Live data from Hacker News

There is no WhatsApp 'backdoor'

whispersystems.org

1–10 of 437 posts

Re: There is no WhatsApp 'backdoor'

#3
tl;dr to me seems: Since users can change devices, they'll need to reissue key material, this needs to be supported. WhatsApp reports key changing optionally, but doesn't tell the server that happened.

If WhatsApp tries to backdoor a channel and one of the users has key change notification, they'll find out about it, and WhatsApp has no idea whether the warning was shown.

Re: There is no WhatsApp 'backdoor'

#5
Color me still-unconvinced.

This retort does not address the fundamental point made in the Guardian piece:

> “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which users might not notice. Using the retransmission vulnerability, the WhatsApp server can then later get a transcript of the whole conversation, not just a single message.”

Re: There is no WhatsApp 'backdoor'

#6

tl;dr to me seems: Since users can change devices, they'll need to reissue key material, this needs to be supported. WhatsApp reports key changing optionally, but doesn't tell the server that happened. If WhatsApp tries to backdoor a channel and one of the users has key change notification, they'll find out about it, and WhatsApp has no idea whether the warning was shown.

If I understand correctly, the default is no key change notification. So for the majority of users, MITM would go unnoticed here.

Re: There is no WhatsApp 'backdoor'

#7

tl;dr to me seems: Since users can change devices, they'll need to reissue key material, this needs to be supported. WhatsApp reports key changing optionally, but doesn't tell the server that happened. If WhatsApp tries to backdoor a channel and one of the users has key change notification, they'll find out about it, and WhatsApp has no idea whether the warning was shown.

> If WhatsApp tries to backdoor a channel and one of the users has key change notification, they'll find out about it

The problem is that the might not find about out retransmissions. You are trusting that the "double-tick" means that the message won't be resent, but presumably WhatsApp can indeed retransmit those messages with the new key under pressure from a state actor.

They need to specifically address this point; it's the only thing worth talking about. The rest is just a discussion of implementation of key exchanges generally.

Re: There is no WhatsApp 'backdoor'

#8
What is the user supposed to do when they get notified of a "safety number changed" message? How do they verify they've not just been MITM? Honest question... I don't use whatsapp or signal at all.

Re: There is no WhatsApp 'backdoor'

#9
>The WhatsApp clients have been carefully designed so that they will not re-encrypt messages that have already been delivered. Once the sending client displays a "double check mark," it can no longer be asked to re-send that message. This prevents anyone who compromises the server from being able to selectively target previously delivered messages for re-encryption.

Can this be verified? Can this be verified to be the case 100% of the time? Is there anything stopping the client from lying to a user [0] with this interface, saying one thing (i.e. "this will not be resent") and doing another (i.e. resending)?

[0] - Or being triggered to lie to a particular user at a particular time.

Re: There is no WhatsApp 'backdoor'

#10
post #6

tl;dr to me seems: Since users can change devices, they'll need to reissue key material, this needs to be supported. WhatsApp reports key changing optionally, but doesn't tell the server that happened. If WhatsApp tries to backdoor a channel and one of the users has key change notification, they'll find out about it, and WhatsApp has no idea whether the warning was shown.

If I understand correctly, the default is no key change notification. So for the majority of users, MITM would go unnoticed here.

I believe that you get a key change notification, but by default it doesn't require any sort of confirmation and will just continue to work with the new key.
Post reply on HN