HNHacker News
TopNewBestAskShowJobs

karlhedderich

5 karma · joined January 8, 2011

submissionscomments
karlhedderich··on Secure Messaging Scorecard
I disagree that the only tool that gives strong metadata protection is pond. i2p-bote, bitmessage, and chatsecure over orbot at least advertise themselves as giving metadata protection by design. Thought I didn't realize bitmessage was in beta still.

The iMessage issue isn't related to iMessage being developed by the same company that handles the OS. It is that Apple holds the decryption keys for your messages; this is security by policy not security by design. http://blog.cryptographyengineering.com/2013/06/can-apple-re...

karlhedderich··on Secure Messaging Scorecard
Last I knew it was strongly suspected that Skype could look at your messages. imessage doesn't pass the mud puddle test indicating apple can look at your messages. Facetime should probably considered suspect but I don't know of any articles that demonstrate how the key exchange is handled. BlackBerry also modified their messaging app to be able to give info to LE. Telegram doesn't have open source server code and uses home rolled crypto. Was telegram even properly audited?

I would also recommend categories for what metadata is exposed; if messages are encrypted at rest on your device; cross platform ubiquity.

You should include bitmessage, and i2p-bote.

I am glad that this is only the first step but I do think that you shouldn't have done it alphabetically but rather by score and usability.