Jack Dorsey says his ‘secure’ new Bitchat app has not been tested for security


Jack Dorsey Block, co-founder of Sunday, CEO and Twitter Started a open source chat app called Bitchat, prospective To give “safe” and “personal” messaging without centralized infrastructure.

The application rely on the Internet, unlike traditional messaging applications, relying on the wide encryption from Bluetooth and to the end. After centralization, Bitchat has a potential to be a reliable application in high-risk environments where the Internet is tracked or inaccessible. According to Dorsey white paper “Prioritizing” the design of the Bitchat system “Priority” security, explaining the protocols and privacy mechanisms in detail.

However, allegations that the application is valid, the application and its code are not considered for security problems or are not considered for security issues or are not tested for security issues, are checked by security researchers.

Since the beginning, there’s dorsey added a warning Bitchat’ın Github: “This program did not receive an external security opinion and will not necessarily meet the security objectives. Do not use for the use of production and rely on security.”

Now this warning was visible on Bitchat’s Basic Github project page, but was not there when the application debuted.

Wednesday, Dorsey Added: “At the war in Github,” continues “.

Security researcher Alex RodoCea found that a person was able to seduce another and thinking of a person’s contacts with legal contact As the researcher explains in a blog post.

RodoCea wrote that the attacker has a “violated identity identification / inspection” system, which allows someone to “identity key” and “identity key” and “identity key” and “identity key”. Bitches calls these “favorite” contacts and mark them with a star symbol. The purpose of this feature is to allow two Bitchat users to know and interact with the same person they speak previously.

Dorsey did not respond to the application for a comment sent to the block email address of TechCrunch.

A screenshot showing an example of a chat with “Bob” in conversation with the attacker “Bob”, it seems like the blade really comes from Bob. (Photo: Alex Rodocea)

On Monday, Radocea, GitHub Project Bitchat presented a ticket to ask how to express the security defect discovered in the Sevimites. Soon Dorsey noted it as “completed” without commenting. (The Dorsey ticket reopened The security issues can be reported by sending Github directly on Wednesday.)

Another man declare Dorsey’s claims related to allegations related to allegations that a cryptographic technique, which has been stolen or compromised by the attacker, is still unable to decipher the attacker.

Someone erected A hacker’s memory to other places to pour a device to other places, a bullet of buffer that exceeds a buffer to force a device to make a device’s memory to open the door to discover a device.

RadoCea warned that Bitchat users still do not trust the application.

“Security is an excellent feature to be viral. However, the key will actually make any cryptist, making anything like this,” said Radocea Techcrunch. “There are people who can carry a person around security and have people who can trust him for their safety, so the project in his current situation may endanger them.”

Touching upon him and other people, Radosea criticized Dorsey’s warning that the knife warned that the knife was not tested for security.

“I’d pretend to receive external security care and don’t look good,” he said.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *