There is no WhatsApp 'backdoor'
301–310 of 437 posts
Re: There is no WhatsApp 'backdoor'
#302Earlier quoted context omitted.
> It'd be trivial to sign the new public key with the old private key How would these 'trivial' steps look like if a telephone gets stolen or upgraded? What easy steps did Facebook & Moxie overlook?
> How would these 'trivial' steps look like if a telephone gets stolen Just as 'trivial' as it is Facebook to swap your key at the request of a government. You should have to start from a blank slate (zero trust) in that situation. Getting your phone stolen is an extraordinary event that warrants requesting some attention from your contacts, even if only to inform them of the old identity being compromised. And then…
Buying a new phone and switching to it Reinstalling your phone OS because "it's slow" Reinstalling WhatsApp because "it crashes" or "it's slow" Swapping a phone because the screen is broke or I dropped into the toilet
I think it's romantic to think that 1 billion of WhatsApp users can be taught about the risks of MITM attacks and how to do a key check.
This is what I do: I have the warnings turn on. When the key change warning appears, and if I care enough about the person and the discussions we have, I try to match the warning with a real world event, so either I already know that something happened, or I try to remember to ask somehow if the person repaired or changed the phone. If I can match the warning with such an event, I feel satisfied. Otherwise, i ask for a key check when I meet that person in real life.
It would help if WhatsApp provided a UI to show whether I have verified the current key of each user (something like a green check-mark next to the name) because it's hard to remember.
Re: There is no WhatsApp 'backdoor'
#303Earlier quoted context omitted.
So, The problem with key notifications being off is for those users who really want to be secure, and downloaded Whatsapp because they wanted E2E, but didn't know they had to go into settings and turn it on. The problem with key notifications on-by-default is that regular users see warnings they don't understand and get warning-fatigue. So how about making a default-on notification that is understandable for all user…
they'd get that message every few weeks to month from me, as i flash a new ROM....
I would also pop up when someone reinstalled the app.
Would be rather annoying but it should be on as default and the first time it pop up give clear information.
Whatsapp is set to notify you when a key changes, this could be due to a change of phone or reinstalling the app. If you do not wish to receive these notifications click here.
Which would allow users who want it to keep and those that don't to turn it off after the first change.
Re: There is no WhatsApp 'backdoor'
#304Color me still-unconvinced. This retort does not address the fundamental point made in the Guardian piece: > “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which u…
This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. PS: I just chec…
Re: There is no WhatsApp 'backdoor'
#305Earlier quoted context omitted.
> The notification that you see in WhatsApp, Signal, SSH, PGP, or whatever is the defense. That defense, which happens to be the only defense, is turned off by default in WhatsApp. You seem to argue they do so because it's bad UX to present such notification by default. That's - in my humble opinion - like suggesting browsers should turn off TLS chain errors by default because it's bad UX and just proceed with the co…
> That defense, which happens to be the only defense, is turned off by default in WhatsApp. > You seem to argue they do so because it's bad UX to present such notification by default. That's - in my humble opinion - like suggesting browsers should turn off TLS chain errors by default because it's bad UX and just proceed with the connection as if nothing happened... One thing we've learned over the years is that secur…
I like to verify keys of my main professional contacts on WhatsApp, but it's hard to remember who you verified keys with, and then whether the key was changed since last time you verified it.
Re: There is no WhatsApp 'backdoor'
#306> That would leak information to the server about who has enabled safety number change notifications and who hasn't , effectively telling the server who it could MITM transparently and who it couldn't; something that WhatsApp considered very carefully. I am not convinced. Why should this option exist at all? Even worse, it is disabled by default. Just enable notifications for everyone and demand verification. If you…
Caveat: I have never used WhatsApp and do not know anything about its interface or options (default or otherwise). >>[The choice to make these notifications "blocking" (i.e. to require manual verification) would] leak information to the server, etc., etc. >Why should this option exist at all? The option does not exist, and should not exist. That's the author's point there. You agree with him and with WhatsApp on that…
I also think the option should not exist, but according to The Guardian article [0], the option exists: "In WhatsApp’s implementation of the Signal protocol, we have a “Show Security Notifications” setting (option under Settings > Account > Security) that notifies you when a contact’s security code has changed."
[0] https://www.theguardian.com/technology/2017/jan/13/whatsapp-...
Re: There is no WhatsApp 'backdoor'
#307Earlier quoted context omitted.
This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. PS: I just chec…
> This allows WhatsApp to MITM. If you're operating under the assumption that users aren't going to check their peers' key fingerprints, then you could just give compromised keys from the beginning -- no rekeying necessary. There's no way to protect against that scenario. That's not a fault of WhatsApp.
Re: There is no WhatsApp 'backdoor'
#308Earlier quoted context omitted.
Regardless of the merit of this specific accusational-and-denial cycle, the fact remains that Whatsapp is closed source crypto and there is no way in principle for the user to verify any security claims. I happen to trust Moxie's principles, but not as much as I distrust the relationship-with-government imperatives implied by FB's vast business interests.
There's "no way in principle"? How is this whole story not evidence to the contrary? The person who found this didn't use WhatsApp source code. Why do you feel that there's no way to verify closed-source software?
Re: There is no WhatsApp 'backdoor'
#309Earlier quoted context omitted.
The "green padlock" was not considered enough because users would not be able to differentiate it from a big lock symbol within the page. Thus we got HSTS. (There was a time when browsers would color the entire URL bar yellow to indicate https, but that went out of favor many years ago.) Moxie deserves respect for the web vulnerabilities he discovered and raised awareness about years ago, and for his general competen…
> catastrophic sacrifices to make security applications popular and viable for the "lay person" This isn't wrong, but it's unfair to bring it up without the most obvious counter-argument. PGP provides absolutely zero security to the average person, because average people don't use it. HTTPS provides lots of security to the average person, whether or not they know what the green lock means, because lots of people use…
Re: There is no WhatsApp 'backdoor'
#310Call me paranoid, but the thing which is strange to me is that Whisper talks about this defending Facebook/WhatsApp. This makes me highly suspicion my usage of Signal :-(