- Cell is not advertising any neighbor cells
How do you get this information in a regular phone?Of course google can install whatever they want on your device if given a NSL including a modified WhatsApp that sends in plaintext straight to the police everything you type but haven't heard of that yet either.
Since Facebook makes money harvesting data wonder if WhatsApp grabs advertising keywords first then sends via textsecure layer.
While there is no doubt you are correct that a baseband attack is possible, it's a much, much harder task for a Telco to get control of your baseband, start poking around in it and reading your private messages via this channel. Has there been any released code that exploits this?
They easily have the technology now to read all your SMS and capture all the data you send. If you can crypt this, you're much better off from a privacy and security perspective than if you don't.
That's what's important about this announcement.
Your BIOS might be spying on your, or your hard disk, or your wifi card, your video card.
This offers good, strong protection for a lot of the attacks your data can be subject to. Not every attack, but the majority.
Moves like this one, though, are fantastic at making mass surveillance much harder, and I applaud them with as many hands as I can borrow.
Maybe it makes sense for non-baseband enabled devices, tablets, phones with baseband chips disabled somehow (physically).
Can you provide examples? Or explain his alleged reasons? I glanced through couple of his posts and failed to see anything on that matter.