TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How secure is TextSecure?

92 点作者 laex超过 10 年前

8 条评论

rsync超过 10 年前
TextSecure cannot be any more secure than the intentionally backdoored systems that they run on.<p>Your carrier can install arbitrary code, without your knowledge, on <i>both</i> your baseband and your SIM card, and depending on your phones implementation, have direct (as in DMA) access to your entire application processor and whatever OS and userland is running on it.<p>There is no way around this. If it&#x27;s a mobile phone, it cannot possible be secure and cannot in any way be considered <i>your</i> device.
评论 #8575968 未加载
评论 #8574700 未加载
georgemcbay超过 10 年前
Haven&#x27;t looked at it in a while but when I did previously it was prone to the nearly universal Android issue of leaking data through AccessibilityService, which is basically this:<p>I leave my phone on my desk, Bob grabs it while I&#x27;m in the bathroom, turns on Unknown Sources, installs an apk from a known URL which implements an accessibility service that forwards all TextView contents over to his nefarious logging servers.<p>Once he installs this service (rooting and USB connection not required, just physical access to a non-PIN-locked phone and takes about 5-10 seconds to do if you&#x27;ve already posted an apk ready to install to some public url) it will always be running and come up on startup whenever the phone is rebooted and never show me any indication that it is running (unless the service ANRs or crashes or I go to the Accessibility settings page in the OS settings which I am unlikely to do as a user who doesn&#x27;t require any special accessibility features).<p>Bob then puts my phone back and I begin to use it unawares. All of my data that is displayed to the UI at all is leaking regardless of how secure the network protocol is.<p>Take-aways:<p>If you are an Android user and care about things like secure chat being actually secure, PIN protect your phone or glue the phone to your skin so nobody can install an APK without your knowledge.<p>If you create an ostensibly secure Android app consider querying AccessibilityManager occasionally to take a look and see if any accessibility services are running and if they are indicate this to the user in some visible fashion that explains the risks, this allows people who have legitimate accessibility issues to use the app but mitigates the possibility of a data leak that the user is completely unaware of. Or alternately use an accessibility delegate on all your TextViews and other leaky widgets and have a setting in your app where when this filtering is disabled it is obvious to the user.
评论 #8574879 未加载
评论 #8574750 未加载
kristofferR超过 10 年前
A few friends of mine really really tried to switch from Hangouts to TextSecure, but we couldn&#x27;t do it - it was just too painful, complicated and buggy. We&#x27;re using Telegram now and it&#x27;s at least way better than Hangouts and TextSecure on the user experience, even though it&#x27;s less secure than TextSecure.<p>Are there any good secure messengers out there that truly works cross platform (iOS, Android and Web&#x2F;Win&#x2F;OSX)? It&#x27;s a shame that something like Telegram seems to be the best right now, considering its dodgy security model.
评论 #8573245 未加载
评论 #8572158 未加载
评论 #8572144 未加载
评论 #8573534 未加载
评论 #8575130 未加载
评论 #8572120 未加载
评论 #8573129 未加载
评论 #8573500 未加载
评论 #8572304 未加载
Tepix超过 10 年前
Right now, the most insecure aspect of TextSecure is that it&#x27;s not yet available on iOS. Can&#x27;t wait!<p>Also, I hope in the long run it&#x27;ll be decentralized like XMPP. I&#x27;d prefer to run my own server to make it harder to gather metadata on a large scale.
评论 #8572109 未加载
评论 #8575126 未加载
ll1t超过 10 年前
I&#x27;m one of the authors of &quot;How secure is TextSecure?&quot;. Here is my take on the paper and the developers&#x27; comments: <a href="https://medium.com/@ll1t/re-how-secure-is-textsecure-cd0ff0f2fcfb" rel="nofollow">https:&#x2F;&#x2F;medium.com&#x2F;@ll1t&#x2F;re-how-secure-is-textsecure-cd0ff0f...</a>
lmedinas超过 10 年前
Got to love Simpsons analogy in the text.
smnrchrds超过 10 年前
How does TextSecure do group chat?
评论 #8572137 未加载
manuw超过 10 年前
Never had problems with Secure text. I use it every day.