Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Zil
Jun 4, 2011

Satanically Summoned Citrus


pseudorandom name posted:

you can't update the firmware without the PIN, unless Apple really screwed something up or is lying

Lets be honest, it could be both.

Adbot
ADBOT LOVES YOU

FMguru
Sep 10, 2003

peed on;
sexually

ohgodwhat posted:

More like lmao

Midjack
Dec 24, 2007



ohgodwhat posted:

More like lmao

also like lame-o

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Midjack posted:

also like lame-o

Zil posted:

Lets be honest, it could be both.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Soricidus posted:

yes, basically blackberrys were designed to be easy to lock down and manage centrally. they also have pgp and s/mime stuff built into the standard messaging client with an idiot proof user interface so you can handle everything on private servers relatively easily and do things like completely block all non-encrypted email, which is probably attractive to this customer set.

the reality: blackberry started from barely any functionality and everything had to be bolted on later in fragile ways that are easy to break

some marketer in waterloo trying to spin this: easy to lock down! remove features at will!

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i haven't looked at this yet but nadim released a thing

quote:

From: Nadim Kobeissi <nadim@nadim.computer>
Subject: [messaging] Capsule: A Protocol for Secure Collaborative Document Editing
Date: March 7, 2018 at 11:59:59 PST
To: messaging@moderncrypto.org

Dear respected peers,

Today's global society strongly relies on collaborative document editing, which plays an increasingly large role in sensitive workflows. While other collaborative venues, such as secure messaging, have seen secure protocols being standardized and widely implemented, the same cannot be said for collaborative document editing. Popular tools such as Google Docs, Microsoft Office365 and Etherpad are used to collaboratively write reports and other documents which are frequently sensitive and confidential, in spite of the server having the ability to read and modify text undetected.

Capsule is the first formalized and formally verified protocol standard that addresses secure collaborative document editing. Capsule provides confidentiality and integrity on encrypted document data, while also guaranteeing the ephemeral identity of collaborators and preventing the server from adding new collaborators to the document. Capsule also, to an extent, prevents the server from serving different versions of the document being collaborated on.

A proposal of Capsule is available here:

https://eprint.iacr.org/2018/253

In this paper, I provide a full protocol description of Capsule. I also provide formal verification results on the Capsule protocol in the symbolic model. Finally, I present a full software implementation of Capsule, which includes a novel formally verified signing primitive implementation.

As it stands, Capsule is by no means a finalized protocol, and all that is presented in the preprint linked above is preliminary and very open to suggestions.

Capsule is by no means a protocol as involved or innovative as some others, such as the Signal protocol. However, I believe that it is valuable to see such a protocol solidly proposed and formalized, given that its targeted use case is underserved despite its legitimacy.

I welcome your feedback on the current Capsule draft. I enjoy working on this project and hope to make of it a good software soon. Let's discuss it and share our opinions!

Sincerely,

Nadim
Sent from my computer
_____________________________

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
is it all written in JavaScript?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
did he just invent git?

Hexyflexy
Sep 2, 2011

asymptotically approaching one

infernal machines posted:

did he just invent git?

Bringing the blockchain to MS office like a pro.

vOv
Feb 8, 2014

https://twitter.com/0x736A/status/974298906329862149

new thread title?

30 TO 50 FERAL HOG
Mar 2, 2005



fishmech posted:

the reality: blackberry started from barely any functionality and everything had to be bolted on later in fragile ways that are easy to break

some marketer in waterloo trying to spin this: easy to lock down! remove features at will!

lol remember when the B.B. servers went down and the phones because completely and totally unusable because 100% of traffic would go through them and also they shared private keys with the Indian government

Potato Salad
Oct 23, 2014

nobody cares


NEED MORE MILK posted:

lol remember when the B.B. servers went down and the phones because completely and totally unusable because 100% of traffic would go through them and also they shared private keys with the Indian government

Yes! I remember certain agencies being upset about this as well.

post hole digger
Mar 21, 2011


lol

VikingofRock
Aug 24, 2008




vOv posted:

new thread title?

vOv
Feb 8, 2014

I Kill You! Sec Researcher

flakeloaf
Feb 26, 2003

Still better than android clock

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Mods

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Security Fuckup Megathread - v15.1 - Stop!!! I Kill You Researcher

MODS!!!

(i've made them aware)

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

lmao amazing

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

vOv posted:

I Kill You! Sec Researcher

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
me get cash money, i kill you researcher

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

thank u blessed garph

Bulgogi Hoagie
Jun 1, 2012

We
haven't looked into it much but whats the thread opinion on key base encrypted git

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Bulgogi Hoagie posted:

haven't looked into it much but whats the thread opinion on key base encrypted git
it looks like this is just git on top of their encrypted filesystem product, which i think is neat, but people who are smarter than me have some understandable concerns about how exactly it works

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Captain Foo posted:

thank u blessed garph

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

anthonypants posted:

it looks like this is just git on top of their encrypted filesystem product, which i think is neat, but people who are smarter than me have some understandable concerns about how exactly it works

it's not quite that because git makes assumptions about filesystem consistency that don't work on network-shared filesystems like nfs, dropbox, etc.

quote:

Why not just make a bare repo in KBFS?

The Keybase filesystem journals changes and syncs them after writes, kind of like Dropbox. Which means you and another team member could be fighting each other and make a conflicted HEAD, where there'd be 2 copies side by side. Similarly, you shouldn't put git repos in Dropbox.

Keybase's git prevents this by locking.

Shame Boy
Mar 2, 2010

my last experience with keybase.io was me installing their chat client because a friend wanted to try it for chat and having it ask to install a loving kernel extension. then when i said no it left the program in this weird limbo state where it would load the UI but then hard-lock presumably because they never expected anyone to ever say no to that

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

ate all the Oreos posted:

my last experience with keybase.io was me installing their chat client because a friend wanted to try it for chat and having it ask to install a loving kernel extension.

yeah because they bring fuse along for the ride

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Meat Beat Agent posted:

me get cash money, i kill you
researcher
would you like to make sec gently caress
researcher

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Chris Knight posted:

would you like to make sec gently caress
researcher

vOv
Feb 8, 2014

Chris Knight posted:

would you like to make sec gently caress
researcher

post hole digger
Mar 21, 2011

Chris Knight posted:

would you like to make sec gently caress
researcher

heh

Shaggar
Apr 26, 2006

Chris Knight posted:

would you like to make sec gently caress
researcher

Shame Boy
Mar 2, 2010

Cocoa Crispies posted:

yeah because they bring fuse along for the ride

yeah i figured it out after the fact, it was still a very :wtc: moment since at the time at least there really wasn't anything that advertised that it wasn't just a chat app

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

fuse is fine, do some research scrub

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
heh.

https://twitter.com/clickhole/status/975824622670270464

vOv
Feb 8, 2014


i saw the image before the caption/rest of the tweet and was expecting it to be some kind of phish thing

Shame Boy
Mar 2, 2010

Subjunctive posted:

fuse is fine, do some research scrub

i'm aware of what fuse is, it didn't say it was fuse. it was just "ok launching this chat app... oh there's a permission window for installing a kernel extension. oh. ok."

Shame Boy
Mar 2, 2010

also wait i'm positive i already had fuse installed for something else, can you install multiple copies of it or something?

Adbot
ADBOT LOVES YOU

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Chris Knight posted:

would you like to make sec gently caress
researcher

:black101:

  • Locked thread