10 ms·
Cryptocat Considered Harmful: The Root Cause
- deleted 13y ago[deleted]
- jgg 13y agoI voted you up due to sentiment, and I don't mean to sound like a grumpy member of the Cabal of Crypto Criticizers, but what's the point in Nadim developing the application if he won't respond well to honest peer review and wakes up every day and decides to fuck around with the basic structure of the application, and not only that, but makes fatal flaws when doing so? I'm all for learning and experimentation, but not when some dude from Syria is literally Tweeting you and saying, "Hey, thanks!", which is the point of the article. I think end-point spying is probably bad enough at this point that we really don't need a broken protocol too. I don't really see the point in constantly changing out crypto primitives like he does, and it has introduced major security vulnerabilities in the past. He should find something, stick with it and then get it audited and reviewed, and then I think less people would bitch. I support the goal of making crypto more usable.
- thirsteh 13y agoI think you responded to my comment that I somehow managed to delete, but re-posted here: https://news.ycombinator.com/item?id=6990738 https://news.ycombinator.com/item?id=6990738 I agree with you. I don't think Cryptocat or how the implementation is handled is perfect by any means, but people have been complaining about that for a long time, and we still don't have good alternatives. What I'm saying is that if somebody makes something that is technically sound and is as attractive for regular users, in Syria and elsewhere, then this whole debate becomes relatively moot. If Nadim is as unwilling to cooperate as you're implying (which I don't think is totally true, but I will grant you that the underlying constructions for the group chat component were switched out recklessly and ignorantly), then surely complaining about it in blog posts will be very ineffective.
- jgg 13y agoI don't think he's unwilling to cooperate, and I don't mean to pick on the guy, because he's basically become a whipping boy. I think the reason he reacts so adversely to the criticism is the obvious use of him by bloggers and "crypto pundits" to bolster themselves. It's not constructive, and I don't wish to encourage that. That said, security issues are still security issues, and my tl;dr as someone no one on this site cares about is for Nadim to just stick with a set of crypto primitives and protocol design that work, fix the problems that arise and stay there until he's more confident in what he's doing.
- ErikRogneby 13y agoIt would be useful to get the opinion of the Crypto Cabal on what is good safe software that is accessible to the general public and deserves to be promoted and well marketed? Any suggestions?
- thirsteh 13y agoThe best general answer to this question is probably "Use Tails: https://tails.boum.org/ https://tails.boum.org/ ." Especially for activists in Syria/regular users who have a genuine concern for their lives. (Tails uses Pidgin with the OTR plugin.)
- lmm 13y agoThings that use OpenPGP or libOTR. At the level of an organization where you can run your own CA, X509 might be easier (it's integrated into outlook IIRC). I don't know what the accessible frontends are and no doubt there's work to be done there, but the basic primitives are a solved problem, and I'm pretty sure a better frontend on top of either would be very welcome.
- jgg 13y agoI'm not a member of any "Crypto Cabal", and I use the term sardonically, directed at the people people who come out of the woodwork to pimp/gratify themselves and their businesses by posting bullshit about crypto, especially on HN (e.g., the "USE BCRYPT USE BCRYPT USE BCRYPT" guy who claimed that the problem with an RSA exponent of 1 was that "1 is a prime number" (?), or ironic articles of the "I JUST LEARNED ABOUT [crypto topic] SO DON'T EVEN THINK ABOUT ENCRYPTION" variety). My opinion, as someone who is not important, is that most crypto software is bad, and most software that is fun to use has bad crypto. The Silent Circle stuff looks good, as does the Whisper Systems stuff, and I personally use Pidgin + OTR, which is crap from a UI standpoint. I totally understand the design/UI motivations behind Cryptocat, but IMO Nadim needs to stick with a protocol design and crypto primitives that work, fix any flaws and then leave it alone until he's more comfortable (perhaps he's done that already).
- thirsteh 13y agoSo make something better that people will actually use--then the question of what to use will become a no-brainer. "Just use Foo." The "best" alternative to something like Cryptocat is Pidgin/Adium+OTR plugins, and you can't seriously claim they're as usable (nor are their implementations actually perfect.) If not that, then help to fix whatever issues the popular tools have. (They're open source, after all.) Make formal security proofs, implement them, open source your prototypes, and have them vetted by as many cryptographers as possible (so one or two if you're lucky.) Then figure out how to market your product. By far the hardest aspect of cryptography engineering is getting people to use your software in the first place. It doesn't matter how good you are at crypto if your software is never used. It's very easy to criticize. Much harder to actually make more secure, more usable alternatives. (And, ironically, the people who ought to be doing this the most are much more hesitant to do so since they know of many more subtle ways to make mistakes.)
- Joeboy 13y ago> By far the hardest aspect of cryptography engineering is getting people to use your software in the place. I think perhaps a neglected aspect of the problem is how to turn difficult social / political problems (eg. nobody uses PGP and people think you're a weirdo if you try to persuade them to) into tractable technical problems (the kind cryptographers mostly talk about). I sometimes think it would be preferable to start from a point where everybody had public and private keys and knew how to use them, but the crypto was no better then ROT13, than the current situation where the crypto is pretty good but getting people to use it is nearly impossible. I also think the emotive "bad crypto puts lives at risk" argument only really makes sense if you're talking about crypto for the military or a small number of political activists, who will in any case benefit if their encrypted transmissions are buried among everybody else's. Those people need to be more careful than the rest of us with our more quotidian privacy concerns. I would rather have more bad (but tractable) crypto than great crypto that is used by nobody. Hopefully somebody will persuade me I am wrong about this so I can stop feeling like a crypto heretic.
- zAy0LfpBZLC8mAC 13y agoCryptographic communication tools have a network effect (just like any other communication system), so it's kinda pointless if only the few high-profile activists use it. Also, that would make them stick out, thus reducing their security in some ways. If you can detect the important people by the communications protocol that they are using, you already have the most important part of the information without any need to decrypt anything. Them being buried among bad cryptoraphy most likely won't work - making cryptography indistinguishable is one of the hard parts, so it's one of the properties that bad tools are unlikely to have. Also, a part of the social/political problem is that people tend to not know that the crypto they are using is bad, and political activists tend to not necessarily be cryptography experts either, so how would they know that they are in danger when everyone around them tells them that the broken crypto they are using is the thing to use?
- delinka 13y agoI understand the problem here: don't experiment with crypto with your users' safety in the balance, claiming all the while that they're safe. The sad reality is that none if his users will ever know that there's a problem until it's too late. Slightly off-topic, but this is one of those areas that bugs the hell out of me, and I don't know the solution. On one hand, security and cryptography people tell lawmakers and those in authority that crypto is math, anyone can do it, it's silly to try to regulate it, etc. On the other hand, these same experts tell the "anyones" of the world not to implement their own crypto, mistakes are easy to make, correct implementations are hard ... Here's the kicker for me: If you absolutely should never release another piece of software that might have bugs that could endanger someone's life, then you'll never release another piece of software. You can become the greatest cryptographic implementor on the planet, implement to the current state of the art, and, in a couple years, still have your work completely obliterated by a new attack against a cryptosystem that you are using correctly.
- thirsteh 13y agoI don't think your two examples are contradictory. It is silly to try to regulate export of strong crypto, and it is difficult to get crypto right.
- afreak 13y agoNadim's ego has lead him down a path where he believes that what he is doing is infallible and his critics do not deserve any level of praise--and it is reenforced by those who do not know any better than he does. You can see this in any project or startup, but in the case of Cryptocat, we have a situation where lives are potentially at risk and there is a likelihood that someone has already been compromised due to his actions. The "cutesy" icons and flashy colours that Cryptocat displays are really nothing more than lipstick on a pig.
- deanclatworthy 13y agoAs a passive observer of all cryptography discussions on HN, I can't help but think if security researchers spent as much time on creating usable, secure software as they did in proving that other's implementations were flawed we'd be in a much better place. As a user, I just want to be able to message another person, over the internet without having to worry about setting up plugins or setting up any kind of keys. I want to add them to my friend list, click their name, send them a message and be comfortable in the fact that my communication cannot be intercepted.
- thirsteh 13y agoBut that would require implementing and marketing a significant piece of software. The users who are risking their lives using Horribly Insecure Piece of Software X are important and we should save them.. but they're not that important. /s
- aaronem 13y agoWould you rather use a piece of communications software which purported to be cryptographically secure, but wasn't, and not know it because no security researchers spent any effort attempting to prove that its crypto implementation was flawed?
- thirsteh 13y ago> Would you rather use a piece of communications software which purported to be cryptographically secure ..than communicate in plain text? Yes. Where's the alternative? We can have Cryptocat shut down, which is what the author is suggesting, but then what are we (and by that I really mean people who currently use Cryptocat) going to do?
- zAy0LfpBZLC8mAC 13y agoSo, let me put that a bit more clearly: You would prefer to communicate in plaintext-equivalent where you think nobody can read it even though in fact everybody can over communicating in plaintext where you know everybody can read it?
- rudin 13y agoGuy creates a blog and his first single post is to discourage someone truly trying to innovate in the cryptography space (though admittedly more in usability aspects). After listening to Glen Greenwald at the CCC it was quite clear that cryptography that is easier to use than PGP is really needed in this world (he almost lost the Snowden story due to it). I think that Nadim needs to be encouraged. Sure, point out any flaws but aim for constructive feedback. The points here centre around it "not good enough". This is a bit of a chicken and egg problem and isn't really helpful.
- lmm 13y agoDon't implement your own crypto. Better people than you have tried and failed. Everyone should know this by now. If you can innovate on the usability, that's great, and we really do need that - but build it on top of a well known, peer-reviewed protocol like OpenPGP. It's not like it's even any harder than rolling your own.
- rudin 13y agoDefinitely. I'm really interested in the progress of OpenPGP.js. It could possibly replace a lot of the sketchier parts of Cryptocat.
- daeken 13y agoEven if it does, it still won't help. Crypto in the browser is like playing soccer in a minefield: either you don't move or you lose a leg. Either way, your game is hosed. The issues are, to put it mildly, insurmountable. The environment is simply too toxic to trust. Between standard Web security flaws, timing attacks (what happens when one context can detect the timing of another? Remember, the code is slow, so your resolution doesn't have to be good), inadequate random number generators, an inability to securely manage memory (don't want key materials floating around), etc. I'd rather trust Bob's Discount Car And Certificate Authority than JS crypto.
- thirsteh 13y ago
- abvdasker 13y agoNote that this article simply shits all over Cryptocat without giving any concrete examples: "has had myriad errors in implementation" and "After being berated by dozens, repeatedly, because of the myriad flaws". I kept waiting for Paul to substantiate his criticism or at the very least link to some of the implementation flaws he keeps trumpeting, but he doesn't. Pointing out that Cryptocat has tried multiple encryption schemes isn't really evidence in itself, either. For all I know this guy could be totally right about Cryptocat, but this is absolutely not the way to make this kind of statement. It isn't well-reasoned and it sure as shit isn't informative.
- cwmma 13y agoConsidered Harmful considered harmful, please use the active voice.
- lotsofcows 13y ago"Considered Harmful" is supposed to be humorous, please do not attempt humour on HN.
- lotsofcows 13y agoSee?
- endou 13y agoA nice quote from Phil Zimmerman from a comment in a post by Schneier which was posted in a comment to this post: "I remember a conversation with Brian Snow, a highly placed senior cryptographer with the NSA. He said he would never trust an encryption algorithm designed by someone who had not earned their bones by first spending a lot of time cracking codes. That did make a lot of sense. I observed that practically no one in the commercial world of cryptography qualified under this criterion. "Yes", he said with a self assured smile, "And that makes our job at NSA so much easier." A chilling thought. I didn't qualify either. " https://www.schneier.com/blog/archives/2011/04/schneiers_law.html#c530393 https://www.schneier.com/blog/archives/2011/04/schneiers_law... edit: By the way I think that Jeffrey Paul has a relevant point, I think it deserves to be taken into account. I understand his words can hurt Nadim Kobeissi nevertheless from my point of view they carry no such will.