'Given the size and scope of WhatsApp's user base, we feel that their choice to display a non-blocking notification is appropriate. It provides transparent and cryptographically guaranteed confidence in the privacy of a user's communication, along with a simple user experience. The choice to make these notifications "blocking" would in some ways make things worse. That would leak information to the server about who h…
There is no WhatsApp 'backdoor'
221–230 of 437 posts
Re: There is no WhatsApp 'backdoor'
#222'Given the size and scope of WhatsApp's user base, we feel that their choice to display a non-blocking notification is appropriate. It provides transparent and cryptographically guaranteed confidence in the privacy of a user's communication, along with a simple user experience. The choice to make these notifications "blocking" would in some ways make things worse. That would leak information to the server about who h…
Huh? Isn't that exactly how it is now?
Re: There is no WhatsApp 'backdoor'
#223'Given the size and scope of WhatsApp's user base, we feel that their choice to display a non-blocking notification is appropriate. It provides transparent and cryptographically guaranteed confidence in the privacy of a user's communication, along with a simple user experience. The choice to make these notifications "blocking" would in some ways make things worse. That would leak information to the server about who h…
You quoted the answer to that already. If these change notices are "blocking", then the sending device won't re-send the message until the user has verified it. If the user hasn't enabled the notification, then the sending device will re-send immediately. This makes it trivial for the server to figure out who's actually enabled the notifications and who hasn't, which means the server can be confident about when it's…
Re: There is no WhatsApp 'backdoor'
#224Earlier quoted context omitted.
> This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. You've just d…
> That way the server has no knowledge of who it can MITM without getting caught. What exactly do you think is the worst thing that could happen if you "catch" them doing this? Now what do you think is the worst thing that could happen if they receive a subpoena or NSL or whatever that tells them to do this regardless of whether the user finds out or not (because the government wants the message contents that badly)?…
[I'm not the OP, but my 0.02]: Hopefully there would be an outcry, initially started by technically sophisticated communities like this, and credible articles in the Guardian, eventually causing significant user anger, and letting competitors gain against them. People running social networks care about mass user anger.
Hopefully that possibility keeps them honest.
Hopefully people don't cry wolf too many times, like today - slowly poisoning the watchdog!
> Now what do you think is the worst thing that could happen if they receive a subpoena or NSL or whatever that tells them to do this regardless of whether the user finds out or not (because the government wants the message contents that badly)?
This has got to primarily be a defense against ongoing mass surveillance. If the government can compel them (via NSL or force or whatever) to change the service so that it just spies on a few targeted individuals, wouldn't it be easier to push these individual a malicious client update, rather than MITM the encryption and hope they have notifications off?
Does anyone know how to build a massively adopted network that resists targeted NSLs? I'm grateful we appear to have one that is resistant to pervasive monitoring.
Re: There is no WhatsApp 'backdoor'
#225Earlier quoted context omitted.
This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. PS: I just chec…
> This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. You've just d…
I'm not sure what exactly is the reason for that, is it UX? like if someone get a new phone and creates a new key pair their friends will get scared because of the warnings?
> Even if they were on by default, a fact of life is that the majority of users will probably not verify keys. That is our reality.
Another fact of life are bad password choices, which is why gmail don't let you use "love", "sex" and "secret" as a password :)
Browsers, for instance, throw warnings when something is wrong with a cert. Even when 99% of the time it's some domain name issue or expiration date, I think it's a nice default. By letting Facebook rekey anytime you (fig) are making them kind of a CA. I don't think there is a good reason for that, specially not when Whatsapp claims that even they can't read your messages... it feels dishonest to me. But then again this is just a messaging app downloaded from Google Play running on Android, my expectations aren't too high...
Re: There is no WhatsApp 'backdoor'
#2261. handle new keys the same way Chrome handles expired SSL certs: a big warning with the option to continue anyway if you want
2. Don't automatically resend a message with a new key (require the user to manually resend, like when iMessage falls back on MMS)
3. enable the key change notifications and make disabling them an "advanced" setting
WhatsApp is making the right choice by designing for ease of use, I think they just landed a little too far away from a secure implementation.
Re: There is no WhatsApp 'backdoor'
#227Earlier quoted context omitted.
Yes, if you make several requests for comment over several days and don't get a response, it is acceptable to run with what you have, as long as you note those facts in the article. Also, he's switching jobs, not landing on the moon. If he has time to tweet, he has time to check his email. If you just assume that both players in this story are human beings trying to do their jobs, you'll understand that neither of th…
Several days? The news of his departure isn't even several days old. Even if he asked lattner to comment five minutes after his email to the swift list, that wasn't a reasonable time to wait before publishing.
Re: There is no WhatsApp 'backdoor'
#228Earlier quoted context omitted.
This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. PS: I just chec…
> This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. You've just d…
Moxie, some of us are of the opinion that [that] (implied) goal is certainly noble but ill-considered.
Modern state surveillance has 2 general unstated goals:
1) Create an atmosphere of fear to affect self-censorship. Some states (such as China) announce this as a matter of state policy. Others (such as US) drop hints. UK is somewhere in between.
2) Identify emerging memes, clusters, and thought leaders. This information is then used to counter, disrupt, and discredit/isolate (respectively).
(And yes, the stated public goals are to prevent terrorism, child pornography, and crimes.)
From the political angle -- activist angle, if you will -- the goal of "serving billions of people from many different demographics all over the world" is minimally misguided, and counter productive, and maximally a hazard.
Re: There is no WhatsApp 'backdoor'
#229Earlier quoted context omitted.
You're right. Everyone is fallible and I'm all for mistakes being made — We are all human. I also agree that the immediate snap response tells us nothing. Based on the BI story, I know a few people that have actually already uninstalled WhatApp for fear of a backdoor. What I wish is that there was a better way for these two entities to communicate rather than finger pointing and name calling so that we as consumers o…
Name calling results in reassigning fear. People are afraid of the unknown and so try to box it up in something digestible they can fear less. We tend to blame others because it's easy and cheap to do so. If you are wrong, that means I'm right and so then I wasn't wrong about it and don't have to think about it anymore. And you are wrong, so why would I think about it again? I think it's interesting the entities are…
I know this isn't your point, but we don't know Musk; we know his (intentionally, carefully curated) public image
Re: There is no WhatsApp 'backdoor'
#230What is the user supposed to do when they get notified of a "safety number changed" message? How do they verify they've not just been MITM? Honest question... I don't use whatsapp or signal at all.
A few would inquisitively ask "Yes, how did you know?", then I would explain them to them the notification I got.