Live data from Hacker News

Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

slashcrypto.org

21–29 of 29 posts

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#21

I do not see this as an actual rebuttal to the idea of it being a backdoor. The article makes two points: 1. Ultimately, verification falls to the user, so even in a secure system, user error, misunderstanding, and/or laziness can result in becoming compromised 2. Clients can lie to us anyway The point about this "backdoor" business is that the WhatsApp client does not even give the user the chance to even make a mis…

The 'remote actor' could always do this though, as there is another 'backdoor', that you and I call the App Store/Play Store, whereby Facebook can push whatever updates they please - including one that could send your decrypted messages back to Facebook - without you knowing as WhatsApp is closed source.

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#22

I do not see this as an actual rebuttal to the idea of it being a backdoor. The article makes two points: 1. Ultimately, verification falls to the user, so even in a secure system, user error, misunderstanding, and/or laziness can result in becoming compromised 2. Clients can lie to us anyway The point about this "backdoor" business is that the WhatsApp client does not even give the user the chance to even make a mis…

[deleted]

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#23
post #14
post #8

It is sad, and misinformative, that this article is currently #1 on HN, while the much more accurate and better-written Guardian piece "WhatsApp backdoor allows snooping on encrypted messages" is #2. The linked piece is hard to critique because it's borderline incoherent. The "conclusion" is simply not a conclusion, particularly this passage: > A provider always has the ability to intercept messages as long as the us…

Apart from the horrifying punctuation, I can't see how the quoted paragraph is technically incorrect. Some kind of real-world validation is required before you can trust that a public key really represents a given entity (at least, that's how I'm interpreting "verify fingerprints") and so it follows that if users don't validate the public keys of their correspondents, they can't know for sure that their conversations…

The paragraph is correct but misses the point.

Whatsapp will re-transmit messages with a key provided by whatsapp without ever giving the user the option to verify that key. Even with the opt-in, the message will be re-transmitted. All the opt-in ensures is that you are notified of the key change (a notification you receive after the message has already been re-transmitted under the new key)

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#24

This just goes to show the importance of picking sound defaults. WhatsApp gets this horribly wrong. Regardless of whether it's a backdoor, their default behaviour is dangerous because it leaves users vulnerable to MITM attacks. Let's not get hung up on semantics, and focus on the HARM.

I should point out that even with the 'correct' setting (which isn't default) whatsapp will still re-encrypt and re-transmit any unsent messages under the new key. All the 'correct' setting does is notify you of the key change.

The article is factually wrong on this.

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#25
post #9

No it is a backdoor. Becuase the app fucks you on purpose, even if you go to great lenghts to verify the keys. Also the vulnerabilty matches perfectly one scenario - when a person is in custody, the LEO cannot open its phone, but they can create account on new device with his sim card and continue "trusted" chats.

I understand why that is a concern for the security conscious. But for the 90% use case, e.g.: I lost my phone and got a new one. Or my phone isn't turning on and I get a new one. I install WhatsApp. How do I roll over my identity? The way I see it is that WhatsApp is delegating the task of identity verification to the network provider (admittedly a weak link for the security conscious). But it _is_ the easiest way f…

The nice solution here that would please security-conscious people with an opt-in would be for that opt-in to prevent automatic re-encryption and re-transmission under the new key.

To expand on the example given above, if the police get your phone, turn it off and wait for a while. You might have quite a few incoming unreceived messages. They can then simply take the sim, put it in a new phone, and register that with whatsapp. They can then read all messages sent to you since they turned of your phone.

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#26
post #20
post #18

Earlier quoted context omitted.

It's actually very accurate technically. The Guardian article seems to miss the basic point. The encryption in WhatsApp and Signal and Apple messaging all are all built to protect data from others in transit not necessarily from the service provider itself. No system where a central service provider manages both key infrastructure and message delivery can ever be secure from MITM by the service provider unless you do…

But the actual point here is the retransmission vulnerability. That's what makes WhatsApp different. That's the backdoor.

I edited the article because I really missed this point, you are right. I thought WhatsApp is not sending the message which got encrypted with the new key. But still, I would not say this is a backdoor, because the user has a relatively easy way to check the keys. If WhatsApp would like to implement a backdoor, they would have done it in a different way I think.

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#27
post #23
post #14

Earlier quoted context omitted.

Apart from the horrifying punctuation, I can't see how the quoted paragraph is technically incorrect. Some kind of real-world validation is required before you can trust that a public key really represents a given entity (at least, that's how I'm interpreting "verify fingerprints") and so it follows that if users don't validate the public keys of their correspondents, they can't know for sure that their conversations…

The paragraph is correct but misses the point. Whatsapp will re-transmit messages with a key provided by whatsapp without ever giving the user the option to verify that key. Even with the opt-in, the message will be re-transmitted. All the opt-in ensures is that you are notified of the key change (a notification you receive after the message has already been re-transmitted under the new key)

I edited this part, you are definitely right.

Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor

#29
post #20
post #18

Earlier quoted context omitted.

It's actually very accurate technically. The Guardian article seems to miss the basic point. The encryption in WhatsApp and Signal and Apple messaging all are all built to protect data from others in transit not necessarily from the service provider itself. No system where a central service provider manages both key infrastructure and message delivery can ever be secure from MITM by the service provider unless you do…

But the actual point here is the retransmission vulnerability. That's what makes WhatsApp different. That's the backdoor.

Look if WhatsApp wants to read your messages without you detecting, there's nothing you can really do to prevent it apart from not using WhatsApp.

For instance if you're on some list for message interception, they can give you MITMed keys when you first login. Or they can insert some subtle signal that tells the app on your specific phone to ignore key changes and avoid showing notification in some way you would struggle to check (closed source and obfuscated code) etc etc. They could even show you the right key if you attempt verification but use a compromised one for communication. This particular vuln. would be a ridiculously crude way to intercept messages.

To repeat, in any system where key distribution and message distribution are centralized, there is no way to protect against the service provider - and anyone who co-opts the service provider (eg. with a court order). The objective of the encryption is to protect against other actors snooping on you

Post reply on HN