I would like to see some clarification on point #5. The only other option I see for the FBI is to continue manually bruteforcing PINs, the arduousness of such a task being why they requested Apple's help in the first place. Is he talking about 0days?
We never intended to "fix" Cryptocat, per se. I agree that would be more trouble than it's worth, especially when there are things like Signal, Ricochet, CoyIM, etc.
Cryptodog is very much a casual project, not an all-encompassing fix for inherent design flaws. I offer it here only as an alternative for former users of Cryptocat who were content with the app.
P.S. Your guess is inaccurate, I am not the GP. HN staff might be able to verify this if it concerns you.
One of the Cryptodog devs here - no Chrome 0days in our possession (yet).
The code's all on Github: https://github.com/Cryptodog/cryptodog. No signed extensions or apps yet, but you can clone and run locally for testing purposes, or use the hosted client linked there.
So far, we've been focusing on refactoring, fixing surface bugs, and making the UI more attractive and intuitive -- none of the underlying cryptography has been touched. It also performs slightly faster than stock Cryptocat. Since Nadim took down his XMPP server, we've had to create our own, but the backend is identical to his setup.
Of course, Cryptodog is by no means the best solution for E2E chat, just as Cryptocat wasn't. The best we can hope to achieve without a complete codebase overhaul is a reasonable level of security (https://leastauthority.com/static/publications/LeastAuthorit...). However, it's still a fairly usable app that can afford casual users protection against basic threats, like corporate data mining.
Issue postings, pull requests, and other miscellaneous contributions are all welcome.
There's absolutely no clear answer to this question, even among military historians, so I'm not sure how you can have no doubt about it.