Live data from Hacker News

There is no WhatsApp 'backdoor'

whispersystems.org

421–430 of 437 posts

Re: There is no WhatsApp 'backdoor'

#421
post #414

Earlier quoted context omitted.

Great link, thanks. However, it doesn't back up the claim you made. A few quotes: "In Europe, there is technically no uniform body of “European law” that directly applies between employers and employees" "Courts and scholars increasingly reference EU law, usually without clarifying whether the existence of a particular civil right protection in the EU Charter actually changed the legal situation as a matter of law, r…

(Note: I made no claims, just jumped in to provide references about the state of affairs in some European countries) The pages I gave are specific case studies of the law in Germany & France. You are right that there is not too much overarching EU level legislation about these things, it's generally in national legislation and up to each country.

Sorry, I should have referred to the grandparent's claim (which is also not backed by the case studies, good examples though they are).

Re: There is no WhatsApp 'backdoor'

#422
post #5

Color me still-unconvinced. This retort does not address the fundamental point made in the Guardian piece: > “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which u…

The discoverer of the vulnerability, t0b0, is weighing in again, saying there is a backdoor:

https://tobi.rocks/2017/01/there-is-a-whatsapp-backdoor/

Edit to add: It's also on HN (empty so far):

https://news.ycombinator.com/item?id=13404263

Re: There is no WhatsApp 'backdoor'

#423
post #410
post #409

Earlier quoted context omitted.

Regardless how the comment tries to work around it, cognitive deficit is in fact rude.

You didn't even bother to respond to the content of my post, rather you're more concerned with some weird sense of decorum. We all have cognitive deficits, but it is not necessarily rude to point out when one's mental faculties are failing.

The sense of decorum we all ought to have in participating in HN is called out in https://news.ycombinator.com/newsguidelines.html. As an example, Be civil. Don't say things you wouldn't say in a face-to-face conversation. Avoid gratuitous negativity.

Re: There is no WhatsApp 'backdoor'

#424
post #111

Why is moxie doing PR for WhatsApp?

>Even though we are the creators of the encryption protocol supposedly "backdoored" by WhatsApp, we were not asked for comment. It's only a small step from criticism of WhatsApp crypto to criticism of Signal crypto. Why wouldn't moxie be interested?

Especially when signal's interface has similar, if less severe, weaknesses.

Re: There is no WhatsApp 'backdoor'

#425

Earlier quoted context omitted.

> But I trust Moxie a lot What does trust have to do with this? The trade-off has been clearly explained. As it stands, WhatsApp is great for protecting sexts and low value conversations if you're not famous (99.99% of everyone), but if you're snowden, or hillary, there is no protection - contrary to what has been advertised.

>there is no protection To my understanding, that's simply not true. What you can accurately say is that with key change notifications turned on, any one* message could be exposed without any means of recourse, but subsequent exposures would require user error. *Question for anyone: could this apply to a "batch" of messages? That is, could servers hold back the delivery of some number of messages and then the attack…

Very good question, and I haven't seen a definitive answer to it yet.

The responses by Bob are presumably numbered, and some might be delivery receipts, or contain delivery receipts (e.g. A cumulative ACK as in TCP). Could the server selectively suppress the read receipts, or manipulate the cumulative ACK? If it simultaneously triggered rekeying on Bob's side, presumably yes. But not seen a definitive statement on that.

Re: There is no WhatsApp 'backdoor'

#426

Earlier quoted context omitted.

> Why not phase the message differently, e.g. "It looks like (user) is chatting from a new device. Is this correct?" Because of exactly what Moxie said in his post. This is a relatively common occurrence in practice. Someone gets a new device. Or uninstalls/reinstalls the WhatsApp app. Or wants to read messages on their laptop, too. And so on. Warning everyone about this all the time leads to people becoming subconsc…

That's why you include a checkbox underneath with the label "Do not show me this warning in the future (insecure)". And then a setting to turn it back on. It's not rocket science.

This shit is really easy to armchair quarterback over the Internet where nobody wins and the points don't matter, but the reality is that figuring out how to design crypto applications in a way that keeps users secure without users disabling or ignoring sometimes-important security problems is a very hard problem. In fact, it may very well be the current hardest practical problem in information security.

So yeah, it is actually kind of like rocket science, and I guarantee you that Moxie has spent orders of magnitude more time thinking with, dealing with, and collecting data on this kind of problem than you or I combined.

Re: There is no WhatsApp 'backdoor'

#427

Earlier quoted context omitted.

Nope. Professional security people have been using binary diffing tools to solve this problem since the early 2000s.

You keep saying this. Can you back your claims? In particular, the claim that Whatsapp has been extensively reverse-engineered?

Your argument is the same one as "nuclear submarines are impossible to build because I just thought about it for five minutes and can't build one". But Electric Boat Corporation from Groton, Connecticut delivers them regularly, on time and under budget (!). Googling around will tell you that these things exist and people do build them.

Re: There is no WhatsApp 'backdoor'

#428

Earlier quoted context omitted.

You keep saying this. Can you back your claims? In particular, the claim that Whatsapp has been extensively reverse-engineered?

Are you asking me to "back up" the claim that security researchers use BinDiff tools to reverse out vulnerabilities from vendor patches? At one of the better-attended Black Hat USA talks last year, a team from Azimuth got up and stage and walked the audience through an IDA reverse of the iOS Secure Enclave firmware. Your argument is that it's somehow harder to reverse a simple iOS application ?

You keep saying it's easy, I keep saying, then do it and show me.

Re: There is no WhatsApp 'backdoor'

#429

Earlier quoted context omitted.

You keep saying this. Can you back your claims? In particular, the claim that Whatsapp has been extensively reverse-engineered?

Your argument is the same one as "nuclear submarines are impossible to build because I just thought about it for five minutes and can't build one". But Electric Boat Corporation from Groton, Connecticut delivers them regularly, on time and under budget (!). Googling around will tell you that these things exist and people do build them.

No, that's not at all my argument. I didn't ask me to show me a completed nuclear submarine. I asked you to show me a Whatsapp reverse engineer.

Re: There is no WhatsApp 'backdoor'

#430

Earlier quoted context omitted.

That's why you include a checkbox underneath with the label "Do not show me this warning in the future (insecure)". And then a setting to turn it back on. It's not rocket science.

This shit is really easy to armchair quarterback over the Internet where nobody wins and the points don't matter, but the reality is that figuring out how to design crypto applications in a way that keeps users secure without users disabling or ignoring sometimes-important security problems is a very hard problem . In fact, it may very well be the current hardest practical problem in information security. So yeah, it…

And we're not moxie's investor meeting or senate hearing comittee. This is a layman discussion thread that he decided to join and answer questions in. (Big respect to him for doing that) So I believe even "stupid" questions should be allowed if they increase understanding or bring up new points.

Furthermore, this is an argument via authority[1]. Of course there are experts, but even an expert should explain and discuss his rationale in the interest of sharing knowledge (which moxie is doing here) - otherwise problems like this will stay "hard" for a long time.

Post reply on HN