Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's a neat project. Others have fleshed out most details. It could even get uptake if spread on social media. Let me focus instead on the more devious possibilities.

"They are encrypted and saved on your devices. Recordings are never sent across the internet and never touch our servers. "

" it is impossible for third party attackers to gain access to your videos without local access to the network your devices are on (that includes us!)"

This claim is made by every developer of security/privacy apps when content stays on the device. It's actually false. They could embed a backdoor in the current or a future release that shares the files. Already requires networking permission when managing videos. Actually, a service like this getting extremely popular could lead to one of the largest leaks of nude pics in history. One person hacking the box containing the source/credentials, getting on the development team, or being the original author w/ trolling intent could subvert it into a giant store of pics/video. Get it to send the data back when on WiFi to avoid high, data bills. Thumbnails of videos sent first to filter out uninteresting parties.

I'm not accusing the author of this at all. I'm just assessing security risk from side I'm good at: subversion. The subversion risk here is spectacularly above average as a network effects developing around this app lead to many eggs in one basket that's probably easy to grab. Or was until the author read my comment and beefed up security in a panic. ;)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: