Live data from Hacker News

WhatsApp's Signal Protocol integration is now complete

whispersystems.org

221–230 of 386 posts

Re: WhatsApp's Signal Protocol integration is now complete

#221
post #94
post #90

Earlier quoted context omitted.

Maybe it is feasible, but at the very least I would wait for someone to reverse engineer it and publicly publish its findings. I do not have the skills to do that. Moreover, if reverse engineering is so easy, why not open-source it from the beginning?

If you don't have the skills to do basic verification of a non-obfuscated binary, you don't have the skills to verify an encrypted messaging protocol implementation from source either: the latter task is harder than the former! I think the misconception some people here have about the necessity of source code is born out of the idea that a cryptographic backdoor would look something like a mysterious HTTP POST of you…

> If you don't have the skills to do basic verification of a non-obfuscated binary, you don't have the skills to verify an encrypted messaging protocol implementation from source either: the latter task is harder than the former!

Those aren't quite the same skill though. Some folks could have the skills to verify protocols from source, but not the skills to work with a non-obfuscated binary. Task 'A' being harder than task 'B' doesn't mean that everyone who can do 'A' (harder task) is capable of 'B (easier). Nor does the inverse follow at all.

If we admit that doing basic (non-messaging protocol impl) verification on a binary is difficult and doing messaging protocol impl verification is also difficult, it seems reasonable to presume that doing both will take more time, work, and as a result, allow for more errors in verification.

Essentially, verifying impls without source code is more difficult/time consuming/error prone than verifying ones with source code.

Of course, they could give someone the source code to verify without making it open source. But that requires that one trust this other party, selected by folks who have an interested in their protocol being reported as secure (whether it is or not).

The goal when folks are looking for freely available source code is to eliminate some of those needs for trust (by allowing a greater number of verifiers) and eliminate some of the conflict of interest (by removing some control the interested party has).

Sure, closed source bits that promise to be good and that we can (potentially) look at are OK. But having source code for them is still better.

Re: WhatsApp's Signal Protocol integration is now complete

#222
post #34
post #20

Earlier quoted context omitted.

> They seem to have replaced TLS/SSL between client and server with "Noise Pipes". WhatsApp was already using a custom protocol instead of TLS. We worked with them to transition over to Noise Pipes, which has some advantages over what they were doing before. Also, we've renamed Axolotl to Signal Protocol: https://whispersystems.org/blog/signal-inside-and-out/

It is killing me that you didn't rename Signal to Axolotl.

This thread is making me want to reread Dune.

Re: WhatsApp's Signal Protocol integration is now complete

#223

Excellent! 3 questions: - What if the government forces WhatsApp to write and push a targeted software update in order to compromise the end-to-end encryption (I'm of course thinking of the FBI vs Apple case)? Is there a way for the user to be notified? - Does WhatsApp Auto Backup encrypt messages before sending them to Google Drive or iCloud? - Would it be possible for WhatsApp Web to rely on backend servers storing…

> - Does WhatsApp Auto Backup encrypt messages before sending them to Google Drive or iCloud? So you make a backup and loose the phone. What about the key? Is that gone too? Without it, encrypted backup is useless. How do you backup the key? You and me maybe will manage to do this, but what about grandma and all those people without anybody close who knows about this?

The decryption key you're talking about can be a simple password. For symmetric encryption (e.g. AES-256) even a simple password would be secure enough, while something like a 24 chars password would be unbreakable.

Re: WhatsApp's Signal Protocol integration is now complete

#225
post #59

What the article fails to mention: 1) I would assume Facebook still gets unencrypted access to my address book for use with their shadow profiles 2) We have zero control over what key the client encrypts the messages for. Is it only the other peer's phone? Or is it for the peer's phone plus Facebook for analysis of the messages? Especially 2) is of some concern to me (against 1 I can't protect myself anyways because…

> whatever you're sending over WhatsApp is likely going to be used by FB

The article links to the technical white paper[0] which explains why your points are invalid.

> I'm still inclined to trust apple's iMessage a bit more

Do you have any proof why iMessage is more secure or is that statement also baseless?

[0]: https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...

Re: WhatsApp's Signal Protocol integration is now complete

#226
post #218
post #179

Earlier quoted context omitted.

It's easy to shoot yourself in the foot with TLS (see: OpenSSL). Also, TLS has roots in a time where we knew much less in terms of crypto; as time went on and flaws were discovered, SSL/TLS was patched all around, meaning it has become much harder to implement correctly. Noise starts from a clean state with modern knowledge of cryptography and modern cryptography. Much easier to understand and replicate, much harder…

It looks like Noise leaves an implementer with more than enough rope to hang themselves with - for example, it allows unauthenticated Diffie-Hellman, it appears to permit user-selected handshake sequences, has 16(!) different official handshake sequences with subtly different properties, each of which allow payloads to be attached to any message in the handshake process that in turn have different levels of reduced s…

You're describing Noise. WhatsApp uses Noise Pipes, which is one of many instances of the Noise framework.

You're right that it's not a good idea for generalists to pick up Noise and go to town with it. Noise isn't misuse-proof.

Re: WhatsApp's Signal Protocol integration is now complete

#227
post #30

What next? Will they open-source the client?

Ofcourse not. They can't put a backdoor code in the open source. Some people would build from source, resulting in the corporation not being able to access their messages when needed. Not really acceptable for the main shareholders.

Re: WhatsApp's Signal Protocol integration is now complete

#228
post #221
post #94

Earlier quoted context omitted.

If you don't have the skills to do basic verification of a non-obfuscated binary, you don't have the skills to verify an encrypted messaging protocol implementation from source either: the latter task is harder than the former! I think the misconception some people here have about the necessity of source code is born out of the idea that a cryptographic backdoor would look something like a mysterious HTTP POST of you…

> If you don't have the skills to do basic verification of a non-obfuscated binary, you don't have the skills to verify an encrypted messaging protocol implementation from source either: the latter task is harder than the former! Those aren't quite the same skill though. Some folks could have the skills to verify protocols from source, but not the skills to work with a non-obfuscated binary. Task 'A' being harder tha…

I think the argument (one I'm not expert to make) is that the source may or may not be helpful to someone who is competent enough to validate a encrypted message application, but it is not what you need to verify.

You must verify the binary because you cannot trust the source, so it is a basic skill of anyone who has the competency to validate an encrypted message application.

Now, its possible, that the source along with repeatable builds make verifying the binary easier for someone with the skills necessary, but even with those things, they still have to verify the binary.

Re: WhatsApp's Signal Protocol integration is now complete

#229
Okay, first off: This is great. The most popular messaging app finally gets the security it needed. And we've just rolled out E2E to 1b 'monthly active users'.

However, I have always wondered one thing about WhatsApp: How does it generate any kind of meaningful revenue? Apparently they've ditched the old $1 subscription model [0], and even that was so loosely enforced that I have never paid a single cent for WhatsApp in my life--and never will (got it while it was free on the iOS App Store and now have a 'Lifetime' subscription, if they don't change those at some point). And even back then, maybe half of their 900m monthly active users [1] were iOS users who paid only once, and the rest may have dodged the fee in various ways. I have a really hard time believing the revenues so gained could ever actually cover the cost of R&D (especially for so many platforms) and infrastructure (which should be huge, given the amount of data they shift). Now they say they want customers to use WhatsApp as a platform, the way Facebook Messenger is doing it, but I'm not seeing any of those features implemented anywhere. I always assumed there was some heavy data analysis going on behind the scenes--which would have been fair, I guess, since we're neither being shown ads nor really paying. Facebook's involvement added to that conviction. Now that they're encrypting everything (which, again, is wonderful), they can't analyze what is really, really interesting data anymore (keywords, etc.). And it's not like there was a public outcry for them to take this step--I would guess that not many end users actually appreciate the importance of E2E encryption.

So the question remains: How are they making money? You still have metadata (I presume), but then again, how do they use this data to make money if they can't always match it to a Facebook profile (where they can show you ads), and also, does this data really provide such a big improvement over all the data collected by Facebook and Facebook messenger? It just seems strange to me that WhatsApp apparently does not want to make any money.

Does anyone have any insight on this? What am I missing?

[0]: http://www.cnet.com/news/whatsapp-kills-1-subscription-fee/ [1]: http://qz.com/495419/whatsapp-has-900-million-monthly-active...

Re: WhatsApp's Signal Protocol integration is now complete

#230
post #178

Earlier quoted context omitted.

If they actually do what they say the do, then yes. Thier is no evidence that they are lying, so for now its probebly save to assume that they can not read your messages.

No, it is not safe to assume that. Edward Snowden already proved that we cannot trust large US corporations.

Thats what I said. You have to trust them. As far as we know they can not read it. Its fully possible that its not true but its far more likely that it is true.

If the work together with the NSA then its more likly that they deploy bad updates to individuels rather then deploying a backdoor to everybody. That is to easy to detect and it would be a marketing desaster.

Post reply on HN