Live data from Hacker News

There is no WhatsApp 'backdoor'

whispersystems.org

171–180 of 437 posts

Re: There is no WhatsApp 'backdoor'

#171
post #5

Color me still-unconvinced. This retort does not address the fundamental point made in the Guardian piece: > “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which u…

If you are concerned enough about the security and privacy of the app, then you should learn how to use the app. That includes learning about the indicators provided by the UI telling you about key changes, delivery notifications, and anything else the developers considered important enough to show the user.

This is design issue and has little to do with knowing how to use the app. It is poor design for a pending message to be delivered to a device whose key was changed after the message was sent.

Re: There is no WhatsApp 'backdoor'

#172
post #72

Earlier quoted context omitted.

Couldn't the server change keys after every message? The delay would be fairly small. Hold the original, change key, retransmit, change key back? Guess that is easily enough mitigated if the client won't allow switching back to the same key.

It could . I guess the point here is: Can there be a backdoor in whatsapp? Of course! Is there a backdoor on Whatsapp as described on the guardian article? No. Can the UX be improved to alert the smaller percentage of users that rely heavily on the encryption features when their communication is not being actively protected without disturbing the UX of the rest of the users? Probably yes,

No it's very different. Without further details, it sounds like it's possible for FB to switch keys and intercept all messages on everyone, all the time.

Re: There is no WhatsApp 'backdoor'

#173

Earlier quoted context omitted.

I don't think the Chris Lattner thing is a war at all. The journalist gave a reasonable effort to get a comment from Lattner, never got a response, so went with a story from a source they found trustworthy. Lattner issued a denial after the fact, and it's included near the top of the story. I guess it's possible that the journalist completely fabricated the story, but I think it's a lot more likely that either someon…

"The journalist gave a reasonable effort to get a comment from Lattner, never got a response, so went with a story from a source they found trustworthy. " Oh well, can't figure out the actual facts, better just publish whatever i do have? Seriously. Also, the "i tried to contact you" is clearly a BS defense. It wasn't a "reasonable effort". This is a reporter. They know that people basically never respond to intervie…

Yes, if you make several requests for comment over several days and don't get a response, it is acceptable to run with what you have, as long as you note those facts in the article. Also, he's switching jobs, not landing on the moon. If he has time to tweet, he has time to check his email.

If you just assume that both players in this story are human beings trying to do their jobs, you'll understand that neither of them did anything wrong.

Re: There is no WhatsApp 'backdoor'

#175
post #72

Earlier quoted context omitted.

Couldn't the server change keys after every message? The delay would be fairly small. Hold the original, change key, retransmit, change key back? Guess that is easily enough mitigated if the client won't allow switching back to the same key.

It could . I guess the point here is: Can there be a backdoor in whatsapp? Of course! Is there a backdoor on Whatsapp as described on the guardian article? No. Can the UX be improved to alert the smaller percentage of users that rely heavily on the encryption features when their communication is not being actively protected without disturbing the UX of the rest of the users? Probably yes,

> Can the UX be improved to alert the smaller percentage of users that rely heavily ... Probably yes

Hell yes! Imagine jusr changing background color and the banner "somebody spies on you." Now it's something like some checkmark somewhere looks a bit different or whatever.. I'm still not sure what when...

Re: There is no WhatsApp 'backdoor'

#177

Earlier quoted context omitted.

If you do not trust your hardware, 2FA is of no use. All communication and display can be MITMed on the untrusted computer. It gives the appearance of a normal login, but the behavior of the trusted site or system is emulated. The real username, password and 2FA authentication token is only send to the target machine by the attacker.

That's not true. It prevents replay attacks, as I said. More advanced tokens also do more. My bank uses a hardware token for signing transfers and other actions which can include a human readable message or part of the target account number, making MITM much harder.

I'd say the risk of replay attack is not proportional to the risk of authenticating and authorizing on a fully compromised machine. It's comparing a candle light with a blazing fire.

A definition issue with regard to "token": I sincerely do not think a device with display and keyboard used to sign transactions can be called "token". I'd say something like: trusted signing processor. But then again, I'm not a security specialist.

Re: There is no WhatsApp 'backdoor'

#178
post #87

Earlier quoted context omitted.

If resending undelivered messages to new keys waited for confirmation of the new key when safety number change notifications are enabled, then users without those notifications enabled would continue to immediately resend undelivered messages to new keys while users with the notifications enabled would not resend until the user manually OKed the change. The WhatsApp servers know (or can know) whether users have outst…

thats then a timing attack, but the client could replace the mesaage with a placeholder and send that immidietly, and the real message after the user approves. this way server could not know.

I think that could mostly work. The placeholder message would have to be of identical length to the original and the resent message would have to use later sequence numbers/message ids (or whatever is used to identify individual messages) so the server couldn't tell that the placeholders were placeholders.

One issue is that it would mean that, in the case of an active attack where the server substituted a key they knew in place of a legitimate new key from the user, the server would be able to decrypt the possibly-placeholder resent message and determine whether the user had notifications on. If the user didn't, they'd know that they were safe to continue to attack the user (this attack is more risky than the passive one on the blocking resend without placeholder messages protocol, of course). So, this does improve the security of the protocol for users with security notifications enabled, at the cost of making users without those notifications less safe. I'm not sure how the tradeoff should be balanced here (just as I'm unsure if the UX tradeoff of having the option of not receiving security notifications is worth it...).

Re: There is no WhatsApp 'backdoor'

#179
post #163
post #99

Earlier quoted context omitted.

> Walmart I can use cash at Walmart

And be sure to smile at the cameras watching you in the store, and the ones in the parking lot that recorded you driving in.

It's shared physical space. I'm OK if they video me. I'm OK if they share that video with law enforcement if there is a reason of substance to do so and as long as they make it publicly known they asked for it within a reasonable timeframe, say 45 days. I'm NOT OK with broad sweeping requests and would only allow them if circumstances required it and the request for the data was disclosed within 90 days.

Re: There is no WhatsApp 'backdoor'

#180
post #23

There seems to be a pretty clear war going on between engineers and journalists lately. - Chris Latter [1] vs Business Insider [2] - Elon Musk vs (Bunch of outlets) - Moxie vs The Guardian I feel like journalists want to write a compelling story and engineers are on the other side like "No, those aren't facts!" I don't follow a lot of media outlets but it seems like journalists either lack the skills or don't care ab…

Yes, because Tobias Boelter, a PhD student in cryptography is totally a journalist...
Post reply on HN