Live data from Hacker News

WhatsApp whitepaper removed sentence about never having access to private keys

twitter.com

1–10 of 111 posts

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#2
Yikes. The bad news about WhatsApp just keeps pouring in.

For me personally I only ever used WhatsApp very lightly with a few work friends. After all of the recent news surrounding the app I sent a message saying I plan on leaving the app soon.

I wish it were easier to switch apps like this but it makes sense that they wouldn't want that to be the case.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#3
Probably because:

All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook.

(https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857..., p. 13)

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#6
The charitable view would be that they are simplifying the document by removing redundant information.

Of course the implication by the tweet is that they removed this claim because they added some mechanism for the client to turn over the keys.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#7
A TD:DR; for people.

The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions:

"At no time does the WhatsApp server have access to any of the client's private keys."

[1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#8
Can anybody remember the story, I think it was a few years ago, when a journalist warned in an article that messaging apps like Whatsapp are vulnerable because they rely on a server for key exchange, and all the security researchers requested that the story should be retracted because it would lead people to use SMS which is even less secure? I may be misremembering some details.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#10

They are talking about public keys though. They just removed the part about not having access to private keys. Omission of the line doesn't actually mean that they now have access to private keys as well.

It doesn't mean they don't either. It's the removal of the previous claim that's worrying.

But honestly, it doesn't matter anyway since Whatsapp is somehow able to backup all your data on Google Drive and restore it on separate phones. How are they able to do that without backing up the private key?

https://faq.whatsapp.com/android/chats/how-to-restore-your-c...

Post reply on HN