Live data from Hacker News

We Chat, They Watch

citizenlab.ca

21–30 of 555 posts

Re: We Chat, They Watch

#22
post #16
post #9

Earlier quoted context omitted.

You also have to trust the source code, or trust a recent audit, then also make sure the build you have kept it's integrity and matches the audit build.

There are degrees of security between "I personally built it from source using a compiler I personally built from source" and "Xi Jinping is CC'ed a plaintext copy of every message". The allegation here is that WeChat is basically the latter. No one makes any remotely similar claim about iMessage or WhatsApp.

How about "Mark Zuckerberg is CC'ed a plaintext copy of every message"

Re: We Chat, They Watch

#23
post #3

Did anyone actually think WeChat communications are secure? Do we have reason to believe iMessage and Whatsapp are more secure?

WhatsApp backups created by the built-in backup option of the messaging client on Android are not encrypted when they are transferred to Google Drive.

Re: We Chat, They Watch

#24
post #3

Did anyone actually think WeChat communications are secure? Do we have reason to believe iMessage and Whatsapp are more secure?

I mean there’s a white paper on iMessage’s security, and there isn’t (i don’t think) on WeChat. WhatsApp’s encryption uses libsignal. The security qualities of iMessage and WhatsApp is known. It’s not of WeChat.

There's a whitepaper on iMessage's security as it was at a single point in time. It may be possible to verify this on a recent build with enough effort, but the average user will never be able to make that validation. So we can't be completely secure there.

More secure than WeChat? ABSA-FREAKING-LUTELY. And do I trust Apple to remain secure? Yes.

I'm mostly putting this here because I've heard people talking about security guarantees without considering tweaks in the supply chain or binary deliveries. Even Signal could get breached with enough effort from Google to push new bits and bypass certificate validation. (Though practically that is not going to happen.)

Re: We Chat, They Watch

#25
I communicate regularly with people in mainland China. For me the best policy is just don't say anything that I would be too concerned about being shared. Of course, my behavior is the same for other apps. Beyond government-level type hacking, I feel a little more safe on some of the Chinese apps, as I know they have a stronger hand in their ability to stop hackers and scammers.

Re: We Chat, They Watch

#26

> Facebook spies on the content that all users send each other, including Chinese (and Canadians and Europeans and Indiana and Australians and Russians...) Sure, the article discusses other sketchy stuff that wechat is doing, but FB and Twitter and Reddit et. al. are all doing similar stuff too.

This article concerns wechat only. Whatabout FB/Twitter/Reddit is not a concern here.

Re: We Chat, They Watch

#28
post #16
post #9

Earlier quoted context omitted.

You also have to trust the source code, or trust a recent audit, then also make sure the build you have kept it's integrity and matches the audit build.

There are degrees of security between "I personally built it from source using a compiler I personally built from source" and "Xi Jinping is CC'ed a plaintext copy of every message". The allegation here is that WeChat is basically the latter. No one makes any remotely similar claim about iMessage or WhatsApp.

You forgot "I personally built it from source using a compiler I personally built from source with a micro-compiler that I handcoded in assembly on a computer that I assembled from transistors myself."

Re: We Chat, They Watch

#30

> Facebook spies on the content that all users send each other, including Chinese (and Canadians and Europeans and Indiana and Australians and Russians...) Sure, the article discusses other sketchy stuff that wechat is doing, but FB and Twitter and Reddit et. al. are all doing similar stuff too.

I don't trust the privacy of any of those services, but there is a huge difference between "the government can subpoena information, or do targeted sniffing if you dont encrypt anything" and "we have a cron job set up that send everything directly to a government server for the express purpose of suppressing speech"

To be clear, those services are lame for being as untrustworthy as I believe they are, but let's not equate the two.

Post reply on HN