Email or username:

Password:

Forgot your password?
45 comments
schratze

@AgathaSorceress I know you're not supposed to attribute to malice what can be explained with incompetence, but

is this a honeypot

it probably isn't, it's probably just your average pile of techbros trying to make money with a few buzzwords and the least amount of work possible

Agatha (gpnvq: VISION3 500T)

@schratze the scary part is allegedly some Important Politicians are recommending this app

schratze

@AgathaSorceress I mean, what's the current going rate for an average politician

Charlotte 🦝 θΔ

@schratze @AgathaSorceress They make very specific claims that are ostensibly not true. Writing the app as it exists in the article is incompetence, marketing it as “more secure than signal” is malice

Be

@schratze @AgathaSorceress Evidently, there's no practical difference between an intentionally constructed honeypot and a pile of techbros trying to make money with a few buzzwords and the last amount of work possible.

Normal :jo_2: :v_enby:

@AgathaSorceress

> Unfortunately, Converso is not open source and their website is totally silent on cryptographic primitives and protocols

Oh boy *straps in*

Normal :jo_2: :v_enby:

@AgathaSorceress i want to comment on every one of these turns but there are so many I'll spam you

What the fuck

I'm not even done reading

Normal :jo_2: :v_enby:

@AgathaSorceress okay so they're basically just lying

Wow

Very nice

Normal :jo_2: :v_enby:

@AgathaSorceress

> Forward secrecy? This doesn't exist.

Smh cancel culture strikes again, forward secrecy is cancelled 😔

Normal :jo_2: :v_enby:

@AgathaSorceress why they fuck are they asking 5 dollars a month for an app that supposedly doesn't use servers

Normal :jo_2: :v_enby:

@AgathaSorceress

> Looks like I accidentally breached Converso's user database. The users collection, which is open to the internet and publicly accessible, contains the registration details for every Converso user.

oh my FUCKING GOD

how can you fail this hard

just how

holy-

Normal :jo_2: :v_enby:

@AgathaSorceress

> Phone numbers, registration timestamps, and the identifiers of groups they're in (i.e. who is talking to who).

*chokes*

Normal :jo_2: :v_enby:

@AgathaSorceress

> selfDestruct: <time-to-live>, // optional

this HAS to be a joke

Normal :jo_2: :v_enby:

@AgathaSorceress

> So private keys are being backed up to Seald's servers, encrypted with user passwords.

(Passwords are user IDs)

@julialuna I swear to god I was just joking, holy fuck, what the fuck

Normal :jo_2: :v_enby:

@AgathaSorceress @julialuna

> "How were you able to decompile the source code of the app and what do you think should be done to protect against that in the future?"

*tired sigh*

Normal :jo_2: :v_enby: replied to Normal :jo_2: :v_enby:

@AgathaSorceress @julialuna

> "May we know what you do and where you are located? Thank you."

mmmyes, mob boss tactics, or simply classist corporate "are you worth our time with your status" brainworm

Normal :jo_2: :v_enby: replied to Normal :jo_2: :v_enby:

@AgathaSorceress @julialuna

> "The vulnerability with Firebase rules have been patched and you are welcome to test it out. The other vulnerability of preset decryption keys has been implemented on our side, we are only waiting to get new credentials so that existing users will be reauthenticated. However, all existing messages sent with the old decryption keys are protected by firebase rules so they still cannot be read by outside parties."

...I, what?

"We have closed the door"

...okay, have you fixed the vulnerabilities? Have you nuked your app and started over? Is this just a "oh shit this must go away" manoeuvre?

Honestly this doesn't astonish me, this gets me super angry, because these fuckers are getting away with it by patching their largest hole while saying that fixed the thousands of leaks in their Swiss cheese ship

I'm just tired, what the fuck

@AgathaSorceress @julialuna

> "The vulnerability with Firebase rules have been patched and you are welcome to test it out. The other vulnerability of preset decryption keys has been implemented on our side, we are only waiting to get new credentials so that existing users will be reauthenticated. However, all existing messages sent with the old decryption keys are protected by firebase rules so they still cannot be read by outside parties."

Normal :jo_2: :v_enby: replied to Normal :jo_2: :v_enby:

@AgathaSorceress @julialuna honestly after reading this I'm just so fucking tired

This app gets away with 0 scrutiny while it fails every security practice while doing a backflip, and matrix gets condemned to hell when E2EE is a little weaker than assumed

(And even then, people are working hard to fix that weakness right now, while this app just hides their mistakes)

Jesus fucking Christ, it doesn't even compare, even matrix's security is a thousand times better than this glorified piece of shit, while it gets dumped because it's not perfect enough. Meanwhile this goes through and is recommended to a lot of people through misleading advertisement tactics

I love Capitalism and FOSS culture (not)

@AgathaSorceress @julialuna honestly after reading this I'm just so fucking tired

This app gets away with 0 scrutiny while it fails every security practice while doing a backflip, and matrix gets condemned to hell when E2EE is a little weaker than assumed

(And even then, people are working hard to fix that weakness right now, while this app just hides their mistakes)

Hugo 雨果

@AgathaSorceress This starts of bad but turns into a horror story, I can't believe how bad it is. And their first reaction was "how do we obfuscate this so nobody else figures it out" instead of actually aspiring to implement security.

Do you think they asked your job/location with an intent of hiring your or with and intent of trying to sue you in some stupid way?

Jacob Christian Munch-Andersen

@AgathaSorceress No way it is actually fixed. The least intricate hole to break the whole thing might be slightly more intricate now, but you can't code like that and end up with just one way of getting in.

Lykrast

@AgathaSorceress what the fuck how does that kept getting worse as the article went along?

Joshua Barretto

@AgathaSorceress Oh my god, everything about this makes me want to scream and cry at the same time.

lena

@AgathaSorceress what a joke ahahahahah "May we know what you do and where you are located? Thank you."

Jeff the Alien
@AgathaSorceress

From the blog:
"A quick look at Seald's homepage answers many questions. Seald is a drop-in SDK for app developers to integrate end-to-end encryption 'into any app in minutes'."

Oh my gawd I am on the floor...!!
Barktic Fox :therian:

@AgathaSorceress i figured I was in for a ride when you put that screenshot from their About page touting transparency near the top of your article, but great googly moogly that escalated quickly.

Jennifer Johnson

@AgathaSorceress I hadn’t heard of this app yet, but am flabbergasted.

Thomas Klopf

@AgathaSorceress I assume anything ‘innovative’ is snakeoil these days. This is a hilarious bit on the converso website:

Seth

@AgathaSorceress My biggest surprise here was that this wasn't Twitter 😂

T.J. Crowder

@AgathaSorceress I love how with all the other horrors on offer, this SQL injection vector just didn't even get a mention:

var i = yield n.executeSql("SELECT name, number FROM contacts WHERE name = '"+t+"';");

I mean, *maybe* `t` has been correctly sanitized previously, but nothing about this app suggests to me that's likely.

Sweet cuppin' cakes...

T.J. Crowder

@AgathaSorceress Has anyone verified this as far as you know? Is this blogger someone you know and trust?

Don't get me wrong, the claims in the app marketing raise all kinds of red flags and I have no reason to doubt the post. Just curious.

SamuelJohnson

@AgathaSorceress I doubt I'll read anything funnier today.

But... The excoriation of Techbros in the comments seems a little off. I thought Techbros were technically competent but socially maladjusted. Clueless incompetents with testicles are Trumps, surely.

Snakeoil buyers and sellers...

DELETED

@AgathaSorceress It looks like scriptkiddies wants to make money.

trenchworms

@AgathaSorceress
also

dont we already have this

i'm sure there's a tor-hidden-serviced based messaging platform that actually does these things?

it's called richochet and it's a p2p model (though i dont have enough experience to know if it's actually good or not)

\u1f01a

@AgathaSorceress Oh, wow!
Striking how naive they are. They either have no clue whatsoever, or they thought nobody would notice.

Ach so... 🇺🇦

@AgathaSorceress Woah, thank you very much for your work and the detailed explanations which even I as a lay person (kind of) understand. I'm truly stunned. I don't consider this app a honeypot (they surely would have done better then). But I do consider it malware through sheer incompetence paired with greed.

Go Up