449 karma · joined December 18, 2011
just another secure mobile OS. nothing to see here, move along.
did i mention that you should never store anything of actual import on a phone?
for a real world example of failed uniformity assumptions, see cryptocat.
trying to argue that we need the F-35 or that it will provide any kind of strategic military value is absurd.
this is absolutely spot on, especially the firmware. nobody talks about it and the attack surface is huge.
just to be explicit, hardware backdoors exist as well :)
as you point out, your focus is on the legal nature of improving the encryption. you mention CALEA, which i'm quoting here for clarity
"A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication."
you are right to point out that skype, under the current laws, is not likely to be considered a "telecommunications carrier". however, they do provide a bridge to the PSTN and this may be part of the legal issue. i suspect they are referencing the yet-to-be-public CALEA II, which may very well require services like skype to be preemptively backdoored for the FBI, etc.
i see skype's current backdoor situation and their comments that you cite as more of a PR/damage control dance than anything. none of the companies that participated in PRISM did/can admit their participation. everyone who does cooperate with the intel services is going to concoct some reason they "had" to cooperate, whether it's true or not.
to me, all of this PRISM and CALEA II nonsense is a reminder that unless a software product is open source, you're unlikely to have any kind of guarantee or expectation of privacy.
skype uses "supernodes", i.e. machines with fixed ip addresses, to effect its udp hole-punching to get p2p comms links working. iirc, the architecture of skype is such that supernodes also handle the key exchange (kex) between peers, which is more than a bit dodgy imo.
the kex should occur directly between the two hosts independent of the supernode, but i recall that this has been their architecture for many years, meaning skype can eavesdrop on any chat/call they choose by manipulating the supernodes. the main change that occurred when MS bought skype was that the supernodes were moved from being presumably-arbitrary hosts with fixed ips to hosts controlled directly by MS. since MS controls the nodes where both udp hole-punching _and_ kex occur, they can trivially MITM comms.
i wouldn't be one bit surprised if skype has been owned by intel services for many years. being literally owned by MS only makes this process easier and avoids involving foreign nationals.
i've run some ecommerce sites and this is basic stuff - new payment modules, time to test card processing works properly.
NOTE: i'm supressing a serious rant along your vector.
keep in mind that cryptocat had been audited at least once and they totally missed the completely-busted prng. i am betting you guys will do a better job than nadim et al :)
http://www.libertariannews.org/2011/08/30/bitcoin-fbi-admits...
yeah, that seems like a reasonable application of the word "terrorist" :P
- 1984 - "War is Peace, Ignorance is Strength ,Freedom is Slavery"
- Johann Wolfgang von Goethe - "None are more hopelessly enslaved than those who falsely believe they are free."
i will refrain from citing other examples of hiding behind the veil of complexity since i don't want to "poke the bear" :)
it's only a matter of time before the glass hardware has an attachment that reads your mind so you exert even less effort than currently, e.g. blinking. google will then take that data and sell it to marketers, the USG, and whoever else they can, so everyone knows what you're going to think before you think it. google predictive thinking... so sad.
if i could legally destroy every glass rig that was anywhere near me, i would be a happy person indeed. the unfortunate situation that now arises is a surveillance arms race, wherein it is illegal (in most countries) to undertake destructive or jamming actions against surveillance technology, be it radio or cellular frequency EM waves, a horde of idiots with cameras or the intelligence services that record all internet traffic, including this post. i would rather not participate, but the concept of passive/massive resistance simply will not work against such technology.
i don't want to develop my own countersurveillance to keep the glassholes at bay. however, i and people who care about privacy are left with few options. i would love to see some legit countermeasures for glass.
allowing password-based auth in sshd is plain stupid. _always_ use pubkey auth, it's a 1-line change in /etc/ssh/sshd_config.
the only thing i use is a throwaway gmail address that is mostly a spam magnet.
the best way to keep anything secure as it relates to your phone is to not use it. in fact, keep your phone well away from where you work and have important conversations. there is a reason certain ppl are not allowed to bring their cellphones to work: it's because they're not even remotely secure.
quaid, start the reactor... FREE MARS!
- having a misleading wired article (or several) written about you in no way qualifies you as an expert on cryptography. anyone who has any level of knowledge in the subject knows this guy is a total hack.
- everything that is somewhat correct about his products is due to people who _actually_ know stuff about cryptography telling him "no, no, no, you need to do X". the entirety of the architecture is effectively crowd-sourced. people telling you how to be a good carpenter is no substitute for being a skilled woodworker.
- nadim should stop making crypto products because bad crypto _puts people at risk_. if you make one bad product, i can see chalking it up to "well, at least he's trying". instead, nadim has routinely and repeatedly demonstrated his lack of real domain knowledge.
i suggest nadim make some turd-like web 2.0/3.0 driven product where security doesn't matter. he clearly has the tenacity to code but lacks the intelligence and domain knowledge to make security-related software.
in another few weeks all the pieces will be public and it will be closer to a full implementation, per my interpretation of your use of the word full.
doing it in go and then using cgo where necessary will get you pretty close to C speed.