Earlier quoted context omitted.
Votes aren't why that comment is dead --- note that it doesn't say "flagged". There is stuff that happens behind the scenes that [deads] users, especially new accounts; I think some of it might be voting ring related but not sure. (That comment is incorrect but I agree with you that it's constructive).
It seems to have come back from the dead too :-)
There is no WhatsApp 'backdoor'
191–200 of 437 posts
Re: There is no WhatsApp 'backdoor'
#192If you need a truly secure communication system, it has to be open source and self-hosted. You still have to trust the hardware though.
Re: There is no WhatsApp 'backdoor'
#193So full-on paranoia mode on: What would you do if you wanted to compare safety numbers? I'm guessing most people would call and read out the code. How far are we from targeted interception of calls, with replacement of key phrases? Voice synthesis seems to be there more or less, if I understood Adobe's recent demo correctly, but real-time parsing of conversations to determine where to intervene is probably not close…
Re: There is no WhatsApp 'backdoor'
#194Color me still-unconvinced. This retort does not address the fundamental point made in the Guardian piece: > “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which u…
This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. PS: I just chec…
They claimed that once a message has been delivered (double check mark),.
> The only notification might be that rekeying warning
The rekeying warning is a fundamental part of WhatsApp's security. If it's disabled, there are many possible attacks, not just this one. The blog entry explains it pretty well.
Re: There is no WhatsApp 'backdoor'
#195Earlier quoted context omitted.
He does address this: Once the sending client displays a "double check mark," it can no longer be asked to re-send that message. That means a user is able to verify visually that the end-to-end is working. "users might not notice" doesn't seem to me as a strong argument to state this as a backdoor. This would imply not noticing that you don't have a green padlock on chrome is a backdoor too, and it clearly is not.
The "green padlock" was not considered enough because users would not be able to differentiate it from a big lock symbol within the page. Thus we got HSTS. (There was a time when browsers would color the entire URL bar yellow to indicate https, but that went out of favor many years ago.) Moxie deserves respect for the web vulnerabilities he discovered and raised awareness about years ago, and for his general competen…
I call those "completely reasonable compromises".
Re: There is no WhatsApp 'backdoor'
#196Earlier quoted context omitted.
A little. Without reading the Guardian piece, I wouldn't even guess that delivery notifications have anything in common with security properties. In other words, the messages are secure only when there is a double checkmark, not just a single checkmark. How am I supposed to know that?!? I am not even sure what do the checkmarks mean. Frankly, that's not a "backdoor", that's just a poorly thought out GUI (in my opinio…
The single/double checkmark is used with Signal's client as well. When you're sending unsecured texts, you get a single checkmark when you send it; when you are sending encrypted messages, a lock symbol and a single check when sent, and a double check when received.
Re: There is no WhatsApp 'backdoor'
#197Earlier quoted context omitted.
Have you ever heard of the obfuscated C contest? Even with the code in front of your face and looking innocent it's hard to see what it does. When you only have decompiled assembly, obfuscation is much easier.
At the binary level, obfuscation is powerful but obvious . Is iOS WhatsApp meaningfully obfuscated?
Re: There is no WhatsApp 'backdoor'
#198Earlier quoted context omitted.
This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. PS: I just chec…
> This is contrary to WhatsApp's claim that even they cannot snoop. They claimed that once a message has been delivered (double check mark),. > The only notification might be that rekeying warning The rekeying warning is a fundamental part of WhatsApp's security. If it's disabled, there are many possible attacks, not just this one. The blog entry explains it pretty well.
And the "fundamental part" is disabled by default...
Re: There is no WhatsApp 'backdoor'
#199Earlier quoted context omitted.
This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. PS: I just chec…
I'm confused. The way I understand it is that once the double checkmark appears, those messages are locked in and never rekeyed. That means once you see those checkmarks, you're guaranteed no one can snoop on that message anymore. Assuming you have the notification on (Which anyone who cares about security could and should turn on), once you see a warning, you could just delete all messages that don't have the double…
The double checkmark stuff the blog talks about just means you cannot retroactively rekey already sent (old) messages. WhatApp inserting itself as a MITM can however read (and double checkmark) and new messages after they did the MITM rekeying
Re: There is no WhatsApp 'backdoor'
#200I take this blog post as confirmation that: 1) ANY one message can be intercepted even if the sender exhibits ideal levels of alertness [Whatsapp server drops message to recipient; sends a rekey request with a fake key; message is intercepted since fake key was generated by server. Sender will see a warning if they turned on that setting (default is to show no warning), but it's too late]. 2) Only Whatsapp has this v…
Let's consider three other facts:
1.) WhatsApp is owned by Facebook. This is a company that's has publicly said through a former, nepotistically appointed director that privacy needs to 'go away'. Their sole purpose is to extract as much PII from users as possible for resale. Offering a completely private messaging service doesn't seem to be in their financial interest.
2.) There is no way to independently verify anything being claimed by Moxie/Facebook. No WhatsApp specific source code - which is clearly different from Signal - why? Furthermore, no view into the infrastructure at Facebook. The latter is more reasonable, but seriously, why are we trusting a company whose CEO calls its users "Dumb fucks" for trusting it with their data?
3.) The Client is updated regularly through auto updates, so it seems possible that many of these notifications could simply be bypassed based on Moxie's own described MITM attack.
Moxie, fuck your blog post. It has some decent points, but helping Facebook is probably the opposite of what decent privacy advocates should be doing. More likely you've helped them be more covert about doing evil shit than helping users. Hope you enjoyed the cheque though.