Live data from Hacker News

WhatsApp backdoor allows snooping on encrypted messages

theguardian.com

241–250 of 334 posts

Re: WhatsApp backdoor allows snooping on encrypted messages

#241

Nothing to worry about according to Gizmodo: > The supposed “backdoor” the Guardian is describing is > actually a feature working as intended, and it would > require significant collaboration with Facebook to be > able to snoop on and intercept someone’s encrypted > messages, something the company is extremely unlikely > to do. http://gizmodo.com/theres-no-security-backdoor-in-whatsapp-d... I, for one, certainly cann…

I hope you are being sarcastic.

Re: WhatsApp backdoor allows snooping on encrypted messages

#242

Nothing to worry about according to Gizmodo: > The supposed “backdoor” the Guardian is describing is > actually a feature working as intended, and it would > require significant collaboration with Facebook to be > able to snoop on and intercept someone’s encrypted > messages, something the company is extremely unlikely > to do. http://gizmodo.com/theres-no-security-backdoor-in-whatsapp-d... I, for one, certainly cann…

There's a there right?

Re: WhatsApp backdoor allows snooping on encrypted messages

#243

How do I know that my Android phone doesn't have a backdoor keylogging everything that I type and uploading it to Google/NSA each night? I haven't rooted and installed wireshark on this device, but even if I did it could just not send it whilst that is logging. Or, it could be that wireshark doesn't see everything. Or I just wouldn't notice as there are many packets going back and forth between my phone and Google. I…

"Life's too short to worry about privacy" is precisely the kind of attitude that normalizes increasingly invasive surveillance and inadvertently feeds into the desire of companies to glean as much information as they can from their users' data. Why does the convenience of Facebook messenger have to come at the cost of privacy?

I think it's an appropriate response to criticise a company for implementing what can only be generously interpreted as a bug, if not a backdoor, and dismissing concerns when it was pointed out to them, all the while making specious claims about being secure and lulling its users into a false sense of security. Public outrage is a powerful tool in ensuring that companies don't get too adventurous in spying on their users for fear of getting caught and called out on it.

At the risk of raising the spectre of authoritarianism, I think the folks who held on to their religious beliefs in countries that enforce/d a particular religion (or no religion), or secretly organised protests against communist regimes would gape in disbelief at the choices of the current generation to use always-on digital assistant devices, communication tools and social media platforms that have been shown to be linked with government surveillance programs. Sure, your government may be democratic and benevolent at present, but what would stop an authoritarian President from using troves of already collected data to purge the country of its "dissidents"? It's not a far-fetched concept - Why do the UK fire and rescue authorities need access to the browsing history of citizens [1]? It will be all too easy for a government with all kinds of data on its citizens to establish a "citizen value" score [2] and optimize access to healthcare and other services based on it. Just the possibility of such a dystopian future should be a cause for concern on our willingness to exchange privacy for convenience.

[1] - http://www.ibtimes.co.uk/big-brother-watching-you-every-orga...

[2] - http://www.independent.co.uk/news/world/asia/china-surveilla...

Re: WhatsApp backdoor allows snooping on encrypted messages

#245
post #130

I remember receiving the downvote brigade[1], when Moxie himself said that I should trust WhatsApp without having the source code and the ability to put it on my device. We (even a "smart" community like HN) clearly do not have the ability to think critically about security, and even when our leaders are sincere -- and I really don't mean to suggest Moxie/Signal was complicit in this move -- we still rush to defend o…

> when Moxie himself said that I should trust WhatsApp without having the source code and the ability to put it on my device. What are you talking about? All I can see there is that you asked for the source code of the QR generator and he delivered. He does not say you should trust WhatsApp.

> All I can see there is that you asked for the source code of the QR generator and he delivered.

Eh, I kind of agree with geocar's point in the original thread. Moxie shared source code to "a" QR generator. Is there any way to verify that this code is what's running inside of WhatsApp?

Re: WhatsApp backdoor allows snooping on encrypted messages

#246
post #225

Earlier quoted context omitted.

how does that help, I think tor can be blocked..?

The GFW is able to recognise Tor usage. > The firewall searches for a bunch of bytes which identify a network connection as Tor. If these bytes are found the firewall initiates a scan of the host which is believed to be a bridge. In particular the scan is run by seemingly arbitrary Chinese computers which connect to the bridge and try to “speak Tor” to it. If this succeeds, the bridge is blocked. http://www.cs.kau.se…

With all the things GFW does I wonder if they have some secret conferences or industry journals related to the firewall's algorithms and infrastructure.

Re: WhatsApp backdoor allows snooping on encrypted messages

#247
Why do we sit here and argue about whether people should use WhatsApp or Signal? It's Facebook. How can we talk about Facebook as a serious candidate for private end to end messaging when they're one of the world's biggest data brokers? Why wouldn't you just use Signal and recommend it to everyone?

Re: WhatsApp backdoor allows snooping on encrypted messages

#248

Earlier quoted context omitted.

Good point. At least as a technical person, I would like to use an open-source messaging application. Of course I'm not going to read the source code but at least I'm sure developers behind the app do not open a backdoor for someone else.

While I'm totally the same in this regard, this does feel a bit like an open-source version of the bystander effect.

I don't know what the bystander effect is, but I assume we're taking about the same thing: I often feel that everyone is, along with myself, thinking "great - open source! I'm sure someone's checking it."

Of course, the counter is that if you publish it you don't risk that someone actually is checking.

Open beats closed, but we must be careful not to think it immediately makes the code sound.

I've been thinking about this particularly recently in relation to Monzo, the will-be bank. There's no web app and slow progress on the android front. Lots of open source effort though, since they publish an API, but... That's my bank account I'm (not) giving open source developers access to.

Re: WhatsApp backdoor allows snooping on encrypted messages

#249
post #242

Nothing to worry about according to Gizmodo: > The supposed “backdoor” the Guardian is describing is > actually a feature working as intended, and it would > require significant collaboration with Facebook to be > able to snoop on and intercept someone’s encrypted > messages, something the company is extremely unlikely > to do. http://gizmodo.com/theres-no-security-backdoor-in-whatsapp-d... I, for one, certainly cann…

There's a there right?

What? You must be some sort of conspiracy theorist. Just be rational and extrapolate from your beliefs: if you admit that Facebook might do this, then why not Google, AT&T, Microsoft? There would be no end to it. Basically it would mean that all businesses are spying on you and handing the information over to the government.

I have complete faith that that is untrue based upon just the history of the last 5 years.

Re: WhatsApp backdoor allows snooping on encrypted messages

#250
post #148

Earlier quoted context omitted.

Thank you. The last link should be the source (a note to moderator).

It's news that Facebook still hasn't fixed it (and they're saying they won't fix it). What do you call a known vulnerability that can be used for eavesdropping that a company refuses to fix ? 1) A mistake 2) A bug 3) A backdoor

4) A deliberate UX trade-off that, while clearly suboptimal for the kind of people who read HN, still leaves WhatsApp's massive base of everyday users in a much better position than they were prior to integrating the Signal protocol: immune to the more mundane threats of passive mass surveillance and the exfiltration of message history from Facebook's servers.
Post reply on HN