Live data from Hacker News

Facebook, WhatsApp Will Have to Share Messages With U.K.?

bloomberg.com

521–530 of 591 posts

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#521
post #447

Earlier quoted context omitted.

As much as would like to believe all promises coming from corporate execs - Facebook has been caught lying more than enough. So thanks for trying, but I have uninstalled WhatsApp and I'm happy with Threema.

Have you considered Riot (Matrix) or Signal? Both are open source so it's possible to verify claims made on their website, which is a lot less possible with proprietary software like Threema.

And with Matrix apps you can choose to run your own server. Not sure what legal ramifications that has, but practically speaking it allows the possibility of eliminating another potential weakness.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#522

Earlier quoted context omitted.

A lack of one is.

I've often wondered whether or not a sufficiently well worded warrant could require that the warrant canary remains published unchanged, rendering the warrant canary useless.

The idea behind the canaries is that they expire, and that one cannot legally force someone to sign false statements. So if no new canary is published when the old one expires, that's a red flag.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#523

Earlier quoted context omitted.

Do you currently have any backdoors installed?

We do not. You don't have to take our word on this -- I wouldn't want you to. As others on this thread have pointed out it's possible enough to tear through our binaries that if we did have a backdoor it would be discovered.

This should be completely believable for a company that relies heavily on user and community trust.

That said, @wcathcart: in community with deep technical expertise like Hacker News, folks do consider how many possible channels and means there are to confidentially leak information from applications.

You're correct that in the general case it's likely that tech-savvy users would scan a popular app like yours and find any 'obviously-placed' backdoors. It's an observational and opportunistic approach, akin to the way a passer-by might spot a poorly locked bicycle on a street.

Unfortunately there's an extra level of complexity here - any app may have unusual behaviors that a sophisticated attacker could trigger for individual users to exploit them - and it's really, really hard for the security-conscious of us -- who might never see or meet those users -- to truly trust that your app is doing what you tell us it is, whether that's end-to-end encryption in all situations, or anything else.

The reason is that without being able to see how the app is written, verify that it's genuinely the same compiled version running on all devices, and audit the behavior it will have under exceptional circumstances -- external observers just don't know.

I'm not expecting you to make the source freely available, incredible though that would be - but attempting to explain the potential disconnect in dialogue you might find with some commentors.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#524

Earlier quoted context omitted.

Will you have something like a warrant canary [1] to let users know in case there ever is a compromise of security? [1] https://en.wikipedia.org/wiki/Warrant_canary

A warrant canary isn't proof of anything.

Can you add some substance to this? Why do you think warrant canaries are weak?

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#525

Earlier quoted context omitted.

Do you currently have any backdoors installed?

We do not. You don't have to take our word on this -- I wouldn't want you to. As others on this thread have pointed out it's possible enough to tear through our binaries that if we did have a backdoor it would be discovered.

Unfortunately, the WhatsApp terms of service say you must not "reverse engineer, alter, modify, create derivative works from, decompile, or extract code from our Services"

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#526
post #484

Earlier quoted context omitted.

Thanks for the clarity. So will WhatsApp refuse to comply, if this goes forward? And is that even possible? I do appreciate that Facebook has the resources to fight. To fight an NSL, even. But IANAL, and have no clue.

Facebook give the government this and the government in acts regulations to “protect” Facebook. I’m sure Facebook is salivating at the thought at getting even more access to your sensitive data. Once the backdoor is installed who knows who’ll have access.

[deleted]

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#527

Earlier quoted context omitted.

A warrant canary isn't proof of anything.

Can you add some substance to this? Why do you think warrant canaries are weak?

If you can be compelled to be silent while breaking constitutional guidelines on the basis of national security, you can be compelled to update a beacon.

Warrant canaries are nice to have, but viewing them as something which provides proof of absence of government meddling is incorrect.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#528

Earlier quoted context omitted.

I've often wondered whether or not a sufficiently well worded warrant could require that the warrant canary remains published unchanged, rendering the warrant canary useless.

The idea behind the canaries is that they expire, and that one cannot legally force someone to sign false statements. So if no new canary is published when the old one expires, that's a red flag.

Please. A receipt for a $10 wrench and any IT guy will crumble.

That wouldn’t even be illegal, since they never hit you with a wrench - you just imagined they were about to go xkcd on you

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#530
post #447

Earlier quoted context omitted.

Have you considered Riot (Matrix) or Signal? Both are open source so it's possible to verify claims made on their website, which is a lot less possible with proprietary software like Threema.

And with Matrix apps you can choose to run your own server. Not sure what legal ramifications that has, but practically speaking it allows the possibility of eliminating another potential weakness.

... but probably opening many new ones, unless one has a really strong security team in place.
Post reply on HN