Skip to content

Comment on Cryptocat Considered Harmful: The Root Causeparent

Comments

It would be useful to get the opinion of the Crypto Cabal on what is good safe software that is accessible to the general public and deserves to be promoted and well marketed?

Any suggestions?

I'm not a member of any "Crypto Cabal", and I use the term sardonically, directed at the people people who come out of the woodwork to pimp/gratify themselves and their businesses by posting bullshit about crypto, especially on HN (e.g., the "USE BCRYPT USE BCRYPT USE BCRYPT" guy who claimed that the problem with an RSA exponent of 1 was that "1 is a prime number" (?), or ironic articles of the "I JUST LEARNED ABOUT [crypto topic] SO DON'T EVEN THINK ABOUT ENCRYPTION" variety).

My opinion, as someone who is not important, is that most crypto software is bad, and most software that is fun to use has bad crypto. The Silent Circle stuff looks good, as does the Whisper Systems stuff, and I personally use Pidgin + OTR, which is crap from a UI standpoint.

I totally understand the design/UI motivations behind Cryptocat, but IMO Nadim needs to stick with a protocol design and crypto primitives that work, fix any flaws and then leave it alone until he's more comfortable (perhaps he's done that already).

The best general answer to this question is probably "Use Tails: https://tails.boum.org/ ." Especially for activists in Syria/regular users who have a genuine concern for their lives.

(Tails uses Pidgin with the OTR plugin.)

Things that use OpenPGP or libOTR. At the level of an organization where you can run your own CA, X509 might be easier (it's integrated into outlook IIRC).

I don't know what the accessible frontends are and no doubt there's work to be done there, but the basic primitives are a solved problem, and I'm pretty sure a better frontend on top of either would be very welcome.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.