I fear articles like this just make the average joe think "oh, whatsapp == secure" when recent events have proven that's far, far from the truth.
http://arstechnica.com/tech-policy/2015/06/intercepted-whats...
>Last fall, WhatsApp added Mr. Marlinspike’s encryption scheme to text messages between users with Android smartphones, but there is no easy way to verify that the encryption software is actually turned on.
So they're being pretty open about the fact users can't determine if their messages are truly encrypted.
If anyone out there does it, feel free to post your findings to http://imfreedom.org/.
I'd be willing to bet that WhatsApp has some competent programmers, and looks very similar to how Apple's built iMessage. I think everyone is entitled to the most security possible, but unfortunately when you're at the scale of WhatsApp, perfect security would make all that ultra-tantalizing data pretty hard to analyze. They're a business, they have a responsibility to their investors to grow the business, and data right now is a _big_ business.
Whereas with Textsecure. Well it just works...
By modifying your own device? I don't think so.
In the United States even if an artifact or process is protected by trade secrets, reverse-engineering the artifact or process is often lawful as long as it has been legitimately obtained.
[0] https://en.wikipedia.org/wiki/Reverse_engineering#United_Sta...
As far as I can see that article says that reverse engineering is legal in the case that: (1) the EULA doesn't mention it (I've no idea what Whatsapp EULA says - do you?). (2) it is done for the purpose of interoperability. What is being proposed by the GP is in fact not interoperability but security testing.
As I said before I think that the laws on this are stupid. But why worry about this when there is a great FOSS program in the same space?
There's a much easier way. Turn off your phone's cellular connection, but turn on wifi and connect it to a wifi network you control. Then just sniff the packets.
1) add authentication with other users
2) make a public statement about it (believe it or not, that hasn't happened yet. Perhaps it will come when the iOS versions supports it - or perhaps it never will)
3) commit to the new encryption system in their privacy policy (make it at least somewhat legally binding - which could also be used against abusive law enforcement orders)
And then, depending on how silly the eavesdropping is, repeating the same message might cause the same encrypted payload to be transmitted?
Watch the network traffic with Wireshark?
This article is now on the front page of WSJ.com!
Now the undesirable effects have come back and users now have to make a harder choice between a broken website or being another datapoint for someone's analytics.
The talk is not just about this, but more so about the way the world changed from attempted mandatory "controls" upon people to allowing them the "choice." The scope of "bundling" (features added to encourage use) gets larger and larger until you realize that you're living in a corporate panopticon along with everyone else. If you're not paying for it---you're the product---and bundling becomes the method used to keep you providing them with the best product.
Sadly, the march to "Safety Fascism" continues unabated.
What is taking so long, if you don't mind me asking? Is there some sort of Signal 3.0 overhaul planned for all the platforms along with a big launch?
Also, I think you've been quite retreated in the past year or so, I assume so you can focus on working. But I believe you should personally get more involved in promoting your apps (as you do in this piece here). Go on more TV shows, podcasts and so on. Look how much Telegram has grown, not because it's any better than Signal (far from it), but because they've actively promoted themselves and took a more pro-active role in building a community.
More mainstream users need to know that "Skype is not secure, but Signal is" - which reminds me - I hope Signal will eventually get encrypted video-chat support as well, to make it a true alternative to Skype (and of course a desktop app, but I know your team has been working on that).
To monetize the apps have you considered trying to get Signal into enterprise, as a much more secure alternative to what enterprise customers are currently using, and then get paid for support? Or do you believe that would complicate things too much and make the apps worse off in the end?
[0] https://github.com/WhisperSystems/TextSecure/commits/master
For there to be enough users, we need public proclamations of support from Bruce Schneier or and maybe Moxie, celebs like that. Maybe interoperability.
I've been using TextSecure for awhile now even though I only communicate w/ one other person that uses it.
Well, it's kinda a big deal if that was the entire reason one was using it…
I agree with this bit. It seems weird that people with clear requirements for privacy, like doctors, lawyers, insurers etc, remain totally clueless about encryption.
While we might have more personal sympathy / affinity with political activists and nerds, they don't seem to be very good at proliferating encryption technology.
Just in case you're not aware. RedPhone for android does encrypted calling, and TextSecure for android does encrypted messaging, so there doesn't seem to be a reason for Signal on Android aside from the brand unification.
I'm dreaming up a crypto currency where the scare resource is human creativity rather than CPU time. It is a little like key based identity taken through the looking glass. Quick read: http://thenewstack.io/why-art-could-become-currency-in-a-cry...
I asked a similar question of vbuterin the other day. Thanks for any response: https://www.reddit.com/r/ethereum/comments/3ai4pm/the_humans...
>A few years ago, Matthew Green, a cryptographer and professor at Johns Hopkins University, unleashed his students on Mr. Marlinspike’s code. To Prof. Green’s surprise, they didn’t find any errors. He compared the experience to working with a home contractor who made “every single corner perfectly squared.”
...happen?
Though I have to say, whilst I understand the absolute ballache of technical reasons for dropping SMS support, I'm _still_ extremely sad to see it gone :(
Is there much hope for strong privacy and anonymity using smartphones? Even with secure apps, there's the baseband, controlled by the cell provider. Can it be isolated?
What are the chances for open-source hardware?
What are the main pros and cons of iOS and Android?
DocScrutinizer05 says on IRC that neo900 will accept cash by mail and Bitcoin. And "anonymous fulfillment" (on-site pickup, I presume) for wholesale (N>50) orders. Cool. Someone could sell them for cash at conferences, etc.