[guardian-dev] ChatSecure for Android 12.1.0 (v12 beta 1)

Nathan of Guardian nathan at guardianproject.info
Fri Aug 16 16:20:45 EDT 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


ChatSecure for Android 12.1.0 (v12 beta 1) is now available.
(This is the app formerly known as Gibberbot)

If you haven't been following the work recently, this release is nothing
short of a complete overhaul of our secure messenger app for Android.

- From a security perspective, the most notable features are:
- - pinning of popular known XMPP SSL certs using Moxie's AndroidPinning
library
- - TOFU-POP/manual approval for unknown certificates
- - NO reliance on CACert stores at all
- - complete encryption of all app data using SQLCipher
- - best practices password and key management using our CacheWord library
- - integration of OnionKit for detecting if Orbot is installed and running
- - import of OTR key rings from desktop apps using KeySync (aka
OTRFileConverter)
- - and of course, the recent fix from Google for the weak PRNG issue

... and did I mention emoji? 😸😹😺😻😼😽😾😿🙀

Source:
https://github.com/guardianproject/Gibberbot/releases/tag/12.1.0

Bug reports (this is still beta 1 after all!):
https://dev.guardianproject.info/projects/gibberbot/issues/new

Direct APK:
https://guardianproject.info/releases/ChatSecure-v12.1.0-beta1-release.apk
https://guardianproject.info/releases/ChatSecure-v12.1.0-beta1-release.apk.asc

or via HockeyApp:
https://rink.hockeyapp.net/apps/2fa3b9252319e47367f1f125bb3adcd1/

or buy joining our GP Beta Band Google Group (using Google Play's new
"beta testing" service):
https://plus.google.com/communities/108480576214602821006

Main updates include

  * local OTR key store is now fully encrypted all of the time
  * Improved notifications (separate for each conversation/contact)
  * Now using Google patch for PRNG weakness bug


Recent commits:

62575a3 Merge branches ‘v12-alpha’ and ‘master’
05670ab bug fixes, ui cleanup, and other small changes
971fc14 ensure otr key store is unlocked when cacheword is opened
83f20e3 show indiv notifications for each sender
522cb60 support for encrypted otr key store and cacheword integration
53c0b24 added classes for read/write AESCBC encrypted key store
e7842f2 disabling SIP/VoIP preference for this release
3507ea8 fixes for 2.3.x phones
2acf557 switched to Google’s fix for SecureRandom bug
aa1dfb3 multiple bug fixes for UI stability relates to fragments load
times, NPE on getActivity() also implement the action buttons me
42b46bb support the new Address super class
5375cb5 handle the proper message type workflow for new encrypted type
support
8c078a8 handle parsing of encrypted messages properly, both inbound and out
03138d0 add new message type flags for encrypted message type
1f99608 update core Address object to understand resources
96969ff updated layout resources, colors and strings
94cfd00 render now based on encryption state per message
29929b5 small fixes to make Otr interaction less crashy
e4d73cc add method for proper account/contacts delete
d0438ea support the creation of new accounts
f3880e1 added dark style for some dialogs
4f1e4dc update chatsecure graphic for landscape view



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBAgAGBQJSDomaAAoJEKgBGD5ps3qpx/gP/RAYbaI1xe01Ew45UgpGh4NH
AOvEKj3YQgavC7zRgaAjm0y08BmnBZamZPkYBiYLXXLzCwABtTpxRKkkHfZM0Kb0
pGeZ8kDsDteHdlqki+1wNtMjdYmIjCj0MClC2RfwUnIes+AJd4YWMoIrw5rHv4mt
e3qV1PF58jRi+xR2tz97jTvWk2zNlnJYie6CCBThszqFZYFVrcHkymFSi3aBOhbB
hxnIpdT5wqlOXecwva4cDb69brZMS7YMMr0fl9u6Rat09BpwvAxXrM9uDrJW+T8J
v25FSFwzs2EiswM7pD97t/zrhJayM+UINTSShH+31m1kjiUSOSbBcaqwzByiFaV2
Q+Z3wHlCsQC50AjqCRcfbj4VfCg8F83KeYLuxAv37vb7zCNzYcLik2i/oxvKWUe4
S92BMpx80T409eRcjwizmqqN2FlJb9IH+scq0+c0GiZbg+zPQLIT/K5bXnjfv9cS
2TYbqAVoMLMniSMXyYpgDL7c3e7CEbI0Io4sHqlv3qwAik8YQ4ZzDVeTCk9W21Pm
aB+vOUwbx4xN03vQnFlbmiq2NynSdnFpoUieZxKrLYDYqhfcSkfjoq/7s3o7oF0N
H1FNCMenrrvZzACSdv5pwHRZlCi/FVEbxABm/q2yJ3b1E58bLq1atYBjJHQfC6Xm
+Fw74iP8mOZvrmVIAujk
=HTKW
-----END PGP SIGNATURE-----

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.mayfirst.org/pipermail/guardian-dev/attachments/20130816/c8b147b8/attachment.html>


More information about the Guardian-dev mailing list