Earlier quoted context omitted.
Regardless how the comment tries to work around it, cognitive deficit is in fact rude.
You didn't even bother to respond to the content of my post, rather you're more concerned with some weird sense of decorum. We all have cognitive deficits, but it is not necessarily rude to point out when one's mental faculties are failing.
There is no WhatsApp 'backdoor'
411–420 of 437 posts
Re: There is no WhatsApp 'backdoor'
#412Earlier quoted context omitted.
> But there are nuances here that are important, and fleshing them out is a big part of what this community is about. The entire point of the crypto community is to maintain as little trust as possible unless you can be highly certain about things. The media reaction to "OMG WHATSAPP IS FOR SURE NOT SAFE" is a HUGE over reaction. But in an industry where audits and open source are huge factors in trust... WhatsApp do…
> But I trust Moxie a lot What does trust have to do with this? The trade-off has been clearly explained. As it stands, WhatsApp is great for protecting sexts and low value conversations if you're not famous (99.99% of everyone), but if you're snowden, or hillary, there is no protection - contrary to what has been advertised.
To my understanding, that's simply not true. What you can accurately say is that with key change notifications turned on, any one* message could be exposed without any means of recourse, but subsequent exposures would require user error.
*Question for anyone: could this apply to a "batch" of messages? That is, could servers hold back the delivery of some number of messages and then the attack could be applied to all such undelivered messages? But once the attack took place, the double check would be displayed on the sender's phone and the notification of key change would appear. My understanding is that the answer to the question is 'Yes'.
Re: There is no WhatsApp 'backdoor'
#413Earlier quoted context omitted.
Why not phase the message differently, e.g. "It looks like (user) is chatting from a new device. Is this correct?" Warning about unusual account activity seem to be very common these days, so why not using them here. The way the warnings are presented as part of the chat history (a very good idea) also means they could be used after-the-fact to figure out when an account was overtaken, even if the warning was initial…
> Why not phase the message differently, e.g. "It looks like (user) is chatting from a new device. Is this correct?" Because of exactly what Moxie said in his post. This is a relatively common occurrence in practice. Someone gets a new device. Or uninstalls/reinstalls the WhatsApp app. Or wants to read messages on their laptop, too. And so on. Warning everyone about this all the time leads to people becoming subconsc…
Re: There is no WhatsApp 'backdoor'
#414Earlier quoted context omitted.
Reference? I've worked at several companies claiming they are allowed to do this (which I don't necessarily believe, of course). Has it been tested in court?
See eg http://btlj.org/data/articles2015/vol26/26_2/26-berkeley-tec... p 1030-1031 for Germany and France. Also: https://en.wikipedia.org/wiki/Nokia#Lex_Nokia
"In Europe, there is technically no uniform body of “European law” that directly applies between employers and employees"
"Courts and scholars increasingly reference EU law, usually without clarifying whether the existence of a particular civil right protection in the EU Charter actually changed the legal situation as a matter of law, rather than as a matter of public policy."
There's a lot of fuzziness around implementation of a very loosely worded human rights clause, combined with prior national laws. Mostly aimed at protection from Government. Previous tests have mostly been cases where the individual did not consent or some such thing.
More directly, EC data protection directive hinges on: 1) contractual obligation; 2) consent; 3) statutory obligations; 4) balancing test. It seems highly likely that most business can legally MITM me if I sign the contract they want me to sign.
Most - but not all - of the private sector examples given (including Germany and France) hinge on the employer not following the correct process: either not notifying the employees, not gaining consent, or opting to allow private communications at work which are strictly forbidden from being monitored (in some countries).
That said, there is also:
"A number of EC member states, including Germany, Italy, the Netherlands, Spain, and the United Kingdom, strictly prohibit ongoing monitoring of employee communications and permit electronic monitoring only in very limited circumstances (e.g., where an employer already has concrete suspicions of wrong-doing against particular employees),265 subject to significant restrictions with respect to the duration, mode, and subjects of the monitoring activities"
It's not immediately clear if the applies to specific, targeted monitoring. The footnote says gives an example where informing the employee of valid reasons for investigating is sufficient.
Re: There is no WhatsApp 'backdoor'
#415Color me still-unconvinced. This retort does not address the fundamental point made in the Guardian piece: > “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which u…
This allows WhatsApp to MITM. Whatapps can rekey both Alice and Bob, decrypt both their messages from that point onwards (incl unsent messages) and forward them re-encrypted with their real keys. The only notification might be that rekeying warning, if the users have turned it on. In this scenario even the double-checkmarks are present. This is contrary to WhatsApp's claim that even they cannot snoop. PS: I just chec…
Re: There is no WhatsApp 'backdoor'
#416Earlier quoted context omitted.
See eg http://btlj.org/data/articles2015/vol26/26_2/26-berkeley-tec... p 1030-1031 for Germany and France. Also: https://en.wikipedia.org/wiki/Nokia#Lex_Nokia
Great link, thanks. However, it doesn't back up the claim you made. A few quotes: "In Europe, there is technically no uniform body of “European law” that directly applies between employers and employees" "Courts and scholars increasingly reference EU law, usually without clarifying whether the existence of a particular civil right protection in the EU Charter actually changed the legal situation as a matter of law, r…
The pages I gave are specific case studies of the law in Germany & France. You are right that there is not too much overarching EU level legislation about these things, it's generally in national legislation and up to each country.
Re: There is no WhatsApp 'backdoor'
#417Earlier quoted context omitted.
Well, there are two options: notification option and confirmation option. Moxie correctly assumes that confirmation option (require manual confirmation to resend if key changes) should either be enabled for everyone or disabled for everyone, as its state can be determined passively by the server. But it depends on the notification option. His conclusion is that confirmation option should be disabled for everyone beca…
>But it depends on the notification option. Ahhhh, dependencies. You're right. This is more involved than I originally thought. Here, does the following look like an accurate summary of the situation? (For optional row/cols, "Optional (yes)" with a value of "secure" means "if the feature is optional, it's secure for users who have it enabled.") Confirmation: Required Disabled Optional (yes) Optional (no) | :------: |…
And I don't think WhatsApp is secure for anyone with its permanently disabled confirmation. Maybe it prevents mass surveillance, but it is still vulnerable to targeted attack. Surely it may cost facebook reputation and the attack will be detected in the end, but it is still possible.
Re: There is no WhatsApp 'backdoor'
#4187.7 billion people in this planet are not part of ISIS.
Nice business model though.
Even if WhatsApp or Telegram or Signal are not compromised, you realky should assume the kernel or baseband are.
When I was a kid, I did an experiment cracking Apple] [ software.
Turns out forget the disk encryption, just hook up the NMI interrupt and you are golden... snapshot whenever you want.
Seriously, security is a joke. Nothing is safe. Get over it.
Re: There is no WhatsApp 'backdoor'
#4197.7 billion people in this planet are not part of ISIS.
Nice business model though.
Even if WhatsApp or Telegram or Signal are not compromised, you really should assume the kernel or baseband are.
When I was a kid, I did an experiment cracking Apple ][ software. Circa 1984, just to see if I could after reading countless documents on the encoding formats (and doing it the hard way).
I'm sure the ops have figured this out by now. I know personally was contacted by them multiple times. Rolls eyes.
Turns out forget the encryption, just hook up the NMI and snapshot whenever you want.
Seriously, security is a joke. Nothing is safe. Get over it.
Re: There is no WhatsApp 'backdoor'
#420Once its off your screen, there is no way to tell that you've never authenticated the current key. No mark, not even burred in a menu.
So perhaps I should not surprised to see the authors of the worst public key management security that I've ever actually used defending even worse public key management security.