Live data from Hacker News

Russia says it can collect encryption keys to decode information from WhatsApp

ibtimes.co.uk

11–20 of 30 posts

Re: Russia says it can collect encryption keys to decode information from WhatsApp

#11
I just leave a couple of excerpts for everyone to understand the level of competence up there.

> After signing controversial anti-terrorist legislation earlier today, President Putin ordered the Federal Security Service (the FSB, the post-Soviet successor to the KGB) to produce encryption keys to decrypt all data on the Internet. According to the executive order, the FSB has two weeks to do it. Responsibility for carrying out Putin's instructions falls on Alexander Bortnikov, the head of the FSB.

https://meduza.io/en/news/2016/07/07/putin-gives-federal-sec...

> Russian President Vladimir Putin said Thursday at a media forum in St. Petersburg that the Internet is a “CIA project” that is “still developing as such,” the Associated Press reports.

http://time.com/75484/putin-the-internet-is-a-cia-project/

Re: Russia says it can collect encryption keys to decode information from WhatsApp

#12
post #7

I think we need to wait for someone that understands Russian to chime in and tell us whether this article interpreted this correctly, or if this is just a law giving the state the authority to collect your private keys from your systems (via however they want to accomplish this)

> or if this is just a law giving the state the authority to collect your private keys from your systems (via however they want to accomplish this)

That. No details are available. People say they have no idea how to accomplish this.

Re: Russia says it can collect encryption keys to decode information from WhatsApp

#13
There was a story about some Russian IT company that got huge amounts of money for bogus claims. Maybe this is the case here, however I doubt that the FSB is that incompetent. Or it's an attempt to deter usage of WhatsApp and other clients.

On the other hand there were rumours that Russia can and does manipulate SS7 e.g. to get 2FA tokens via SMS, they also have likely control over the GSM and 3G/4G stations. As this is a black box it's probably not impossible that a network operator could access the keys via the baseband if there is a hole a "feature" e.g. for DMA access from the baseband to the phone, however this is pure speculation from my part.

Re: Russia says it can collect encryption keys to decode information from WhatsApp

#14

I just leave a couple of excerpts for everyone to understand the level of competence up there. > After signing controversial anti-terrorist legislation earlier today, President Putin ordered the Federal Security Service (the FSB, the post-Soviet successor to the KGB) to produce encryption keys to decrypt all data on the Internet. According to the executive order, the FSB has two weeks to do it. Responsibility for car…

>...to produce encryption keys to decrypt all data on the Internet. According to the executive order, the FSB has two weeks to do it.

Maybe they'll offer $1K for someone who comes up with the solution. Saves the FSB having to put a staffer on it.

Re: Russia says it can collect encryption keys to decode information from WhatsApp

#15
post #9
post #7

I think we need to wait for someone that understands Russian to chime in and tell us whether this article interpreted this correctly, or if this is just a law giving the state the authority to collect your private keys from your systems (via however they want to accomplish this)

The linked fsb.ru update says nothing about ability to collect encryption keys by themselves. It only says that the method with which the companies will be able to give them the encryption keys is approved. Still, my russian may be rusty, but it seems to me, the FSB just documented a procedure which the companies will need to follow to provide the FSB with the keys.

Yep, you're right. The article in question misrepresented the linked Russian text. Source: I'm Russian.

Re: Russia says it can collect encryption keys to decode information from WhatsApp

#16
The linked article completely misrepresents FSB's announce. It says that FSB has come up with the procedure by which companies can hand them their encryption keys, not that they will be able to decrypt everything themselves.

Is it possible to correct the title? It's actively misleading now.

Re: Russia says it can collect encryption keys to decode information from WhatsApp

#17
post #7

I think we need to wait for someone that understands Russian to chime in and tell us whether this article interpreted this correctly, or if this is just a law giving the state the authority to collect your private keys from your systems (via however they want to accomplish this)

I speak russian and I can ensure you this story is ridiculous for every IT-related person in Russia. Russian segment of the internet already produced a lot of memes and jokes about "all keys in 2 weeks" (and teleport in last day, please). It's just level of incompetence of the Russian government.

This law is just reason to ban every messenger who will not send traffic to FSB.

Re: Russia says it can collect encryption keys to decode information from WhatsApp

#18
post #5

Apparently they required companies to provide their private keys. Once you have that you can capture traffic and decrypt it.

Whatsapp, Signal, and Telegram generate the keys on the clients to provide end-to-end encryption. The companies themselves do not have keys to provide to anyone.

[deleted]

Re: Russia says it can collect encryption keys to decode information from WhatsApp

#19

Seems like to me this sort of bluff works on the average users and not the hardcore users who understand what they are doing, so it's entirely fruitless. Unless it's not a bluff, in which case we would wonder why the hell they announced it.

I wouldn't call it a bluff, but FUD. Of course the carriers can MITM pretty much all traffic, unless the keys were exchanged on a private channel. The internet is not private, SMS 2FA ain't either. It's FUD, because the spin that this announcement is a bluff would lead Terrorists from using it anyhow, revealing sensitive information. Putting on the tin-foil: If even I could figure that out, perhaps it's indeed intended as deterrent, e.g. because AI is not strong or efficient enough to process the amounts of data. That's still less paranoid than thinking AI was indeed strong enough and just keeping people busy with unsubstantial stories.

Of course there's also the theory, that even governments are sometimes just stupid.

Re: Russia says it can collect encryption keys to decode information from WhatsApp

#20
I actually believe the Russian government can do that.

It's trivial for a messenger app to include code that sends a copy of your private key to the messenger app's company's HQ, if served with a warrant or if obliged by law (and that seems to be precisely what's happening here).

If the messenger app is open-source (like Telegram or Signal), you can satisfy yourself that the messenger app isn't sending your private key behind your back.

But it's a different story if the app is closed-source and its parent company was involved in PRISM (like Whatsapp).

Post reply on HN