Live data from Hacker News

Facebook, WhatsApp Will Have to Share Messages With U.K.?

bloomberg.com

101–110 of 591 posts

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#101
post #90
post #76

1) If someone wants to find something you are "hiding", they will anyway. It's always been like this. Encryption is never a protection against this. 2) Personally I still think e2e encryption is not a secure solution on operating systems that runs godmode 3rd party, eg. google play services: it relies on a key that can be stolen too many ways too easily. Signal included. 3) internet eons (20 years) ago we nearly all…

The landscape changed. More people use the internet, more spy agencies from multiple countries siphon traffic en bulk, information of higher value is exchanged over the internet, more untrusted parties are involved (e.g. wifi hotspots). I mean go ahead, do everything unencrypted. But I surely won't entrust data to you if you're leaking like a sieve.

> I mean go ahead, do everything unencrypted.

That is not what I wrote. I wrote "encrypt everything". There is valuable and useful use of encryption, I'm just not certain everything everywhere needs it or benefits from it.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#103
post #61

Earlier quoted context omitted.

Historical messages, yes. However an app maker can be coerced into adding a hidden user that can participate in chats and receive all future messages decrypted. It doesn't require any special crypto hacks for that to work.

Signal code is open. You can build it yourself and compare that build with whatever you download from the app store. So it's not that simple.

I don’t think the iOS App Store allows for that sort of checksum comparison.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#104
post #92

If the source code isn't available for audit by 3rd parties (or yourself), and you can't build it from source, then it was never really "secure" anyway. What lawmakers do or don't say is just noise. Platforms that rely on trust (in this case, trusting that FB isn't doing bad things) provide very weak guarantees about privacy/security. They could easily include a keylogger in WhatsApp and bypass the e2e encryption, fo…

> If the source code isn't available for audit by 3rd parties (or yourself), and you can't build it from source, then it was never really "secure" anyway. What lawmakers do or don't say is just noise. Careful - you're right that WhatsApp is untrustworthy, but laws that force them to add backdoors could well be applied to open-source code as well. Or make possession of non-backdoored software, open or not, illegal. Or…

If I can compile audited code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors (excluding perhaps hardware level backdoors--but that's why we do the encryption in software).

Implementing hardware backdoors that are opaque to end users is theoretically possible, but more difficult in practice. You could, for example, build a screen/monitor that just captures everything on the screen and forwards it to some other entity, but in practice it's not so easy because of bandwidth limitations, etc. I suppose it would be much easier to create a physical keyboard that phones home over a mobile network, although it would only give you half the conversation.

*edit: added the word "audited".

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#105
post #101
post #90

Earlier quoted context omitted.

The landscape changed. More people use the internet, more spy agencies from multiple countries siphon traffic en bulk, information of higher value is exchanged over the internet, more untrusted parties are involved (e.g. wifi hotspots). I mean go ahead, do everything unencrypted. But I surely won't entrust data to you if you're leaking like a sieve.

> I mean go ahead, do everything unencrypted. That is not what I wrote. I wrote "encrypt everything". There is valuable and useful use of encryption, I'm just not certain everything everywhere needs it or benefits from it.

It's a sensible default since the developers don't know when users will need it and users don't want to bother to choose for every single action they take. And they may not even know in advance that they will need it. An innocent conversation can quickly turn into something confidential or private.

That said, I do agree that p2p is preferable since it cuts out a central party that can be strongarmed by government being in control

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#108

from whatsapps official homepage, respectively ( https://faq.whatsapp.com/en/android/28030015 , https://faq.whatsapp.com/en/general/26000050 ) >WhatsApp has no ability to see the content of messages or listen to calls on WhatsApp. That’s because the encryption and decryption of messages sent on WhatsApp occurs entirely on your device. Before a message ever leaves your device, it's secured with a cryptographic lock, a…

The phrase "In the ordinary course of providing our service" seems to imply that in some circumstances they do/can store messages?

Probably not deliberately, but something can always go wrong, which is probably why they added an additional clause that messages older than 30 days should be deleted.

More interesting is what happens if someone gets a new phone. In that case (if I understood correctly) they might ask for the sender to resend the messages with a different key. If they really are forced to add a backdoor then that's where I would fit in a MITM attack, as it is limited in scale and detectable when used excessively.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#109

Earlier quoted context omitted.

although you anonymously purchase the oyster card, you can be de-anonymized the moment you scan the card, as face recognition links you with that card.

What happens if you cover your face while you scan?

you may slip up, or the system can always flag the id card if they're unable to make an automatic link to a card bought with cash, causing a human operator to get involved. If they see that you block your face everytime, they then can activate and access the total surveillance resources and flag the card.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#110
>> while the U.S. won’t be able to use information obtained from British firms in any cases carrying the death penalty.

Lol. So I guess it cannot be used for actual terrorism. They can use it up until an act of terrorism occurs. Then, now that murder charges are on the table, they cannot use the same date source to catch the perpetrators? The US isn't going to waive the death penalty on every terror case. That isn't politically possible.

We have to just admit that US laws are increasingly incompatible with those of the rest of the world. Treaties are getting harder and harder to reconcile. The US needs to back off its departure from international norms.

Post reply on HN