Live data from Hacker News

WhatsApp Just Switched on Encryption for a Billion People

wired.com

41–50 of 65 posts

Re: WhatsApp Just Switched on Encryption for a Billion People

#44
> WhatsApp has no way of complying with a court order demanding access to the content of any message, phone call, photo, or video traveling through its service

Unless the NSA/FBI/CIA secretly orders WhatApp to release compromised app update with a backdoor.

Re: WhatsApp Just Switched on Encryption for a Billion People

#45
post #39

So now WhatsApp is finally on par with iMessage and Signal, and shares the same weakness: public key distribution. Key distribution is controlled by a centralized server that could, for malicious or other reasons, send you new fake keys for people you communicate with. For iMessage, this is explained in this 2015 post by Matthew Green: http://blog.cryptographyengineering.com/2015/09/lets-talk-ab... At least with Sign…

If you go to Settings -> Account -> Security, you can enable the option that will notify you in case the key changes.

You do have to trust the client and opt in, but the feature exists.

Re: WhatsApp Just Switched on Encryption for a Billion People

#47

So, now we have a billion people who think they're communications are secure, as opposed to just encrypted.

Are you implying WhatsApp designed an insecure encryption?

how do you know it's secure other than what you read from the press release?

Re: WhatsApp Just Switched on Encryption for a Billion People

#48
post #18
post #11

The article says: "With end-to-end encryption in place, not even WhatsApp’s employees can read the data that’s sent across its network." But according to the diagram: http://www.wired.com/wp-content/uploads/2016/04/Whatsapp_Enc... ... A's message is encrypted with Whatsapp's public key, which means that Whatsapp's private key can (and has to) decrypt it on the server side to encrypt it in turn with B's public key. If…

it use the public key of the other user, not whatsapp. in effect, whatsapp is just acting as a key server. now they could have that users private key, but that's another matter

So in theory they could help by intercepting these keys and handing them to authorities without actually decryption the data themselves

Re: WhatsApp Just Switched on Encryption for a Billion People

#49
post #45
post #39

So now WhatsApp is finally on par with iMessage and Signal, and shares the same weakness: public key distribution. Key distribution is controlled by a centralized server that could, for malicious or other reasons, send you new fake keys for people you communicate with. For iMessage, this is explained in this 2015 post by Matthew Green: http://blog.cryptographyengineering.com/2015/09/lets-talk-ab... At least with Sign…

If you go to Settings -> Account -> Security, you can enable the option that will notify you in case the key changes. You do have to trust the client and opt in, but the feature exists.

You're right. So when you get a notification of a key change (for malicious or other reasons) it is up to you to verify that the user did indeed have a key change — preferably out of band, or at least over another medium.

Re: WhatsApp Just Switched on Encryption for a Billion People

#50
post #46

Earlier quoted context omitted.

Basically Telegram is _nothing_ compared to this.

Really? How so? I can understand from scale perspective, but is it more secure than Telegram?

Telegram received quite a backlash from crypto community for rolling out nonsensical throw-a-bunch-of-crypto-algorithms-together homebrew protocol that was designed by Math PhD™ students and having an audacity of conducting a contest to break it.

This OTOH uses peer reviewed, strong, modern crypto that was designed by people who know how to do these things.

Post reply on HN