28.05.2023 Views

The-art-of-invisibility-_-the-world’s-most-famous-hacker-teaches-you-how-to-be-safe-in-the-age-of-Bi

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

worthless.

There are three basic “flavors” of text apps:

Those that provide no encryyption at all—meaning that anyyone can

read yyour text messages.

Those that provide encryyption, but not from end to end—meaning that

the communication can be intercepted byy third parties such as the

service provider, which has knowledge of the encryyption keyys.

Those that provide encryyption from end to end—meaning that the

communication can’t be read byy third parties because the keyys are

stored on the individual devices.

Unfortunatelyy the most popular text-messaging apps—like AIM—are

not veryy private. Even Whisper and Secret mayy not be totallyy private.

Whisper is used byy millions and markets itself as anonyymous, but

researchers have poked holes in these claims. Whisper tracks its users,

while the identities of Secret users are sometimes revealed.

Telegram is another messaging app that offers encryyption, and it is

considered a popular alternative to WhatsApp. It runs on Android, iOS, and

Windows devices. Researchers have, however, found an adversaryy can

compromise Telegram servers and get access to critical data. 18 And

researchers have found it easyy to retrieve encryypted Telegram messages,

even after theyy have been deleted from the device. 19

So now that we’ve eliminated some popular choices, what remains?

Plentyy. When yyou’re on the app store or Google Playy, look for apps that

use something called off-the-record messaging, or OTR. It is a higherstandard

end-to-end encryyption protocol used for text messages, and it can

be found in a number of products. 20

Your ideal text message app should also include perfect forward secrecyy

(PFS). Remember that this employys a randomlyy generated session keyy that

is designed to be resilient in the future. That means if one keyy is

compromised, it can’t be used to read yyour future text messages.

There are several apps that use both OTR and PFS.

ChatSecure is a secure text-messaging app that works on both Android

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!