The Coder Who Encrypted Your Texts
wsj.com
wsj.com
Is there much hope for strong privacy and anonymity using smartphones? Even with secure apps, there's the baseband, controlled by the cell provider. Can it be isolated?
What are the chances for open-source hardware?
What are the main pros and cons of iOS and Android?
DocScrutinizer05 says on IRC that neo900 will accept cash by mail and Bitcoin. And "anonymous fulfillment" (on-site pickup, I presume) for wholesale (N>50) orders. Cool. Someone could sell them for cash at conferences, etc.
I'm dreaming up a crypto currency where the scare resource is human creativity rather than CPU time. It is a little like key based identity taken through the looking glass. Quick read: http://thenewstack.io/why-art-could-become-currency-in-a-cry...
I asked a similar question of vbuterin the other day. Thanks for any response: https://www.reddit.com/r/ethereum/comments/3ai4pm/the_humans...
I fear articles like this just make the average joe think "oh, whatsapp == secure" when recent events have proven that's far, far from the truth.
http://arstechnica.com/tech-policy/2015/06/intercepted-whats...
>Last fall, WhatsApp added Mr. Marlinspike’s encryption scheme to text messages between users with Android smartphones, but there is no easy way to verify that the encryption software is actually turned on.
So they're being pretty open about the fact users can't determine if their messages are truly encrypted.
If anyone out there does it, feel free to post your findings to http://imfreedom.org/.
I'd be willing to bet that WhatsApp has some competent programmers, and looks very similar to how Apple's built iMessage. I think everyone is entitled to the most security possible, but unfortunately when you're at the scale of WhatsApp, perfect security would make all that ultra-tantalizing data pretty hard to analyze. They're a business, they have a responsibility to their investors to grow the business, and data right now is a _big_ business.
Whereas with Textsecure. Well it just works...
By modifying your own device? I don't think so.
In the United States even if an artifact or process is protected by trade secrets, reverse-engineering the artifact or process is often lawful as long as it has been legitimately obtained.
[0] https://en.wikipedia.org/wiki/Reverse_engineering#United_Sta...
As far as I can see that article says that reverse engineering is legal in the case that: (1) the EULA doesn't mention it (I've no idea what Whatsapp EULA says - do you?). (2) it is done for the purpose of interoperability. What is being proposed by the GP is in fact not interoperability but security testing.
As I said before I think that the laws on this are stupid. But why worry about this when there is a great FOSS program in the same space?
1) add authentication with other users
2) make a public statement about it (believe it or not, that hasn't happened yet. Perhaps it will come when the iOS versions supports it - or perhaps it never will)
3) commit to the new encryption system in their privacy policy (make it at least somewhat legally binding - which could also be used against abusive law enforcement orders)
There's a much easier way. Turn off your phone's cellular connection, but turn on wifi and connect it to a wifi network you control. Then just sniff the packets.
And then, depending on how silly the eavesdropping is, repeating the same message might cause the same encrypted payload to be transmitted?
Watch the network traffic with Wireshark?
This article is now on the front page of WSJ.com!
Now the undesirable effects have come back and users now have to make a harder choice between a broken website or being another datapoint for someone's analytics.
The talk is not just about this, but more so about the way the world changed from attempted mandatory "controls" upon people to allowing them the "choice." The scope of "bundling" (features added to encourage use) gets larger and larger until you realize that you're living in a corporate panopticon along with everyone else. If you're not paying for it---you're the product---and bundling becomes the method used to keep you providing them with the best product.
Sadly, the march to "Safety Fascism" continues unabated.
What is taking so long, if you don't mind me asking? Is there some sort of Signal 3.0 overhaul planned for all the platforms along with a big launch?
Also, I think you've been quite retreated in the past year or so, I assume so you can focus on working. But I believe you should personally get more involved in promoting your apps (as you do in this piece here). Go on more TV shows, podcasts and so on. Look how much Telegram has grown, not because it's any better than Signal (far from it), but because they've actively promoted themselves and took a more pro-active role in building a community.
More mainstream users need to know that "Skype is not secure, but Signal is" - which reminds me - I hope Signal will eventually get encrypted video-chat support as well, to make it a true alternative to Skype (and of course a desktop app, but I know your team has been working on that).
To monetize the apps have you considered trying to get Signal into enterprise, as a much more secure alternative to what enterprise customers are currently using, and then get paid for support? Or do you believe that would complicate things too much and make the apps worse off in the end?
[0] https://github.com/WhisperSystems/TextSecure/commits/master
I've been using TextSecure for awhile now even though I only communicate w/ one other person that uses it.
Well, it's kinda a big deal if that was the entire reason one was using it…
For there to be enough users, we need public proclamations of support from Bruce Schneier or and maybe Moxie, celebs like that. Maybe interoperability.
I agree with this bit. It seems weird that people with clear requirements for privacy, like doctors, lawyers, insurers etc, remain totally clueless about encryption.
While we might have more personal sympathy / affinity with political activists and nerds, they don't seem to be very good at proliferating encryption technology.
Just in case you're not aware. RedPhone for android does encrypted calling, and TextSecure for android does encrypted messaging, so there doesn't seem to be a reason for Signal on Android aside from the brand unification.
Though I have to say, whilst I understand the absolute ballache of technical reasons for dropping SMS support, I'm _still_ extremely sad to see it gone :(
>A few years ago, Matthew Green, a cryptographer and professor at Johns Hopkins University, unleashed his students on Mr. Marlinspike’s code. To Prof. Green’s surprise, they didn’t find any errors. He compared the experience to working with a home contractor who made “every single corner perfectly squared.”
...happen?
And there we go, highest voted comment on the article: a strawman about child pornography. Think of the keeeds
On the other hand, I wonder how many privacy advocates have never experienced anything awful in that sense.
I'm on the privacy side myself and it's true child touchers are just hearsay for me. I know they exist, I know it happens, but it's not generally at the forefront of my mind when thinking about much of anything really. And I really wonder what I'd think if everytime I thought about policy I also had poor Timmy's story echoing away for all eternity in my head.
And then I wonder for the motivations of the people for whom child touchers are hearsay but are really opposed to privacy. Their motives must include things like drug dealers, terrorists, a belief in their own clean slate, money. It's pretty interesting to think about what goes on behind the scenes of any argument that gains popular traction.
For example, internet blocking of child abuse media (hot topic in Germany a couple of years ago) doesn't help children (who aren't abused 'over the internet' but in real life) because it routes resources away from public education on the matter (such as encouraging victims to speak up), social and health support (so victims that spoke up don't fall into a void) and regular police work (so that the perpetrator gets busted).
I guess child abuse on the internet is a popular topic with policy makers because "protecting children" is an easy way to score points in public and "on the internet" hides the fact that this abuse happens somewhere - and closer to any single person than they may be comfortable with. "internet" became a code word for "somewhere else".
That's a great platform to win an election.
Now, pick any company with > 10000 employees. Just by running the numbers it likely employs a child abuser. You work for such a company? It's likely that one of your coworkers, maybe even somebody you deal with every day, is a child abuser.
That's not a great platform to win an election.
If I had an ulterior motive for arguing against a particular technology, spinning it as "think of the kids" would be something easy and safe to do. Anybody arguing against you could be painted as horrible horrible people who don't think of the kids.
I know more than a few people who were abused as children, but none of them have become think-of-the-children anti-privacy advocates. It's probable that it's a selection effect, since the prior for my knowing someone who disagrees with my politics so deeply well enough to know their abuse history is low. But at the same time, I'd expect to run into at least one person by now.
I think that most people with first-hand experience around child abuse are probably not anti-privacy advocates. At that level it becomes clear that the real problems are social conventions that adults can exploit (family and professional relationships with defined subordinate roles for children), enabling them to commit abuse. Having secure communications doesn't help with this much. In fact, if a child thought they could tell someone about abuse without their abuser knowing, it might be helpful.
I think that the anti-privacy activists are actually people who are rather far away from the societal evils they claim to oppose privacy to protect against. The people who have opinions about the NSA reading email or encrypted messaging tend not to be personally affected by social instability from terrorism, or the drug war, just by basic socioeconomics. Child molestation is probably a similar, far-off evil. It's enough for these people that these systems could hide evildoing, and because of that they clearly need to be compromised so that the state and legitimate community forces can hunt evildoers. I think the real motive is simply a naive belief in the goodwill of those community forces.
This in turn can be explained by a naive moral system, where it is moral to obey rules. This is the 3rd or 4th level of the Kohlberg moral development scale, and the level Kohlberg conjectured most people remain at during their lives. Background: https://en.wikipedia.org/wiki/Lawrence_Kohlberg%27s_stages_o...
In some countries you can be killed for your political views. You can also be killed for what you are -- gay, for example.
Anyway, in most cases the person who said that is a complete hypocrite, like a politician/businessman who wants to ban encryption to be able to spy on their competitors, not to "protect children".
That's even a higher level of blindness. Those people understand how the world works. They know that hackings, theft, revolutions, and coups d'etat exist, and those who once were righteous, legal and legitimate may be prosecuted.
What if there were a revolution and the new government decided that now being a sports fan were illegal? That new government may have access to apparently innocent communications where people discussed sports events. Communications that were legally intercepted and innocent in one scenario may be life-threatening if laws change.
That's why we need encryption, that's why all person-to-person communications must be private (we can discuss the transparency degree for governments communications), and that's why governments must find some other way of fighting crime than just exposing everybody naked to make it easier to pick the bad apples.
Sorry for the rant, but encryption is saving lives of gays, illegitimately prosecuted politicians and such. Banning it with lame excuses is short-sighted and may backfire some day.
The Making of a Conservative Environmentalist, by Gordon K. Durnil, at p. 43
http://www.iupress.indiana.edu/product_info.php?products_id=...
https://firstlook.org/theintercept/2014/02/24/jtrig-manipula...
It's a perfect demonstration of the fundamental insecurity of the web thus far. When an insecure communication mode (HTTP) is the default and perfectly ok most of the time, the browser has no idea when you are supposed to be operating on a secure channel (HTTPS) but have been tricked into downgrading by a man in the middle attack.
I can't prove it but I believe his work is a significant factor behind the shift towards deprecating HTTP in favor of HTTPS all the time. That is the only real solution.
Agree about the sentiment, but there are some ways to help this. The server can for instance tell the client to always require https:
https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
Doesn't help if the client hasn't yet connected to the right server at least once, though.
Half of me is really happy every time I see Signal getting more popular. The other half is more like OH GOD THE STAKES ARE HIGHER NOW WHAT IF I MADE AN EXPLOITABLE MISTAKE BETTER RE-READ SOME CODE.
But seriously, you should read the code. It's there, open for anyone to audit after all. Maybe start somewhere random in the guts [1][2][3] and check for things like "ereh 2# roodkcab"?
1: https://github.com/WhisperSystems/Signal-iOS/blob/master/Sig...
2: https://github.com/WhisperSystems/Signal-iOS/blob/master/Sig...
3: https://github.com/WhisperSystems/Signal-iOS/blob/master/Sig...
You can watch it here: https://vimeo.com/15351476
> President Barack Obama called [protected-messaging apps] “a problem.”
but
> Encrypted messaging was viewed [by the U.S. State Department] as a way for dissidents to get around repressive regimes. With help from Mr. Schuler, Radio Free Asia’s Open Technology Fund, which is funded by the government and has a relationship with the State Department, granted Mr. Marlinspike more than $1.3 million between 2013 and 2014, according to the fund’s website.
Here's the thing that Moxie recognizes, that many other programs don't (in any domain):
He says he wants to build simple, “frictionless”
apps, adopting a Silicon Valley buzzword for
“easy to use.”I recommend against such apps and platforms for anything other than stopping the riff raff. That's what I use them for. I pointed out the difference between secure code and secure systems in this [1] writeup. Shared much of my framework for analyzing or designing-in security in the process. The TCB of most solutions today is ridiculous: people are building on foundations of quicksand. There's only a few exceptions I've seen such as GenodeOS (architecturally) or Markus Ottela's Tinfoil Chat. Markus has been unusually alert to our concerns and updated his app appropriately even for covert, channel suppression. Quick question: which of the many crypto apps on the market can deliver a covert channel analysis to you at app and system level? Answer: few to none despite it's importance over decades with a rediscovery in past 5+ years in mainstream security.
Strong security is hard. Moxie seems awesome as a coder and good to great in both crypto and OPSEC. Thing is, his offerings break the decades old rule of having a strong TCB. Just like most of the rest. It's why they're usually bypassed or broken by strong attackers. Gotta do the whole thing with concern for each aspect of the system. TFC is a clever cheat on that even more than my MILS scheme with a KVM and a highly-assured guard. If you don't cheat around it, you better do it right or your users will suffer the consequences. Those trying to contain vulnerabilities of mainstream OS's and components with any success are expending literally hundreds of thousands of dollars worth of labor per year. It's why I push for clean-slate, hardware and software platforms like DARPA and NSF have been funding recently (eg SAFE, CHERI processors). Alternatives using COTS tech are pretty complex and most users will probably fail to secure them to be honest.
[1] https://www.schneier.com/blog/archives/2013/01/essay_on_fbi-...
You can also negotiate source from one of the separation kernel vendors, compile it on target of your choice, and port L4Linux (user-mode Linux) to it to keep legacy apps. CHERI processor and CheriBSD are open source. EROS source was published and could be extended. JX Operating System has almost everything under JVM's safety protections with relatively small TCB. Cool tools like Softbound and Astree knock out bugs in what's left.
There's many tools to start with to get smaller, strong TCB's. They're just the only one's the open-source community doesn't work on. Tiny, tiny set of exceptions. People not wanting to worry about it can just build on Tinfoil Chat: largely eliminated TCB with clever use of data diodes and physical separation. A Moxie-coded version of that portable to arbitrary embedded systems could be made NSA-proof. So, there's options for anyone wanting to get started.
Meanwhile, I'll keep using GPG on airgapped machines with diverse hardware and interface protection. Only thing that works per Snowden leaks. For now...
I admire your work Moxie, but sadly we stand on different sides of war on general purpose computing. I can't help but be saddened that "the other side" got someone so talented and dedicated.
Edit: although, of course you have to trust Github or whoever if you install from source.
https://f-droid.org/forums/topic/redphone-and-textsecure/#po...
The best thing that one can say is that it is well indicated by the UI whether the message will be secure. Blue for encrypted. Green for clear. I've managed to explain this to some very tech unsavy people.
TextSecure has delivery receipts so you can see when your messages aren't being delivered, and there's a web-based unregistration flow on the Open Whisper Systems website so that users can unregister their numbers if they've uninstalled.
The TextSecure app could ping your server with a "I am still here" message if it goes a week without sending any messages. Don't hear from it for two weeks? Unregister it.
Would this not work?
https://github.com/Spark-Innovations/SC4
Strong encryption that runs in a browser. Recently completed its first security audit.
Cheers.
Not being rude (yep), but you did.
Cool project though.
Also wanted to share one of the most provocative moxie-isms I've heard in recent years from him, in reference to WL:
"What about the truth has helped you?"
Installed it, used it, uninstalled it.
Years later, a contact asks me that he "saw me in TextSecure", sent me a message.
Obviously, I didn't get that message.
Why - o why - was/is TextSecure pretending to not know about metadata when it does? Why could that happen? Moxie?
You can unregister here: https://whispersystems.org/textsecure/unregister
Well, _maybe_ you can. I spent several days six months ago trying to unregister, and finally just accepted the fact that TextSecure will never let me go. Oh well.
I hope text secure gets usernames one day that you can associate with phone numbers & emails.
The web-browser version is a good development, it shows that desktop and multi-device versions are on the way.
I hadn't herd of their new app Signal. Has anyone tried it? I'm really interested in hearing anyone's experience using it.
BTW, I ended up installing Telegram ...and it may be mere co-incidence, but I started noticing some weird things happening that I've never seen before. I connect to the internet exclusively via tethering to my phone and while tethered I started seeing messages in Firefox from my desktop machine giving warnings that were something like "Could not establish secure connection because the server supports a higher version of TLS". My guess is that it was some sort of MITM attack... and I was possibly targeted due to the traffic to Telegram servers.
One other thing regarding Telegram: I really don't like that it reads my contact list and uploads it to their server to check if my contacts have a Telegram account. I've blocked the permission for now.
It has a pretty UI though, so most people seem to think it's great.
But your point stands - there's no UI to indicate if it was secure or not and the code isn't open so you can't know for sure.
Entropy of a rot13 message would be much lower than that of a properly encrypted channel. High entropy is not proof of "meaningful encryption", mind you, since a compressed rot13 or plaintext message would have high entropy too.
(Deterministic|reproducible) (compilation|builds) are a fairly recent endeavor; though they're not yet common they are technically feasible. The two efforts I'm aware of are Debian[1] and Chromium[2], though I'm not sure what state they're currently in. From their site, Chromium appears to include Android builds.
There may be Android-specific concerts w.r.t the JVM's JIT, but if you can't trust the onboard runtime, you've already lost IMO.
--
[1] https://wiki.debian.org/ReproducibleBuilds
[2] https://www.chromium.org/developers/testing/isolated-testing...
[3] https://f-droid.org/wiki/page/Deterministic,_Reproducible_Bu...
https://github.com/bitcoin/bitcoin/blob/master/doc/gitian-bu...
https://trac.torproject.org/projects/tor/wiki/doc/TorBrowser...
https://blog.torproject.org/blog/deterministic-builds-part-t...
Moxie: "I'd like to avoid distributing APKs outside of the Play Store"
Why give a single entity the power to push a malicious update anytime?
Edit: In contrast, the F-Droid builds were built and signed by F-Droid, so they could at any time include any code they wanted. Whom do you trust more, the developer or some alternate app store?
And I certainly trust an open source project much more than a US company.
What it boils down to is that with the Play store, you can be sure that you're not getting malicious updates from some intermediary, as each developer signs their own APKs, and Google doesn't have the keys. Whereas if f-droid is compromised, all applications they build are compromised. That's a much greater risk.