So, now we have a billion people who think they're communications are secure, as opposed to just encrypted.
WhatsApp Just Switched on Encryption for a Billion People
41–50 of 65 posts
Re: WhatsApp Just Switched on Encryption for a Billion People
#42Re: WhatsApp Just Switched on Encryption for a Billion People
#43How does this compare with Telegram? Same, better or worse?
Re: WhatsApp Just Switched on Encryption for a Billion People
#44Unless the NSA/FBI/CIA secretly orders WhatApp to release compromised app update with a backdoor.
Re: WhatsApp Just Switched on Encryption for a Billion People
#45So now WhatsApp is finally on par with iMessage and Signal, and shares the same weakness: public key distribution. Key distribution is controlled by a centralized server that could, for malicious or other reasons, send you new fake keys for people you communicate with. For iMessage, this is explained in this 2015 post by Matthew Green: http://blog.cryptographyengineering.com/2015/09/lets-talk-ab... At least with Sign…
You do have to trust the client and opt in, but the feature exists.
Re: WhatsApp Just Switched on Encryption for a Billion People
#46Re: WhatsApp Just Switched on Encryption for a Billion People
#47Re: WhatsApp Just Switched on Encryption for a Billion People
#48The article says: "With end-to-end encryption in place, not even WhatsApp’s employees can read the data that’s sent across its network." But according to the diagram: http://www.wired.com/wp-content/uploads/2016/04/Whatsapp_Enc... ... A's message is encrypted with Whatsapp's public key, which means that Whatsapp's private key can (and has to) decrypt it on the server side to encrypt it in turn with B's public key. If…
it use the public key of the other user, not whatsapp. in effect, whatsapp is just acting as a key server. now they could have that users private key, but that's another matter
Re: WhatsApp Just Switched on Encryption for a Billion People
#49So now WhatsApp is finally on par with iMessage and Signal, and shares the same weakness: public key distribution. Key distribution is controlled by a centralized server that could, for malicious or other reasons, send you new fake keys for people you communicate with. For iMessage, this is explained in this 2015 post by Matthew Green: http://blog.cryptographyengineering.com/2015/09/lets-talk-ab... At least with Sign…
If you go to Settings -> Account -> Security, you can enable the option that will notify you in case the key changes. You do have to trust the client and opt in, but the feature exists.
Re: WhatsApp Just Switched on Encryption for a Billion People
#50Earlier quoted context omitted.
Basically Telegram is _nothing_ compared to this.
Really? How so? I can understand from scale perspective, but is it more secure than Telegram?
This OTOH uses peer reviewed, strong, modern crypto that was designed by people who know how to do these things.