Categories
Security Community Security Industry Software Security

The Practical Limitations of End-to-End Encryption

Internet discussions about end-to-end encryption are plagued by misunderstandings, misinformation, and some people totally missing the point. Of course, people being wrong on the Internet isn’t exactly news. Yesterday, a story in The Atlantic alleged that the Trump Administration accidentally added their editor, Jeffrey Goldberg, to a Signal group chat discussing a military action in […]

Categories
Cryptography Open Source Software Security

Reviewing the Cryptography Used by Signal

Last year, I urged furries to stop using Telegram because it doesn’t actually provide them with any of the privacy guarantees they think it gives them. Instead of improving Telegram’s cryptography to be actually secure, the CEO started spreading misleading bullshit about Signal®. Since then, I’ve been flooded with people asking me about various other […]

Categories
Cryptography Security Industry Vulnerability

Session Round 2

Last week, I wrote a blog post succinctly titled, Don’t Use Session. Two interesting things have happened since I published that blog: A few people expressed uncertainty about what I wrote about using Pollard’s rho to attack Session’s design (for which, I offered to write a proof of concept and report back with results–even negative […]

Categories
Cryptography Software Security Vulnerability

Don’t Use Session (Signal Fork)

Last year, I outlined the specific requirements that an app needs to have in order for me to consider it a Signal competitor. Afterwards, I had several people ask me what I think of a Signal fork called Session. My answer then is the same thing I’ll say today: Don’t use Session. The main reason […]

Categories
Software Security

What Does It Mean To Be A Signal Competitor?

A lot of recent (and upcoming) blog posts I’ve written, and Fediverse discussions I’ve participated in, have been about the security of communication products. My criticism of these products is simply that, from a cryptography and security perspective, they’re not a real competitor to Signal. For all its other faults, Signal sets the bar for […]

Categories
Open Source Security Community The Furry Fandom

It’s Time for Furries to Stop Using Telegram

I have been a begrudging user of Telegram for years simply because that’s what all the other furries use, despite their cryptography being legendarily bad. When I signed up, I held my nose and expressed my discontent at Telegram by selecting a username that’s a dig at MTProto’s inherent insecurity against chosen ciphertext attacks: IND_CCA3_Insecure. […]