Secure Communication Comes To Android
An anonymous reader writes "Forbes is reporting that Moxie Marlinspike and Stuart Anderson's startup, Whisper Systems, has released a public beta of two Android applications that provide encrypted call and SMS capabilities for your Android phone. In the wake of recent GSM attacks, it'll be interesting to see if smartphones end up providing a platform that fundamentally changes the security we can expect from mobile communication."
Just like encrypted email! Everyone uses that...
While interesting, these apps aren't that useful because the other caller would have to be using the same software for it to work which limits it to just a few people using Android with these apps.
Taxation is legalized theft, no more, no less.
However, the site claims "we will be making the source available for download and inspection shortly."
Now everybody's mom can call them to dinner without fear of being overheard by certain Three Letter Agencies.
Faster! Faster! Faster would be better!
What I would like to see is a PGP/gpg utility for Android. The closest I can get to this is cross-compiling a statically linked gpg binary for ARM and running that in a terminal.
We'll know it's at least OK if the FBI and CIA start lobbying congress to outlaw it.
We'll know it's pretty good if the NSA starts lobbying congress to outlaw it.
The government is absolutely convinced that law enforcement will come to a screeching halt if people can communicate casually without being subject to eavesdropping. This despite the courts' general distaste for such evidence (people rarely speak candidly in phone conversations regarding criminal enterprises and therefore establishing context and the meaning of codewords becomes a prosecutorial hurdle), and the paucity of successful prosecutions built primarily on the strength of intercepts.
So we've had cryptography treated as a munition. And clipper. And CALEA.
Of course, if the keys are on a server somewhere they can always just subpoena them.
Moxie Marlinspike, there's that guy again! Wish I had a recognizable name like him.
it just reminds me that I really need to start speaking in Klingon more frequently.
the beta...be advised its "US Only" at this time apparently.
Good people go to bed earlier.
It's a VOIP app that encrypts the audio. Except the fact that the protocol itself is documented this is not materially different from skype which is also encrypted and has governments apparently scrambling to crack.
A truly revolutionary app would encrypt the phone's mobile call audio.
Skype provides encrypted calls and SMS for how many years now? Oh, this is from Forbes...
... these apps aren't that useful because the other caller would have to be using the same software for it to work ...
From TFA:
Looks to me like the product uses defacto-standard encrypted communication tools and integrates them with the phonebook to make their use automatic when calling a contact with whom you can have an encrypted conversation.
So it looks to me like your encrypted communications wouldn't be limited to people using the same android app. You could talk to anybody using the same underlying "standard" scheme.
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
Well, I hate to break it to you, but more than a few people are of the opinion that people in the US and companies should start paying for their impact on the climate, i.e., a carbon tax. Oh, and with that little hiccup in the Gulf they want companies to pay for their potential environmental impact as well. This would be a pre-emptive strike against coal and oil.
Today, that would mean $10 a gallon gasoline and similarly doubling or tripling the cost of coal.
I suspect it will be a difficult measure to pass, but it is very likely to do so in the near future. Certainly Obama is on the side of a carbon tax.
Considering we haven't built a big power plant in decades and are on the edges of running out of electric power, I don't see this getting any cheaper anytime soon either. There are proposals to build new nuclear plants, but they will likely sit for years and years as the environmental battles go on and on. Even if we pushed the environmentalists out of the way it would be 10 years before a large plant came online.
I keep hearing about building new transmission lines to improve the grid? Where? Maybe in the middle of Montana or in Death Valley. I know anyone proposing building such a thing near a populated area is just being stupid - every such proposal lately has been shot down. This is why they are thinking of building a new transmission line through a lake because there are no homes at the bottom of the lake.
We are likely to see rationing of electricity within the next few years. Transportation is going to get a lot more expensive and this will push the price of everything up. It might make cheap stuff from China impractical to ship to the US which would be a net benefit, but it will also make farm goods from the state next door much more expensive.
There doesn't seem to be too many details on their site yet. I am wondering if both parties establish a connection with the Whisper Systems server and make the connection that way? Is this end to end encryption? Is the key exchange end to end or with their server? I didn't think that a mobile phone could receive in incoming data connection without a special account.
1) Encryption = hidden writing 2) Whisper = Popular UK chocolate bar, now withdrawn 3) Whisper Systems (anag) Sweetish Mrs Spy
IBM doesn't play chess with the Universe.
It won't be long until people try to light shoes on fire on cross-Atlantic flights or attempt something on a plane landing in, oh, say, Detroit or something. All because people have something to hide ...
The Luddites were ahead of their time.
Secure communications seems to be the often cited reason for the popularity of Blackberrys among corporates and politicians. If Andriod is able to pull this off, Blackberry's image of a cult device are numbered.
It won't be secure unless the hardware, software and distribution are controlled, tracked and audited. Prove there isn't a hidden API in the RF modem that will dump RAM and the keys on command.
Since it's going out as a VOIP call, why not route it via TOR? Yes, it would likely slow down the talking a bit (great, I could finally take notes while still keeping up with the conversation), but it would make it that much more difficult to track down the caller and/or recipient. Might also work for the SMS if it's using an Internet-based route instead of the actual cell system SMS.
I hope this comment is well received... I could have moderated instead!
Persecutors will be violated!
There are several encryption programs for Nokia's Symbian phones that work over GSM, but they don't look terribly compatible even amongst one another, which has presumably stymied adoption.
These two Android apps are compatible with Zfone, which is SIP not GSM. So they should work with the commercial Zfone clients for Windows Mobile and Symbian, which covers the vast majority of smartphones outside the U.S.
I've found no Zfone port for the iPhone or BlackBerry but they're bit players outside the U.S. Maemo support has sadly not yet happened, but presumably once the MeeGo platform stabilizes.
The Christian religion has been and still is the principal enemy of moral progress in the world. -- Bertrand Russell
Is it just me, or is Moxie Marlinspike one heck of a unique name? It sounds very fitting for some character on a television show.
Encrypted voice is US only, so that's no good for the rest of the world. Also, searching for TextSecure on Market doesn't yield any results on my Android 1.5 device (although the FAQ claims it works on all versions of Android), though 2.2 is fine. Sending encrypted texts to myself didn't work either, it says "Bad encrypted message..." but that might just be me doing something wrong.
Plus we can look at the impact done by availability of Zfone/ZRTP (this new encrypted VoIP standard from Phil Zimmermann) for Symbian smartphones (half of all smartphones)
That is also the case with this application.
The secure voice communication *is* done with ZRTP.
The secure texting is done with Off-the-record (already widely used in Adium, Pidgin and the likes).
Oh, nobody was aware of its availability? Exactly...
The more these (standard) technologies are deployed, the more they will get used.
As an example, Adium is a rather popular multi-system chat software for Mac OS (based on the same libpurple of pidgin fame) has Off-the-record (the same system as used by this software for SMS), and thus Off-the-record is starting to get some usage.
"Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
In fact, the texting part uses Off-the-record, which is available on lots of software, including libpurple-based like Pidgin (as a plugin) and Adium (out of the box).
So if you configured an account able to receive SMS (like a SIMPLE or Skype account) on these software, it already works.
And as the webOS chat module is libpurple-based it might not by that much difficult to bolt OtR on Palm Pre (some hobyist have successfully ported other libpurple plugins onto the Pre).
"Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
I'm interested in seeing how the key exchange is handled. After all, you can have a great encryption algorithm but if your implementation sucks, it won't do you any good.
For texting the implementation is Off-the-Record, which is already used in several other softwares (the libpurple-based Pidgin and Adium, for instance). The details of this are here.
Granted, the hurdle there would be things like losing the phone, getting new hardware, etc, but it's still interesting to think about.
Read OtR's website and their arguments about "Deniability" and "Perfect forward secrecy". Some of the problems are addressed in the way OtR works (as opposed to older encryption system such as pidgin-encryption).
"Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
I've been using it on my android devices since I first got a G1. Hell I even used it before then on a bog standard landline phone...
*dial number*
*ring ring*
"Hello?"
"Hi it's Chris, the Satsuma is flying without wings beyond the crust of the BIG APPLE pie."
"Got ya"
Sorted.
Nobody mentioned rob gongrijps cryptophone yet. It uses regular cellphone calls. Instead of voip. You both need to have that phone tough.