WhatsApp backdoor allows snooping on encrypted messages
131–140 of 334 posts
Re: WhatsApp backdoor allows snooping on encrypted messages
#132Earlier quoted context omitted.
Aren't all messages undelivered, until they are?
Hehe, yes, but the point is this: if you had verified fingerprints with Bob and are happily chatting with him, all the messages that reached him (two tick marks in WhatsApp) are safe. Only those that have not yet been delivered (one tick mark) would, when the server sends you you a new key, be re-encrypted and re-sent. All of this, as usual, is predicated on the client behaving as promised.
Boelter said: “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which users might not notice. Using the retransmission vulnerability, the WhatsApp server can then later get a transcript of the whole conversation, not just a single message.”
I frankly didn't understand what was said here.
Re: WhatsApp backdoor allows snooping on encrypted messages
#133I remember receiving the downvote brigade[1], when Moxie himself said that I should trust WhatsApp without having the source code and the ability to put it on my device. We (even a "smart" community like HN) clearly do not have the ability to think critically about security, and even when our leaders are sincere -- and I really don't mean to suggest Moxie/Signal was complicit in this move -- we still rush to defend o…
EDIT:
Sorry, misread.
Re: WhatsApp backdoor allows snooping on encrypted messages
#134Earlier quoted context omitted.
I thought that was the whole point of end-to-end. That you don't need trust in the server because the messages are opaque. If this is an exploit that can be performed by a compromised server, it's very much relevant
So, just to clarify my understanding: Basically, what we have here is a weakness in the client , namely a provision that allows the server to send the client a fresh key and ask for re-encryption and re-sending with the new key. This, in turn, would allow for a good old MITM attack if the server were to be compromised. This re-encryption and re-sending of messages would be without intervention by the user, though a m…
IMO they have been since they joined Facebook.
Re: WhatsApp backdoor allows snooping on encrypted messages
#135I remember receiving the downvote brigade[1], when Moxie himself said that I should trust WhatsApp without having the source code and the ability to put it on my device. We (even a "smart" community like HN) clearly do not have the ability to think critically about security, and even when our leaders are sincere -- and I really don't mean to suggest Moxie/Signal was complicit in this move -- we still rush to defend o…
Not sure if I understood you well: do you imply that Moxie was involved in creating this backdoor? EDIT: Sorry, misread.
That is why I said I really don't mean to suggest Moxie/Signal was complicit in this move
Re: WhatsApp backdoor allows snooping on encrypted messages
#136Well, I kind of feel that I have to repost my comment on this old thread[1] with regards to the government of Egypt blocking Signal application: "Isn't it "weird" that they chose to block Signal app and not the signal-protocol based Whatsapp? If Whatsapp really implements the same kind of security and privacy measures that Signal does, why is Whatsapp allowed to continue operating? If signal is preventing them spy on…
Simple explanation would be that activists use Signal. [1] They don't trust WhatsApp and rely on Signal for secure messaging. Blocking Signal means they are able to target activists without impacting much of the rest of the population. [1] Many of the people I know who are activists in countries where they need to protect their identities use Signal
I would never trust a closed source messaging app if I was an activist, regardless of what encryption they claim to implement.
Re: WhatsApp backdoor allows snooping on encrypted messages
#137Earlier quoted context omitted.
Well there are two possible scenarios I can envisage. a) The issue was an oversight and simply a bug that needs to be fixed. The question is why FB doesn't want it fixed? b) Moxie knew that this issue existed but was NDA'ed into leaving it there for nefarious purposes. Now it's public knowledge, where do we go from here?
This exploit is not in the original Signal protocol, and was introduced by WhatsApp. Signal discards undelivered messages when the encryption key changes, WhatsApp implemented re-transmission because they think it improves usability. It does do that, and it also introduces this security risk. It says so right in the article. Stop spreading FUD.
Re: WhatsApp backdoor allows snooping on encrypted messages
#138Re: WhatsApp backdoor allows snooping on encrypted messages
#139I remember receiving the downvote brigade[1], when Moxie himself said that I should trust WhatsApp without having the source code and the ability to put it on my device. We (even a "smart" community like HN) clearly do not have the ability to think critically about security, and even when our leaders are sincere -- and I really don't mean to suggest Moxie/Signal was complicit in this move -- we still rush to defend o…
I have no doubt Moxie acted in good faith and wanted to expand encryption to a large number of users, but this is just another example of why proprietary software cannot be trusted.
Any and all proprietary implementations of the Signal protocol are now suspect. OWS should denounce these implementations as least as firmly as they do interoperable open source Signal client forks.
Re: WhatsApp backdoor allows snooping on encrypted messages
#140Well, I kind of feel that I have to repost my comment on this old thread[1] with regards to the government of Egypt blocking Signal application: "Isn't it "weird" that they chose to block Signal app and not the signal-protocol based Whatsapp? If Whatsapp really implements the same kind of security and privacy measures that Signal does, why is Whatsapp allowed to continue operating? If signal is preventing them spy on…
This is a nice idea, but it's also baseless speculation. You're implying that WhatsApp, Inc. gave the Egyptian government the ability to remotely retrigger this backdoor whenever they want to (for those who haven't actually read the article: this backdoor only works when WhatsApp issues a key change for a conversation, and only then in certain circumstances). In other words, you imply that Egypt said "Hey WhatsApp, p…
It doesn't have to be THIS particular backdoor. "Why build one when you can build two at twice the price? Only, this [second] one can be kept secret."