Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

3/5/2014
09:45 AM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Cryptocat Wins Apple Approval

NSA surveillance and other worldwide events drive interest in secure messaging, and iOS users now have a new option.

Privacy? There's an app for that, and more are on their way. Cryptocat, an open-source app for encrypted online chat sessions, is now available for free through Apple's iOS App Store, after initially being rejected several months ago.

The Electronic Frontier Foundation, through its Coders' Rights Project, provided advice to Crypocat's developers that helped convince Apple to change its mind about the app. EFF attorney Kurt Opsahl in an email declined to provide details about the privileged counsel it provided. "However we are very pleased that Apple included the program in the App Store," he said.

Cryptocat is already available as a web app and an OS X app, and its mobile debut comes as ongoing revelations about the scope of NSA surveillance drive people's desire for countermeasures and dreams of entrepreneurship.

[Make sure to protect all your personal data. See LinkedIn Privacy: 5 Safety Tips.]

Wickr, which aspires to be a more secure version of Snapcat, on Monday said it had closed a deal for $9 million in venture funding. Silent Circle has just begun taking orders for its $629 Blackphone, a privacy-focused smartphone that features a customized version of Android called PrivatOS and a suite of secure communications apps. Last week, Whisper Systems released TextSecure, a free private instant messaging app for Android. The company also makes the RedPhone app for secure calls. Other secure communications software includes SafeSlinger and Off-the-Record Messaging.

It's not just blowback from the NSA documents leaked by Edward Snowden. It's also timing: Among the recent RSA Conference, TrustyCon (organized as a protest to RSA), and RightsCon Silicon Valley, there are a lot of security and privacy events at this time of year.

Nadim Kobeissi, lead developer of Cryptocat, said in an email that past criticism of Cryptocat has been addressed. He emphasized that Cryptocat relies on open, transparent code reviews in conjunction with professional audits.

"We published our codebase three months before the app's release, so that the code could be reviewed by independent enthusiasts and auditors," Kobeissi said. "No product is perfect, but we take every step to make our methodology, protocols, and cryptographic research verifiable by anyone who cares to look, months before the software is out there."

The absence of perfect security was underscored on Tuesday by reports of a cryptography processing flaw in the open-source GnuTLS library that renders hundreds of open-source packages vulnerable. Ars Technica suggested the bug may go back to 2005.

A year ago, Matthew Green, a cryptographer and research professor at Johns Hopkins University, published a blog post that highlighted some of the limits of encryption apps, including Cryptocat. While he found things to admire in each of the apps, he didn't consider any of them secure enough to employ in fighting an oppressive regime. And given what's going on in Ukraine at the moment, that's not a hypothetical use-case.

"The real issue is that they each run on a vulnerable, networked platform," Green wrote. "If I really had to trust my life to a piece of software, I would probably use something much less flashy -- GnuPG, maybe, running on an isolated computer locked in a basement. Then I would probably stay locked in the basement with it."

For truly secure electronic communication, it appears that the only way to win is not to play. Or did you think that a free app could thwart intelligence agencies with budgets in the billions and legal regimes that bend to accommodate their hunger for data? And if it did, torture tends to defeat even the strongest encryption. Risk comes with the territory.

Yet Green backs away from this depressing conclusion, noting that smartphones have already changed the way people interact with government and that encryption apps might just lead the way to truly private communication.

If that were ever to happen, if software flaws and government subversion of encryption standards were eliminated, we'd soon have laws requiring a backdoor.

The NSA leak showed that one rogue insider can do massive damage. Use these three steps to keep your information safe from internal threats. Also in the Stop Data Leaks issue of Dark Reading: Technology is critical, but corporate culture also plays a central role in stopping a big breach. (Free registration required.)

Thomas Claburn has been writing about business and technology since 1996, for publications such as New Architect, PC Computing, InformationWeek, Salon, Wired, and Ziff Davis Smart Business. Before that, he worked in film and television, having earned a not particularly useful ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Li Tan
50%
50%
Li Tan,
User Rank: Apprentice
3/6/2014 | 12:17:25 AM
Good thing for Apple
This is a good thing for Apple - it can put in a plug for the new Cryptocat on iOS. The secure messaging and the also mobile security as a whole is a big concern from end user communities. The approval of Cryptocat will definitely help to boost the strength of iOS in this area.
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7227
PUBLISHED: 2020-01-18
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, ...
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.