Cryptocat currently uses public key fingerprints. The project also expects to begin testing Cryptocat on Mozilla's Firefox operating system for mobile phones later this year.Īlso on the technical side, Cryptocat would like to employ the so-called "Socialist Millionaire Protocol" (SMP) within the application, which is a way for two people to confirm each other's identity. The applications will allow multiple people to chat at the same time and also have push notifications and message delivery confirmation amongst other features, Kobeissi wrote. CRYPTOCAT FIREFOX ANDROIDIn May, Cryptocat plans to release mobile applications for the iPhone and Android mobile platforms. "Cryptocat is being built so that anyone can chat on the Internet without being surveilled, even if they're not a computer scientist," Kobeissi wrote. In February, the Cryptocat team proudly announced that Cryptocat had earned a Veracode Level 2 classification and a Security Quality Score of 100/100.Kobeissi wrote in a report outlining Cryptocat's goals that while the project does not use in-depth methods to track usage due to privacy reasons, as many as 8,000 people were using the application daily in December. The incident has also caused embarrassment for the security specialists at Veracode. According to the developers, the bug didn't affect private chats because it only occurred in group chats with more than two participants. The Cryptocat developers have since responded with a post on their development blog, expressly thanking Steve Thomas for his effort. Thomas says that the hole makes it possible to decrypt a seemingly secure, encrypted chat recording in a matter of minutes. Cryptocat can be used as a Browser extension for Chrome, Firefox and Safari. CRYPTOCAT FIREFOX CRACKEDThe idea is to prevent attackers from drawing conclusions about previous or subsequent keys when one key is cracked on a communication channel, so that earlier and later messages continue to be protected. This technique generates new key pairs for every chat to create what is known as Perfect-Forward-Secrecy (PFS). CRYPTOCAT FIREFOX SOFTWAREThe software uses Off-the-Record (OTR) messaging to encrypt users' messages. The expert was especially angered about the bug fix description, saying that the developers made an attempt to cover up their mistake claiming the fix became necessary because of backwards compatibility problems.Ĭryptocat is designed to provide a securely encrypted online chat facility. This meant the private Elliptic Curve Cryptography (ECC) keys would be "ridiculously small" and would present an ideal attack vector for brute force attacks. A function that expected an array of 15-bit integer values was actually handed a string of the digits 0 to 9 with the ASCII value of the digit taking the place of the 15-bit integer value and shrinking the possible values from 2^15 to 10. Thomas says that the vulnerability was triggered by a flaw in the code for converting strings into arrays of integers. On his web site, Steve Thomas has a massive go at the software developers. The security hole affects all versions of the chat software since 2.0, as the hole was only discovered and closed in version 2.0.42. According to security expert Steve Thomas, messages sent via Cryptocat between 17 October 2011 and 15 June 2013 are compromised.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |