Live data from Hacker News

Facebook, WhatsApp Will Have to Share Messages With U.K.?

bloomberg.com

301–310 of 591 posts

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#301
post #198

Does anyone have any advice for what platform might be best to migrate to? I'm not overly concerned with group E2E, but it is a nice-to-have. Telegram and Discord seem like two of the most practical options, Keybase and Matrix seem like two of the most ideal from a security standpoint. I wonder what offers the best cross-section of features and user experience.

Telegram is not EtE encrypted by default. Only special “private chats” are and they unavailable on desktop.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#302
post #176

Earlier quoted context omitted.

Unless your mom is planning to involve herself in illegal activities I don't see a problem. Most electronic communication channels are compromised anyway. If you don't want eavesdroppers, don't use electronics.

> Unless your mom is planning to involve herself in illegal activities I don't see a problem. I assume you'd be happy to post all your credit card receipts and emails for all of us to see then. You're not doing anything illegal, right? That would be the only reason you don't want those things to be visible.

Better ask for browsing and messaging history.

That should be a much better analogy. Especially in the postmodern hypersensitive world.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#303

Yes, this is something that literally everyone who reads HN will oppose. Meanwhile do you hear the deafening silence from the average Joe who thinks he has "nothing to hide"? Don't hate the politicians who keep pushing this. They're just trying not to get fired. And the surest way to get fired in a western country right now is to be seen doing nothing about the terrorism problem and then having terrorist acts committ…

You are absolutely right. I also already assume the government can access virtually anything I am doing anyways. I think we are all naive to believe otherwise.

I also have nothing to hide :-)

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#306

In other news: US, UK subjects agree to stop using WhatsApp in favor of Telegram and Signal: https://telegram.org/ https://www.signal.org/ These are free software, not controlled by a giant corporation (although both are limited liability companies; Telegram in London/Dubai, Signal in San Francisco IIANM); with the developer/company not having unencyrpyed access to your data.

Telegram group chats are not e2e encrypted, while Signal is notorious for being unreliable at actually delivering messages. Also, if you change your phone number the official Signal recommendation is to manually tell all your friends about the new number. WhatsApp just lets you do it. I use both apps regularly but neither of them is perfect.

In Telegram regular chats are not encrypted by default either. Only special “secret chats” are and they only can be established between mobile devices, not desktop.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#307
It's the Russians that continuously screw us up the only want control to run their gang activity,sex trafficking child molesting pure EVIL into our country the one's that bring this and terrorism should be put to death they are also racist natzi white supremacist

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#308

Earlier quoted context omitted.

There is no other endgame in which this is pointful.

You're assuming the people making these rules actually understand encryption, which is doubtful at best.

In many cases, (In my country for sure, and I bet this is common elsewhere) members of the legislative branch are approached by people from the intelligence community, who hand them the drafts for stuff they 'need'.

And you can bet those people do understand encryption.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#309
post #92

Earlier quoted context omitted.

> If the source code isn't available for audit by 3rd parties (or yourself), and you can't build it from source, then it was never really "secure" anyway. What lawmakers do or don't say is just noise. Careful - you're right that WhatsApp is untrustworthy, but laws that force them to add backdoors could well be applied to open-source code as well. Or make possession of non-backdoored software, open or not, illegal. Or…

If I can compile audited code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors (excluding perhaps hardware level backdoors--but that's why we do the encryption in software). Implementing hardware backdoors that are opaque to end users is theoretically possible, but more difficult in practice. You could, for example, build a screen/monitor that just captures everyt…

Your assumption how backdoors work is very limited/wrong, I am afraid.

You assume that you actually understand the code well enough to identify the backdoor - e.g. as some sort of function that will bypass authentication when some secret hardwired password is provided (to give a dumb example).

However, to give a real world example of backdoored crypto, it is nothing of the sort. For example, the issue with the potentially backdoored Dual_EC_DRBG pseudorandom number generator has been known since 2004 at least - but the algorithm has been standardized by ISO/NIST and used for years until the potential backdoor issue was widely publicized following the Snowden leaks and the standard was withdrawn.

Good luck finding something like that only by reading code unless you are expert in crypto and mathematics. If you were only auditing code whether or not it matches the published, supposedly correct, standard (or algorithm description), you would never find this. The backdoored code was working completely fine, exactly as intended. But the weak random number generator allowed an adversary with sufficient computing resources to break the encryption.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#310
post #234

Earlier quoted context omitted.

Still remember how one German Islamist terror group just used their web-email provider's draft feature. They never 'sent' anything. There are often quite simple ways to circumvent this kind of thing.

Yeah only a stupid person can think that backdooring whatsapp will actually prevent the next 9/11. And that's in my opinion the core issue with most politicians, stupidity/tech illiteracy. I'd love to hear about either a possible alternative government structure in which there are no politicians or a way to attract the smartest people in governments.

On the politicians side I agree, tech illiteracy seems to be largely correct. As far as the intelligence agencies are concerned, well I think they know exactly what they are doing. So they know that a WhatsApp backdoor doesn't help against the next 911, it still allows a lot of general surveillance so. And that is what the agencies are after. Terrorists are just an excuse IMHO.
Post reply on HN