Live data from Hacker News

WhatsApp backdoor allows snooping on encrypted messages

theguardian.com

211–220 of 334 posts

Re: WhatsApp backdoor allows snooping on encrypted messages

#211
post #130

I remember receiving the downvote brigade[1], when Moxie himself said that I should trust WhatsApp without having the source code and the ability to put it on my device. We (even a "smart" community like HN) clearly do not have the ability to think critically about security, and even when our leaders are sincere -- and I really don't mean to suggest Moxie/Signal was complicit in this move -- we still rush to defend o…

> when Moxie himself said that I should trust WhatsApp without having the source code and the ability to put it on my device. What are you talking about? All I can see there is that you asked for the source code of the QR generator and he delivered. He does not say you should trust WhatsApp.

That's not what geocar asked. He didn't ask anything, actually.

Rather he pointed out that what you see in the WhatsApp UI is meaningless because you have no way of knowing that the app you're running matches the code Moxie linked, or that the code your friends are running does. Moxie replied with a link to the QR generation code but this didn't answer geocar's question, probably because there is no answer.

Here's a simple way to put it. End-to-end messaging security is assumed to be (at least traditionally) about moving the root of trust. Before you had to trust Facebook. Now you don't. A closed source app that can update on demand doesn't move the root of trust and this probably doesn't match people's intuitive expectations of what it does.

Many people have pointed out similar things to what geocar has pointed out: E2E encryption is essentially meaningless if you can't verify what your computers are actually doing. Unfortunately fixing this is a hard problem.

I wrote about this issue extensively in 2015 in the context of encrypted email and bitcoin apps (where you can steal money by pushing a bad auto update):

https://moderncrypto.org/mail-archive/messaging/2015/001510....

I proposed an app architecture that would allow for flexible control over the roots of trust of programs using sandboxing techniques. Unfortunately there's been very little (no?) research into how to solve this problem, even though it's the next step in completing the journey that Signal has started.

By the way, just to make it super clear, the work Moxie has done on both Signal and WhatsApp is still excellent. It is, as I said, necessary work. But the Guardian has unfortunately not understood security well enough, nor have people from the cryptography community really helped journalists understand the limits of this approach. Nor has Facebook, I think.

Re: WhatsApp backdoor allows snooping on encrypted messages

#212
post #178

Earlier quoted context omitted.

I'd go further and say Moxie is complicit by way of negligence. It's unethical to assist in the implementation of your protocol when you can't guarantee its privacy protections will actually stand. Otherwise it's free PR for Facebook to tout "Snowden-approved crypto". I have no doubt Moxie acted in good faith and wanted to expand encryption to a large number of users, but this is just another example of why proprieta…

> Moxie is complicit by way of negligence. I just want to voice my opinion that maybe 1 in 100 people have Moxie's integrity and ethics.

one in a billion... he's the most ethical hacker and political actor i've encountered...

Re: WhatsApp backdoor allows snooping on encrypted messages

#213
This is why you should never trust proprietary secure messaging solutions that offer you both the client and the channel.

The future of trusted secure messaging will be open source, auditable, independent non-native clients that connect and send over third party message channels independently.

See https://www.seecret.io

Re: WhatsApp backdoor allows snooping on encrypted messages

#214
post #169

Earlier quoted context omitted.

It makes WhatsApp effectively not E2E encrypted. All messages can be recovered by Facebook. How is that NOT a backdoor?

All messages, sent while a person is offline. It is bad, but not nearly as bad as "all messages"

It is in fact all messages. They can simply not deliver the first message and force a resend record that mesaage. Afterwards force again a resend with the old encryption key and deliver that mesaage. No one would get a notification.

Re: WhatsApp backdoor allows snooping on encrypted messages

#215
post #169

Earlier quoted context omitted.

It makes WhatsApp effectively not E2E encrypted. All messages can be recovered by Facebook. How is that NOT a backdoor?

All messages, sent while a person is offline. It is bad, but not nearly as bad as "all messages"

Can't they (WhatsApp) simulate a user being offline?

Re: WhatsApp backdoor allows snooping on encrypted messages

#216
post #30
post #22

Earlier quoted context omitted.

'As such I think it's unfair to just complain about WhatsApp here.' I disagree. WhatsApp have a known vulnerability which they won't fix (indeed they deliberately added this vuln on top of the Signal protocol), and no denial that they have used this vulnerability in the past. They made a big PR song and dance about this feature only to backdoor it. That deserves criticism.

Exactly -- plus, the "notify key changes" setting is off by default. When I was looking through WhatsApp on my girlfriend's phone (it's useful to know what popular applications look like to be able to help others, even if I don't use them myself) I was very surprised to learn it was off by default. That's the same as disabling certificate checking on https and hoping that the pubkey you got is valid. It took me a whi…

> plus, the "notify key changes" setting is off by default

that's the thing: That setting is pure placebo security-theater. There's nothing to guarantee that this setting actually causes notification on all key changes, whether it's on or off.

Knowing that we all have trouble trusting Facebook, we can assume that all this setting does is inform users when their counterpart has a new phone (which in itself is a very slight privacy issue. I might not want you to know that I have a new phone / reinstalled WhatsApp).

It won't inform users when Facebook adds another public key for analytics and it also won't inform when the NSA adds a key through their special surveillance interface Facebook built for them.

That's the issue with all IM services that manage public keys for their users and thus, my original point was that it's pointless to rage against WhatsApp alone.

Worse: Let's say they change the default due to the present outrage: Then everybody will be pleased with them while the actual backdoor remains in place.

Re: WhatsApp backdoor allows snooping on encrypted messages

#217
post #150

I'm not a crypto guy, but I'm trying to understand how this backdoor could be used by governments or WhatsApp/Facebook itself. I'm not entirely sure how such an attack based on this backdoor would work. The article says that WhatsApp servers have the ability to trigger the clients to generate new keys, but even with new keys how can the server read the messages at all? Has the server got a copy of the new generated k…

I'm trying to understand this same thing. I don't see why triggering a client to generate new keys is a problem. Giving the client keys to use is a problem, but that's not what it's saying.

Edit: it is described much better here: https://tobi.rocks/2016/04/whats-app-retransmission-vulnerab...

The idea is that in addition to the keys being regenerated, the recipient phone is spoofed (a key point not mentioned). So the FBI could tell the Whatsapp company to generate a fake recipient phone and connect the sender phone to that phone instead.

Re: WhatsApp backdoor allows snooping on encrypted messages

#218
post #190

Earlier quoted context omitted.

Good point, but there is an explanation: blocking WhatsApp would lead to more intense backlash. See what happened in Brazil. Not to say it isn't both, but the price of blocking (one of) the most popular messaging apps is higher to a government than blocking one in the low low percentiles of usage.

Can you make an unblockable app?

check out Ricochet. If i recall correctly, it uses blockchain type transport over tor.

Re: WhatsApp backdoor allows snooping on encrypted messages

#220
post #47

Well, I kind of feel that I have to repost my comment on this old thread[1] with regards to the government of Egypt blocking Signal application: "Isn't it "weird" that they chose to block Signal app and not the signal-protocol based Whatsapp? If Whatsapp really implements the same kind of security and privacy measures that Signal does, why is Whatsapp allowed to continue operating? If signal is preventing them spy on…

Simple explanation would be that activists use Signal. [1] They don't trust WhatsApp and rely on Signal for secure messaging. Blocking Signal means they are able to target activists without impacting much of the rest of the population. [1] Many of the people I know who are activists in countries where they need to protect their identities use Signal

Also that the folks in the government doing the banning probably use WhatsApp themselves to conduct business and do their jobs.
Post reply on HN