Live data from Hacker News

WhatsApp whitepaper removed sentence about never having access to private keys

twitter.com

11–20 of 111 posts

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#11
post #7

A TD:DR; for people. The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions: "At no time does the WhatsApp server have access to any of the client's private keys." [1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...

Would you have a link to the previous version?

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#12

They are talking about public keys though. They just removed the part about not having access to private keys. Omission of the line doesn't actually mean that they now have access to private keys as well.

I'm not sure if the title of this post changed, but now it only says "might have access" which is not untrue

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#13
After Facebook bought what’s app, I’ve never for a moment believed it was secure.

I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#14

They are talking about public keys though. They just removed the part about not having access to private keys. Omission of the line doesn't actually mean that they now have access to private keys as well.

It doesn't mean they don't either. It's the removal of the previous claim that's worrying. But honestly, it doesn't matter anyway since Whatsapp is somehow able to backup all your data on Google Drive and restore it on separate phones. How are they able to do that without backing up the private key? https://faq.whatsapp.com/android/chats/how-to-restore-your-c...

I thought the backups were unencrypted (or encrypted with a key that was specific to backups) for that exact purpose.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#15

Probably because: All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook. ( https://scontent.whatsapp.net/v/t39.856…

Probably not because that doesn't say whatsapp will have the private keys, just that the vender will. In fact the next sentence you left out of the quote is

> However, these private keys will still not be stored on the WhatsApp chat server.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#16

They are talking about public keys though. They just removed the part about not having access to private keys. Omission of the line doesn't actually mean that they now have access to private keys as well.

Why would they remove such an important line?

I'm not sure they deserve the benefit of the doubt. Facebook has shown themselves to be dodgy as hell when it comes to our privacy.

I would prefer them to explicitly state that they don't have access to the private keys.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#17
post #9

A a side-note I'm interested in the PDF diffing tool the author is using, seems pretty well made

I have always used diffpdf. Its been around forever. I don't know if it is what is used in the screenshot: http://www.qtrac.eu/diffpdf-foss.html

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#18

After Facebook bought what’s app, I’ve never for a moment believed it was secure. I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.

It's closed-source/proprietary/non-Free software. Even if it weren't from Facebook, that would be enough to warrant skepticism.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#20

After Facebook bought what’s app, I’ve never for a moment believed it was secure. I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.

I've also heard many people claim this with Facebook and other platforms. I would love to see a study on this because I'm unsure of the evidence so far. Humans can make mistakes. They can forget typing something into Google, Facebook, etc. I can't even remember the Google searches I did yesterday!
Post reply on HN