Live data from Hacker News

There is no WhatsApp 'backdoor'

whispersystems.org

281–290 of 437 posts

Re: There is no WhatsApp 'backdoor'

#281

I love this post for the in-depth explanation of the UX challenges around e2e encryption and why they made the decisions they did. It's educational. I think Moxie highlights a very good point that is commonly underrated among "security Dunning-Krugers": Opening yourself to the possibility of an attack is often OK if the attack is easily detectable, and if the identity of the attacker would be obvious upon detection.…

In most cases, I'd much rather disallow Facebook from MITMing my messages than try to "ruin their reputation" (hint: I won't, because Facebook already does far worse things on a regular basis without so much as an eye-bat from the world).

In other words: I care about the confidentiality of my messages far more than the promise of some sort of dubious ability to shame Facebook for simply fulfilling its business model. Sure, there are some cases where allowing security to be exploited in one area protects the security of another, but those are called "honeypots", and I sure as hell hope my private communications are not a part of that.

Transparency is a dependency of trust. WhatsApp is not transparent; therefore, it is not trustworthy. Simple as that.

Re: There is no WhatsApp 'backdoor'

#282
post #186

Earlier quoted context omitted.

That's news to me. At least it's news that this is actually practical for any interesting cases (i.e. real crypto code). Do you have a reference?

I'm in a cab typing on my phone but good Google searches are "llvm lifter" and "symbolic execution" or "SMT".

AFAICT that's (at best) research level stuff. I'd love to be proven (heh) wrong, though. I think what lisper was after was actual practical applications, e.g. something along the lines of the CompCert C compiler[1].

[1] Which I'll note was written and verified in Coq a high-level proof-oriented language.

Re: There is no WhatsApp 'backdoor'

#283

Earlier quoted context omitted.

this requires humans to be able to generate and remember passwords with decent entropy

Pass phrases.

There is one pass phrase I remember, 5 passwords, 2 PINS, 2 phone numbers. My password manager and address book remember hundreds of passwords, phone numbers and emails each.

For some reasons everybody uses an address book, many people let browsers remember passwords but almost everybody resists the idea of using a password manager and end up with low entropy passwords.

Re: There is no WhatsApp 'backdoor'

#284
post #112
post #89

Earlier quoted context omitted.

You mean someone publishing source code and then falsely verifying the binary checksum? I mean, at the end of the day, it's very easy to verify - if the binary doesn't match what whomever gets when they compile, there better be a reason for it. Regardless, I don't think this is the biggest problem facing open source.

> if the binary doesn't match what whomever gets when they compile, there better be a reason for it. True, but deterministic compiles are stupendously difficult in most cases. Which is improving slowly, but still isn't usually an option.

Debian is up to 92% deterministic builds, so not that hard:

https://tests.reproducible-builds.org/debian/reproducible.ht...

Re: There is no WhatsApp 'backdoor'

#285
post #237

Earlier quoted context omitted.

> That defense, which happens to be the only defense, is turned off by default in WhatsApp. > You seem to argue they do so because it's bad UX to present such notification by default. That's - in my humble opinion - like suggesting browsers should turn off TLS chain errors by default because it's bad UX and just proceed with the connection as if nothing happened... One thing we've learned over the years is that secur…

At one of my jobs the network team uses a thing called "Forcepoint's TLS inspection" (aka Websense) (aka Raytheon). My browser happily let's that network team MITM me all day long without a peep, and logs & archives all my TLS traffic for who knows how long. The funny thing is a VM I setup from my same laptop tried to make an https:// connection and the browser outright refused, without any possible workaround until…

Assuming this is a laptop they assigned to you, what's wrong with any of that?

Re: There is no WhatsApp 'backdoor'

#286
post #249
post #234

Earlier quoted context omitted.

tptacek, Over the years interacting with you here on HN, I think this basically sums up the worldview that puts you and I at odds: > Open vs. closed-source software is a concern orthogonal to verifiability. Is there a place where you have written at length, defending this assertion? I am open to it. But it does not resonate with my understanding, nor my (substantial, I think) experience in deployments of open- and cl…

What do you mean by verifiablity? If you are using a casual, inspection = verification definition then I think most would agree that it is true that open source is easier to inspect. But "verified" software often means formal mathematical verification, and that is orthogonal to if the source is open.

> But "verified" software often means formal mathematical verification, and that is orthogonal to if the source is open.

I think there may be cross-talk here related to who's doing the verifying too. I think the parent is assuming "verification" would imply that a 3rd party could verify the software in question. AFAIUI it's currently nowhere near practical for a 3rd party to verify closed-source software of any non-trivial size. (Correct me, if I'm wrong, obviously.)

It's still a research problem even for open-source unless the software is built with formal verification in mind (for example in Coq or Agda), but at least there's an existence proof that it's possible to do for non-trivial software (see CompCert C). That was still a multi-year effort and it's still a somewhat (architecturally) simple program as compilers tend to be.

Re: There is no WhatsApp 'backdoor'

#287
So if the security of Whatsapp's keys hinges so much on the key change notifications, why turn them off by default? Why allow them to be turned off at all?

No one (today) would get the idea to make https warnings optional even though that audience is even broader than Whatsapp's. (Possibly even because that audience is so broad)

Re: There is no WhatsApp 'backdoor'

#288

Earlier quoted context omitted.

At one of my jobs the network team uses a thing called "Forcepoint's TLS inspection" (aka Websense) (aka Raytheon). My browser happily let's that network team MITM me all day long without a peep, and logs & archives all my TLS traffic for who knows how long. The funny thing is a VM I setup from my same laptop tried to make an https:// connection and the browser outright refused, without any possible workaround until…

Assuming this is a laptop they assigned to you, what's wrong with any of that?

If you are in Europe (or at least some countries in Europe), it's illegal to read in-transit messages even if the recipient is at work and the interceptor is their employer.

Re: There is no WhatsApp 'backdoor'

#289
post #267
post #246

Earlier quoted context omitted.

Moxie, I think it's fair to say that you are the world thought leader on these matters right now. One thing that the rest of us are wondering right now is: > I've been impressed with the level of care that WhatsApp has given to that requirement. To what degree do you really know that? Is there a place where we can read about your interactions with Facebook, the level of access they've given you, and the degree to whi…

> But there are nuances here that are important, and fleshing them out is a big part of what this community is about. The entire point of the crypto community is to maintain as little trust as possible unless you can be highly certain about things. The media reaction to "OMG WHATSAPP IS FOR SURE NOT SAFE" is a HUGE over reaction. But in an industry where audits and open source are huge factors in trust... WhatsApp do…

I think that here you've made a great point. For many users, the level of privacy that Whatsapp gives is unnecessary, but if you are the person that needs to discuss mission-critical matters over Whatsapp, they give you the possibility to do that safely.

The only problem would then be that they can MITM one message, even if they'd be caught that way. I doubt they'd do that for less than world-changing messages, but still that's the only problem if you enabled the notifications and checked the numbers.

Re: There is no WhatsApp 'backdoor'

#290
post #207

Earlier quoted context omitted.

This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. PS: I just chec…

> This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. You've just d…

So,

The problem with key notifications being off is for those users who really want to be secure, and downloaded Whatsapp because they wanted E2E, but didn't know they had to go into settings and turn it on.

The problem with key notifications on-by-default is that regular users see warnings they don't understand and get warning-fatigue.

So how about making a default-on notification that is understandable for all users? Like:

::: It seems like Alice switched to a new phone (i)

where Bob can click the (i) for more info, or just ignore the notification. If Bob was security-conscious, he'd perk up at that message, while the majority would just go "meh" or congratulate them on their new phone.

Post reply on HN