Live data from Hacker News

WhatsApp backdoor allows snooping on encrypted messages

theguardian.com

21–30 of 334 posts

Re: WhatsApp backdoor allows snooping on encrypted messages

#22
post #12

No matter what IM service you use: As long as they manage the public keys for their users, they will be vulnerable to exactly this problem. This isn't just WhatsApp. This applies to iMessage and Signal too. In all cases, we rely on the word of the service provider that they don't sneak additional public keys to encrypt for into the clients and in all cases we hear that doing so would cause a message dialog to appear,…

'As such I think it's unfair to just complain about WhatsApp here.'

I disagree. WhatsApp have a known vulnerability which they won't fix (indeed they deliberately added this vuln on top of the Signal protocol), and no denial that they have used this vulnerability in the past.

They made a big PR song and dance about this feature only to backdoor it. That deserves criticism.

Re: WhatsApp backdoor allows snooping on encrypted messages

#23
post #14
post #8

Earlier quoted context omitted.

Signal is bad as explained previously, it requires Google on your phone to even work. If you think Google is more trustworthy than Facebook, sure go ahead and just use Hangouts or whatever. We cant have nice good encryption and safe communication when geeks push this Signal onto unsuspecting users, when the real option is to keep improving Tox.Chat and bitmessage.

> Signal is bad as explained previously, it requires Google on your phone to even work. only for notification delivery. The message payload is not part of the push notification.

He never said it was. Google services aren't isolated like normal apps either, as far as I know they can access other app's data (when installing cyanogenmod, I had to install google apps in some weird way from the bootloader because it has to change protected things on the phone). His point of requiring google's stuff to be installed is valid, even if he wrote it thinking payload gets sent over it.

Re: WhatsApp backdoor allows snooping on encrypted messages

#24
post #11
post #9

Earlier quoted context omitted.

Which is the case with Signal as well, and this "security" feature of "google play services" is why the developer of Sigal does not want Signal to be in f-droid.org's repositories. He wants to be able to push "updates" for any future "vulnerability" onto the users of Signal.

A big reason I dont trust signal. Every single that app has some bad side, signals is the reliance on Google.

Using Signal on iOS here - what is the reliance on Google?

Re: WhatsApp backdoor allows snooping on encrypted messages

#25
Some more background:

This was presented in the lightning talks at 33c3, starting around minute 48: https://media.ccc.de/v/33c3-8089-lightning_talks_day_4

Here's the congress wiki with some more links: https://events.ccc.de/congress/2016/wiki/Lightning:A_Backdoo...

And a blogpost: https://tobi.rocks/2016/04/whats-app-retransmission-vulnerab...

Re: WhatsApp backdoor allows snooping on encrypted messages

#28

The key part is this, and it was apparently reported back in April 2016 with Facebook replying it's "expected behavior", it's not something a general attacker can do but it would enable WhatsApp/Facebook to read conversations: > WhatsApp has the ability to force the generation of new encryption keys for offline users, unbeknown to the sender and recipient of the messages, and to make the sender re-encrypt messages wi…

I don't think this is as serious as it seems, this exploit only applies to undelivered messages, which granted is not great, but is at least something.

And any WhatsApp update could potentially include code to snoop on decrypted messages so exploits that can only be performed from the WhatsApp server side - i.e the example in the article about snooping entire conversations - are not really that relevant.

Having said that, it's disappointing and they should adopt Signal's approach.

Re: WhatsApp backdoor allows snooping on encrypted messages

#30
post #22
post #12

No matter what IM service you use: As long as they manage the public keys for their users, they will be vulnerable to exactly this problem. This isn't just WhatsApp. This applies to iMessage and Signal too. In all cases, we rely on the word of the service provider that they don't sneak additional public keys to encrypt for into the clients and in all cases we hear that doing so would cause a message dialog to appear,…

'As such I think it's unfair to just complain about WhatsApp here.' I disagree. WhatsApp have a known vulnerability which they won't fix (indeed they deliberately added this vuln on top of the Signal protocol), and no denial that they have used this vulnerability in the past. They made a big PR song and dance about this feature only to backdoor it. That deserves criticism.

Exactly -- plus, the "notify key changes" setting is off by default. When I was looking through WhatsApp on my girlfriend's phone (it's useful to know what popular applications look like to be able to help others, even if I don't use them myself) I was very surprised to learn it was off by default. That's the same as disabling certificate checking on https and hoping that the pubkey you got is valid. It took me a while to believe it was actually the default and she hadn't turned it off herself (probably by accident), but it seems to be true. I just can't imagine how people call Whatsapp encrypted when whatsapp can push a new key à la "here, go encrypt your messages to this pubkey please".
Post reply on HN