Live data from Hacker News

WhatsApp's Signal Protocol integration is now complete

whispersystems.org

311–320 of 386 posts

Re: WhatsApp's Signal Protocol integration is now complete

#311
post #140

Earlier quoted context omitted.

By default, Telegram stores a plaintext copy of every message you've ever sent or received on their servers. WhatsApp does end to end encryption using the Signal Protocol by default, and doesn't store anything server side.

Don't forget that Telegram uses custom in house encryption and they say "trust us", it's good. Telegram encryption can't be verified.

The custom in house encryption is a protocol that if tou have the skill to break, go collect 200,000$ in bitcoins https://telegram.org/crypto_contest

Re: WhatsApp's Signal Protocol integration is now complete

#312

Earlier quoted context omitted.

For my part: because "Axolotl" is one of the most widely name-dropped terms in hipster cryptography, and because it's been adopted by other projects, and because it's distinctive, and because they basically own the term. In a stroke, everyone doing secure key ratchets would have been using their product . It's also just a cool name.

I always liked "Axolotol" because axolotols are a type of salamander with the amazing ability to regenerate parts of their bodies (including their brains!), and the Axolotol protocol, like OTR, is "self-healing", meaning it's capable of recovering from a compromised session key ( https://whispersystems.org/blog/advanced-ratcheting/ ).

And you're spelling it wrong which pretty much validates the renaming.

Re: WhatsApp's Signal Protocol integration is now complete

#313

This is really excellent. A few thoughts: 1) They seem to have replaced TLS/SSL between client and server with "Noise Pipes". Based on a couple of minutes Googling this seems to be a brand new one-man protocol from Trevor Perrin (the same guy who did Axoltl on which Signal is based). At least, I'd never heard of it. I wonder if this is the first inkling of a post-TLS future? http://noiseprotocol.org/noise.html 2) It'…

> It's a shame to see key words be killed off by internationalisation concerns [....] I hope further research here can develop better replacements for encoding short binary strings in i18n friendly ways I rather like the urbit way of encoding numbers. I can't remember the exact details but it's something like: There are 256 unique three letter words (all nonsense, but deliberately picked to be possible to pronounce).…

This sounds a bit like babble print, which is a more complex type of encoding mechanism.[0]

The first I encountered that was in SILC, where it was used to make the key fingerprint more or less pronounceable. It's interesting that the encoding scheme never really got wider attention, although it is available in both openssh and openssl.

Similar ideas come and go, and get rediscovered - so maybe now is the time for wider acceptance.

A bit of googling provided me with a nice starting point for implementations, so babble print has certainly been recognised in some circles.[1]

0: http://bohwaz.net/archives/web/Bubble_Babble.html

1: https://github.com/eur0pa/bubblepy

Re: WhatsApp's Signal Protocol integration is now complete

#314

Earlier quoted context omitted.

> whatever you're sending over WhatsApp is likely going to be used by FB The article links to the technical white paper[0] which explains why your points are invalid. > I'm still inclined to trust apple's iMessage a bit more Do you have any proof why iMessage is more secure or is that statement also baseless? [0]: https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...

A white paper is not an implementation. Whatsapp is owned by Facebook and required to increase their bottom line. They are not a charity.

Assuming Facebook is lying isn't a very good technical argument. There are other ways for them to make profit than doing the shady things you are implicitly accusing them of doing without any base.

Re: WhatsApp's Signal Protocol integration is now complete

#316

Earlier quoted context omitted.

What's more, my client says "You aren't secure because X needs to upgrade WhatsApp", but the other party is seeing "you are secure", complete with fingerprint and everything. I wonder which of the two devices is lying.

I hit the same thing - I think my client just had a stale view of what version the person I was talking to was running. I did a refresh of the Favorites list on iOS and it sorted it out.

thanks for the hint. that solved it for me too.

what I'm wondering: My WhatsApp tells me it can't encrypt because the other person uses an outdated version. But the other person gets told the chat is encrypted. What is the truth then? Is it still doing crypto but my UI is denying it? Or is it not encrypted and the other person has a false sense of security? That's at least a bit strange...

Re: WhatsApp's Signal Protocol integration is now complete

#317

Earlier quoted context omitted.

Because words coming from Nahuatl are cool! (coyotl, mesquitl, tomatl, ahuacatl, etc.) See more from https://en.wikipedia.org/wiki/List_of_English_words_from_ind... They’re distinctively spelled, don’t collide with existing search terms, often have available domains, etc. Most importantly, they anticipated the web 2.0 trend of ending words with two consonants in a row. ;) Finally, just look at this guy: https://uploa…

> Because words coming from Nahuatl are cool! (coyotl, mesquitl, tomatl, ahuacatl, etc.) > Most importantly, they anticipated the web 2.0 trend of ending words with two consonants in a row. ;) But those words (coyote, mesquite, tomato, and avocado, unless I seriously miss my guess) all end in a vowel.

[deleted]

Re: WhatsApp's Signal Protocol integration is now complete

#319
post #199

Earlier quoted context omitted.

"Secret Chat" uses Telegram's (flawed) E2E protocol, so the server would only see ciphertext. A "normal" chat is stored in plaintext. This is also why normal chats work in multi-device environments, but secret chats don't. Unlike iMessage (and I assume Signal - haven't looked at the actual protocol), they don't do anything fancy like making the sender encrypt messages with multiple public keys (one for each device th…

If you know something that telegram doesn`t know, maybe you should contact them, and ask your bitcoins worth of 200,000$ https://telegram.org/crypto_contest . Easier to "talk".

https://www.schneier.com/crypto-gram/archives/1998/1215.html...

http://thoughtcrime.org/blog/telegram-crypto-challenge/

Re: WhatsApp's Signal Protocol integration is now complete

#320
post #290

Kind of weird but I got the message claiming my chats were e2e encrypted but when testing it with a friend, his said no such thing, and his client claimed mine was out of date and our messages were NOT encrypted, despite there being a lock my side. https://imgur.com/a/pgJsH This is kind of worrying. I'm sure it's not malicious but I have literally no idea if things are encrypted right now.

There was another comment in this thread that said one of you might have stale data. If you kill the app and try again it should update. https://news.ycombinator.com/item?id=11432356

We went as far as killing the app, rebooting our phones, etc.
Post reply on HN