[guardian-dev] Silent Circle Source

Chris Ballinger chrisballinger at gmail.com
Mon Nov 12 15:25:53 EST 2012


* Any redistribution, use, or modification is done solely for personal
benefit and not for any commercial purpose or for monetary gain


 It looks like they added an extra clause.



On Mon, Nov 12, 2012 at 12:08 PM, Abel Luck <abel at guardianproject.info>wrote:

> Abel Luck:
> > it's coming... https://github.com/SilentCircle
> >
> > (some of it at least)
>
>
> Just casually browsing the repo [1] here are some initial observations:
>
> * it looks like this is their XMPP client for IOS / OSX and supporting C
> libs
> * it's BSD 3-clause licensed [2]
> * uses its own messaging protocol on top of XMPP (Silent Circle Instant
> Messaging Protocol aka SCimp) [3] (note, this is not OTR)
> * doesn't appear to support user to user authentication, but supports
> some sort of ZRTP like Short Authentication String [4]
>
> Something worrying, is that the SAS seems to be designed to be exchanged
> in-band.
>
> That is, the users type the SAS to each other to ensure it is identical,
> but if you're being MITMed that won't do you much good (remember SAS is
> to detect MITM).
>
> According to their site [5] they use push notifications for background
> messaging.
>
> Would be awesome if an iOS / obj-c developer could examine it further
> (Chris?).
>
> ~abel
>
>
> [1]: https://github.com/SilentCircle/silent-text
> [2]:
> https://github.com/SilentCircle/silent-text/blob/master/PROJECT%20README
> [3]:
>
> https://github.com/SilentCircle/silent-text/blob/master/SilentChat/SilentChat/SilentChat/SCPP/XMPPSilentCircle/XMPPSilentCircle.h
> [4]:
>
> https://github.com/SilentCircle/silent-text/blob/master/SilentChat/SilentChat/SilentChat/App/ConversationManager.m#L814
> [5]: https://silentcircle.com/web/faq/
> _______________________________________________
> Guardian-dev mailing list
>
> Post: Guardian-dev at lists.mayfirst.org
> List info: https://lists.mayfirst.org/mailman/listinfo/guardian-dev
>
> To Unsubscribe
>         Send email to:  Guardian-dev-unsubscribe at lists.mayfirst.org
>         Or visit:
> https://lists.mayfirst.org/mailman/options/guardian-dev/chrisballinger%40gmail.com
>
> You are subscribed as: chrisballinger at gmail.com
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.mayfirst.org/pipermail/guardian-dev/attachments/20121112/694cbbe7/attachment.htm>


More information about the Guardian-dev mailing list