Daily Shaarli

All links of one day in a single page.

July 13, 2018

Wire Chat App's SAME ORIGIN POLICY restrictions do not allow 3rd parties to build on top of its open source code · Issue #10 · caura/wire · GitHub

Documenting here Wire's restrictions on CORS(Cross-Origin Resource Sharing). Without this change, building on top of Wire's open source project is not an option. This is a continuation of g...

WhatsApp also has the glaring vulnerability that Facebook could at any time rese... | Hacker News

WhatsApp also has the glaring vulnerability that Facebook could at any time reset your key to a compromised one without your knowledge, and WhatsApp will resend any hanging messages automatically upon the change, making any undelivered messages available to the one who has the decryption capability associated with that new key. It's possible they've put in a method to do this without notifying the user. Also, this "automatic resend" behavior means that a physical attack can be made simply by switching SIMs on the phone before the message is sent. It requires some careful timing to be a real vulnerability and anyone using a phone to communicate will certainly opt for a more secure platform for critical applications.

Wire server code now 100% open source — the journey continues

Earlier this year, we started open sourcing Wire server code under the AGPL license. Today, the code necessary to run Wire servers is…

Edward Snowden sur Twitter : "Many don't seem to understand why I object to @Telegram having unsafe, censorable public channels in an app that is promoted as a secure messenger. Some presumed I just don't understand how channels work. So let's talk about it:"

Many don't seem to understand why I object to @Telegram having unsafe, censorable public channels in an app that is promoted as a secure messenger. Some presumed I just don't understand how channels work. So let's talk about it

Apple is sharing your face with apps. That’s a new privacy worry. - The Washington Post
Wire application-level security audits – Wire – Medium

Kudelski Security and X-41 D-Sec have published application-level security audits of Wire’s iOS, Android, web application, and calling…

Russia: Move to block Telegram the latest blow in government assault on freedom of expression online | Amnesty International

On Friday, the Tagansky District Court in Moscow is expected to rule on a request by Roskomnadzor, the Russian media watchdog, to block Telegram for its refusal to provide the Federal Security Service (FSB) with backdoor access to encrypted messages.

Have the Tech Giants Grown Too Powerful? That’s an Easy One - The New York Times

Tech companies have changed the world by building answers to obvious questions — but now the obvious, pressing questions are about them.