Skip to content

Comment on Cryptocat Considered Harmful: The Root Cause

Comments

As a passive observer of all cryptography discussions on HN, I can't help but think if security researchers spent as much time on creating usable, secure software as they did in proving that other's implementations were flawed we'd be in a much better place.

As a user, I just want to be able to message another person, over the internet without having to worry about setting up plugins or setting up any kind of keys. I want to add them to my friend list, click their name, send them a message and be comfortable in the fact that my communication cannot be intercepted.

As another passive observer, I am grateful for all of the time that security researchers spend on proving that many cryptographic implementations found in the wild are flawed. If they did not do this, all implementations would be closed source ROT13 with a $50k pricetag.

I'm still waiting for simple, usable crypto - but I'm not willing to settle for evidence-free, warm assurances of safety from borderline incompetents in the field while I wait for it.

I can't help but think if security researchers spent as much time on creating usable, secure software as they did in proving that other's implementations were flawed we'd be in a much better place.

Can this comment be part of the HN crypto thread drinking game? It's in every thread x10. I can't help but think if commenters spent as much time learning how to use good crypto as complaining about the time researchers spend picking apart bad crypto, all of their issues with the current implementations would disappear.

I can't help but think if commenters spent as much time learning how to use good crypto as complaining about the time researchers spend picking apart bad crypto, all of their issues with the current implementations would disappear.

Not really, because each commenter here interacts with 10's if not 100's of people who have little to no chance of learning to use good crypto.

Trying to evaluate and attack systems is a vital part of building secure systems. Many of these researchers do work on their own systems (think tor, redphone, ...) while also engaging with the crypto community at large to find flaws and improve methodology.

As a user, I just want to be able to message another person, over the internet without having to worry about setting up plugins or setting up any kind of keys. I want to add them to my friend list, click their name, send them a message and be comfortable in the fact that my communication cannot be intercepted.

The problem isn't that nobody understands that, the problem is that that's a very difficult (arguably impossible) problem to solve.

I thought tptacek's response to my question here was interesting, WRT crypto dick waving:

https://news.ycombinator.com/item?id=5776111

Edit: another thought, looking at the incentives involved:

* If you, as a security guy, spend your time breaking stuff, you win some points for that if you score a 'hit'. If you don't, well no one is really paying attention. Pretty much all systems - even those written by really bright guys like cperciva - have flaws, so if you look enough, you'll probably find some.

* If you write your own system, you attract the attention of all the people out to break it. And eventually they probably will find some problem and write Comic Book Guy style posts about how the system is badly flawed. And your reputation will suffer.

Ironically, tptacek spends a large amount of time criticizing crypto, but a lot of the time it's useful criticism (i.e. actually provides some kind of a solution.)

I have nothing against criticism. If there's a flaw in something, let's talk about it. But I don't care for "I know how to do it better," and nothing more.

tptacek's comments are usually interesting and insightful, and he seems like a good person who does his best to interact in meaningful ways here, rather than simply channeling the Comic Book Guy as is the custom in crypto dick waving forums.

Would you rather use a piece of communications software which purported to be cryptographically secure, but wasn't, and not know it because no security researchers spent any effort attempting to prove that its crypto implementation was flawed?

Would you rather use a piece of communications software which purported to be cryptographically secure

..than communicate in plain text? Yes.

Where's the alternative? We can have Cryptocat shut down, which is what the author is suggesting, but then what are we (and by that I really mean people who currently use Cryptocat) going to do?

So, let me put that a bit more clearly:

You would prefer to communicate in plaintext-equivalent where you think nobody can read it even though in fact everybody can over communicating in plaintext where you know everybody can read it?

I wouldn't prefer that, but I'm also not as convinced that Cryptocat is as "clearly broken" (i.e. plaintext is trivially recoverable) in its current state as a lot of people on here are. Most of the attacks that I've seen so far were against the group chat implementation, which, granted, is significant, but not against the primary component, the OTR chat.

I think it is somewhat naive to believe that any mechanism other than a one-time pad will absolutely keep your communications safe, and that it's a little dangerous to insinuate that Cryptocat leaks information about the plaintext but X or Y doesn't.

Where is the author suggesting that Cryptocat be shut down?

He makes the very valid point that advertising a insecure product as secure to people who need security but don't understand it is very wrong. He's asking that the advertising be corrected.

We're not worrying about your credit card getting ripped off - this software claims to solve life or death problems.

He wants it taken off the app stores.

I don't disagree with the point that you shouldn't pretend, but literally no one is in a position to make absolute promises like that, yet everyone's doing it.

I'm not saying it's okay, but let's keep in mind that they say on their frontpage (http://crypto.cat) that you shouldn't trust it with your life. That's better than most security software marketing.

Yeah, but they're not saying it on the app stores, hence wanting the text changed or the app removed.

I have no answer. I don't think anyone can argue that the research is not valuable, but what would be more valuable is a peer-reviewed piece of software created by experts in this field so we would not even be having this discussion (re: telegram, cryptocat etc.)

OTR is as close to this as you'll get for IM at the moment, and even the most popular implementations like OTR for Pidgin (or Cryptocat!) haven't been vetted very thoroughly (not to mention Pidgin itself has a fairly spotted security track record.)

The people at heml.is are looking at implementing something like TextSecure as an IM, and its interface does look quite attractive, but it's a no-go as long as they're not open source (especially given that none of its authors are cryptographers), and thus can't receive a thorough review. (Actually getting qualified people to perform a review once it's open source is a challenge in itself, but perhaps people will spend more of their energy on that than writing blog posts saying they could do it better.)

But that would require implementing and marketing a significant piece of software. The users who are risking their lives using Horribly Insecure Piece of Software X are important and we should save them.. but they're not that important.

/s

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.