Feb 16, 2017

Confide defends messaging app's security


Confide, an ephemeral messaging app, has become popular among government operatives, as Axios reported last week. But now the app's encryption—how it ensures messages can't be intercepted by outsiders—is under question.

While the company claims that its app offers "military-grade encryption," some experts aren't so sure that it's as secure as it sounds.

What Confide says: According to co-founder Jon Brod, "Confide's message encryption is based on the PGP standard" and uses "recommended best practices to ensure the security of network connections, such as using TLS 1.2 with certificate pinning to prevent against [man-in-the-middle] attacks."

For each platform on which it's available, the company has selected various encryption tools—the latest version of OpenSSL for iOS and Spongy Castle for Android. Brod added that the company plans to upgrade to the newest version of OpenSSL in its app's next update. OpenSSL, in particular, raised concerns among security experts as it's been found to have a number of security vulnerabilities over the years, including the Heartbleed bug, which wreaked havoc on the Internet in 2014. Brod says that Confide's Android app uses OpenSSL for one single function but it's not one impacted by Heartbleed or any other published vulnerability.

Questions remain: With that said, it's still difficult to be fully certain of Confide's security as the company's software is proprietary and hasn't been reviewed by a third-party.

"This one's a tough call. The application doesn't smell fully kosher, but at least it uses some standard encryption routines, which many other applications fail to do," computer forensics expert Jonathan Zdziarski wrote in a blog post after taking a look at the app. "Ultimately, the application warrants a cryptographic review before I could endorse its use in the White House," he wrote, adding that since OpenSSL isn't FIPS 140-2 compliant (a government encryption standard), it shouldn't be used by government workers.

And as one security expert told Axios, it all depends on how well all of Confide's precautions have been implemented—a sloppy or faulty job could mean the app is far from secure.

What to watch: With reports of staffers using encrypted chat apps, some Congresspeople are already asking for investigations into whether their use violates federal record-keeping laws. On Tuesday, House Republicans Darin LaHood and Lamar Smith sent a letter to the EPA's independent watchdog following news that some employees have been using another app, Signal.

Go deeper

Trump considers quarantine for states near epicenter of U.S. coronavirus outbreak

President Trump speaks to the press on March 28 in Washington, DC. Photo: Sarah Silbiger/Getty Images

President Trump said on Saturday he is considering a "short term" quarantine of New York, New Jersey and parts of Connecticut — areas congruent with the New York metro area, the epicenter of the novel coronavirus in the U.S.

Reality check: These states have already taken steps to quarantine residents and promote social distancing to combat COVID-19. The governors of New York and New Jersey issued statewide stay-at-home orders last week, and non-essential businesses in Connecticut were ordered to close as of this Monday.

New York is latest state to delay primary due to coronavirus

Photo: Barbara Davidson/Getty Images

New York — the epicenter of the coronavirus outbreak in the U.S. — has moved its presidential primary to June 23, Gov. Andrew Cuomo said on Saturday.

Why it matters: 23 other states and the District of Columbia haven't held primaries yet. The White House is recommending, for now, that Americans practice social distancing and gather in groups of no more than 10 people — while many states have issued stay-at-home orders.

Go deeperArrowUpdated 32 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 1 p.m. ET: 622,450 — Total deaths: 28,794 — Total recoveries: 135,779.
  2. U.S.: Leads the world in cases. Total confirmed cases as of 11 a.m. ET: 105,573 — Total deaths: 1,711 — Total recoveries: 895.
  3. Federal government latest: President Trump is reportedly considering a quarantine on New York, parts of New Jersey and Connecticut. He signed the $2 trillion coronavirus stimulus bill to provide businesses and U.S. workers economic relief.
  4. State updates: A group of Midwestern swing voters that supported President Trump's handling of the coronavirus less than two weeks ago is balking at his call for the U.S. to be "opened up" by Easter. Alaska is latest state to issue stay-at-home order — New York is trying to nearly triple its hospital capacity in less than a month.
  5. World updates: Italy reported 969 coronavirus deaths on Friday, the country's deadliest day. In Spain, over 1,300 people were confirmed dead between Thursday to Saturday.
  6. 🚀 Space updates: OneWeb filed for bankruptcy amid the novel coronavirus pandemic.
  7. What should I do? Answers about the virus from Axios expertsWhat to know about social distancing.
  8. Other resources: CDC on how to avoid the virus, what to do if you get it.

Subscribe to Mike Allen's Axios AM to follow our coronavirus coverage each morning from your inbox.