TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Testing a new encrypted messaging app's extraordinary claims

199 pointsby crnkovicabout 2 years ago

18 comments

cyclotron3kabout 2 years ago
This is my absolute favourite kind of post on HN. It's got everything; intrigue, mystery, scandal and of course heavy on the technical side too. All packaged up in a compelling narrative.
评论 #35899108 未加载
评论 #35901688 未加载
jazzyjacksonabout 2 years ago
There is software that lives up to these claims, it&#x27;s Tinfoil Chat. The article is correct about the necessary trade-offs: due to peer to peer transport (onion hidden service 2 onion hidden service) both ends of the conversation have to be online -- it at least spools the message waiting for the recipient to appear.<p>For hole punching and signaling that has to be done by third party, well, the third party is TOR<p>TFC then goes on to break out the encryption and decryption machines from the network and passes messaging over opto-couplers to prevent your keys from getting exfiltrated. Qubes qrexec could similarly isolate the components.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;maqp&#x2F;tfc">https:&#x2F;&#x2F;github.com&#x2F;maqp&#x2F;tfc</a>
评论 #35898231 未加载
anaganiskabout 2 years ago
My goodness what are they even planning to patent? Seald SDK? Ract native? Firestone? RSA? The app does nothing, LOL.
评论 #35900618 未加载
评论 #35899926 未加载
评论 #35899957 未加载
randyrandabout 2 years ago
IMO you should consider putting Converso in the title of your blog post so that it shows up when people Google, as a warning.<p>I just checked and your blog post does not come up in the results for Converso.
评论 #35931608 未加载
评论 #35943486 未加载
haser92about 2 years ago
A quick search after the CEO turns out, the man is a genius: &quot;Tanner Haas, who is an M.I.T. drop out&quot; was a human health specialist in 2020: <a href="https:&#x2F;&#x2F;londondailypost.com&#x2F;this-denver-based-startup-aims-to-create-a-new-category-in-human-health&#x2F;" rel="nofollow">https:&#x2F;&#x2F;londondailypost.com&#x2F;this-denver-based-startup-aims-t...</a> ...now he is a crypto expert.
评论 #35916724 未加载
kotaKatabout 2 years ago
&gt; 2023-05-05: Converso asks: &quot;May we know what you do and where you are located? Thank you.&quot;<p>What are you, a cop?
评论 #35902994 未加载
deepserketabout 2 years ago
How incompetent you have to be to ask &quot;How were you able to decompile the source code of the app&quot; after reading this post?
r0xzabout 2 years ago
&gt; 2023-05-05: Converso asks: &quot;How were you able to decompile the source code of the app...?&quot;<p>Seriously? What the fish?!
tailspin2019about 2 years ago
This is so incredibly bad. I’m stunned.<p>Great investigative blog post!<p>Tldr; Do not under any circumstances use or recommend “Converso”.
评论 #35899949 未加载
apollo_mojaveabout 2 years ago
Amazing.<p>Have you by chance looked at the new update? Not that anyone should ever use this app in the first place, but I&#x27;m curious whether the massive vulnerability you discovered was fixed.
评论 #35901371 未加载
ementallyabout 2 years ago
This was an article about the app [0].<p>&quot;Man Creates Messaging App FBI Can&#x27;t Crack and Anyone Can Download, Stopped at Airport Days Later&quot;<p>I would just use SimpleX tbh [1]<p>[0]<a href="https:&#x2F;&#x2F;www.westernjournal.com&#x2F;man-creates-messaging-app-fbi-cant-crack-anyone-can-download-stopped-airport-days-later&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.westernjournal.com&#x2F;man-creates-messaging-app-fbi...</a><p>[1] <a href="https:&#x2F;&#x2F;simplex.chat" rel="nofollow">https:&#x2F;&#x2F;simplex.chat</a>
评论 #35908164 未加载
aboringusernameabout 2 years ago
It&#x27;s actually kind of sad to see people <i>actually</i> using this and believing in the claims being made. And this is all supported by Google who, frankly, should be denying service to what <i>should</i> be considered spyware. I mean, I swear this type of app used to be considered spyware...<p>It seems these days if your data ends up on a server that&#x27;s A-ok! With all the talk on HN about the &quot;GDPR&quot; it sure seems like an absolute failure - where&#x27;s the QC from Google looking at the code and proactively doing something about the real, potential harm that can come from this? It really seems if you want to harvest user data you can whip together an app that looks and feels okay, but behind the scenes is designed to do nothing but collect your data for whatever nefarious purpose the developer has in mind - and this is all 100% legal and the chances are whoever was involved will not even get so much as a fine!<p>Now there&#x27;s an app that openly collects user data and is publishing it as a matter of public record, consequences be damned.<p>Android and Google need to take responsibility here and use Play Protect to treat the app as harmful and to better shield users.<p>This is an excellent write-up and investigation which is something Google should be doing to expose the dangers of their own platforms - hacking together a few API&#x27;s&#x2F;SDK&#x27;s to mass harvest user data is absolutely not okay. Frankly, they should be legally mandated to review these apps in depth, and be provided full, unobfuscated source code, along with a detailed network-map of all URL&#x27;s the app accesses, API keys etc and should approve (similar to Apple) before Android allows it to be used. If you install it outside of the app-store a very strong warning should be in place to let users know of potential spy&#x2F;malware<p>I also discovered this app is actually on the play store [1]! And the app data safety says &quot;No data shared with third parties Learn more about how developers declare sharing&quot;. It&#x27;s an absolute JOKE this is not being enforced by Google at all. Shame on them.<p>I believe Mozilla did an investigation and found most apps are outright LYING about their &quot;data safety&quot; so that feature is beyond useless when Google doesn&#x27;t actively moderate it.<p>[1]: <a href="https:&#x2F;&#x2F;play.google.com&#x2F;store&#x2F;apps&#x2F;details?id=com.conversoapp.android">https:&#x2F;&#x2F;play.google.com&#x2F;store&#x2F;apps&#x2F;details?id=com.conversoap...</a>
ssss11about 2 years ago
Wow what a read. Best read I’ve had in months.
评论 #35901330 未加载
urbandw311erabout 2 years ago
I wonder if there might be grounds for any users to sue based on the publishing of their personal data online and misrepresentation of the product and its security features.
评论 #35901394 未加载
randyrandabout 2 years ago
This is so embarrassing. How can they even attempt to exist after this?<p>This big question — who is paying to develop this terrible app and why? Do they know it’s terrible?
egberts1about 2 years ago
Love these articles such as this OP where the concept is ripped apart and identified as snake-oil.<p>Good job, keep it up.
tortoise_inabout 2 years ago
You should use conversations. I guess it&#x27;s best and open-source also. Now getting some major overhaul
Michelangelo11about 2 years ago
You are doing God&#x27;s work, sir.