Live data from Hacker News

Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

slashcrypto.org

1–10 of 29 posts

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#2
No it is a backdoor. Becuase the app fucks you on purpose, even if you go to great lenghts to verify the keys.

Also the vulnerabilty matches perfectly one scenario - when a person is in custody, the LEO cannot open its phone, but they can create account on new device with his sim card and continue "trusted" chats.

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#4
If the title of the article is the conclusion, I really don't see how they arrive there based on the post.

If I read the post and came up with the thesis sentence myself, it would be "WhatsApp is vulnerable to MITM attacks because it tries to automate key changes by default"

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#5
It's a backdoor because it grants access (to new messages as well as any messages replayed) with explicit authorization by the application but without explicit authorization by the user.

That seems to fit the currently accepted understanding of the word: https://en.wikipedia.org/wiki/Backdoor_(computing)

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#6
This is a backdoor because it is used to fool people. In countries like Mexico, carriers do not charge your data use of fb and WhatsApp. They offer it as free social network. I am sure government is behind of such a good will to users from big companies. You get free communication in exchange from your privacy. What a nice deal!

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#7
I agree with most comments on this thread -- This is indeed a back door and it is irresponsible for someone who works in Security to claim that it is not. If the key-verification functionality that you describe were "opt-out", then you might have a case on your hands, but because it's "opt-in", the user would not know when What's App is potentially spying on them.

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#8
It is sad, and misinformative, that this article is currently #1 on HN, while the much more accurate and better-written Guardian piece "WhatsApp backdoor allows snooping on encrypted messages" is #2.

The linked piece is hard to critique because it's borderline incoherent. The "conclusion" is simply not a conclusion, particularly this passage:

> A provider always has the ability to intercept messages as long as the user does not verify fingerprints. With WhatsApp, it is even harder to make sure, no MitM takes or took place. WhatsApp is closed source, so who can tell, if WhatsApp just displays wrong identity keys and lets the user think that everything is perfectly OK ..?

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#9

No it is a backdoor. Becuase the app fucks you on purpose, even if you go to great lenghts to verify the keys. Also the vulnerabilty matches perfectly one scenario - when a person is in custody, the LEO cannot open its phone, but they can create account on new device with his sim card and continue "trusted" chats.

I understand why that is a concern for the security conscious. But for the 90% use case, e.g.: I lost my phone and got a new one. Or my phone isn't turning on and I get a new one.

I install WhatsApp. How do I roll over my identity?

The way I see it is that WhatsApp is delegating the task of identity verification to the network provider (admittedly a weak link for the security conscious). But it _is_ the easiest way for the average user to continue chats on a new phone.

If the default setting were reversed, HN would stop complaining, but the 90% would.

The most 'secure' means of communication is probably a one-time pad communicated via paper on magic ink that you then burn, or something. There is a cost to ease of use in many cases. I wish the conversation was less about right v wrong, and more about what tradeoffs should be made and where to draw the line.

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#10
This just goes to show the importance of picking sound defaults. WhatsApp gets this horribly wrong. Regardless of whether it's a backdoor, their default behaviour is dangerous because it leaves users vulnerable to MITM attacks.

Let's not get hung up on semantics, and focus on the HARM.

Post reply on HN