Live data from Hacker News

WhatsApp whitepaper removed sentence about never having access to private keys

twitter.com

21–30 of 111 posts

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#22
post #7

A TD:DR; for people. The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions: "At no time does the WhatsApp server have access to any of the client's private keys." [1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...

Would you have a link to the previous version?

This website seems to have version 2 which includes that text on page 11. You can scroll down and read it without downloading it.

https://www.academia.edu/36044237/WhatsApp_Encryption_Overvi...

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#23
post #15

Probably because: All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook. ( https://scontent.whatsapp.net/v/t39.856…

Probably not because that doesn't say whatsapp will have the private keys, just that the vender will. In fact the next sentence you left out of the quote is > However, these private keys will still not be stored on the WhatsApp chat server.

That's in a different place (p. 11), but the gist is still the same. Even my quote includes "The WhatsApp server has no access to the client’s private keys".

I guess it wasn't clear, but I was trying to refute the claim implied by the Twitter post (by showing that the document still claims that WhatsApp servers don't have access to the private keys).

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#24

After Facebook bought what’s app, I’ve never for a moment believed it was secure. I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.

> I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after

I have heard something similar to this but just assumed it was a coincidence. Has this every been proven with verified results ?

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#26

After Facebook bought what’s app, I’ve never for a moment believed it was secure. I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.

I've also heard many people claim this with Facebook and other platforms. I would love to see a study on this because I'm unsure of the evidence so far. Humans can make mistakes. They can forget typing something into Google, Facebook, etc. I can't even remember the Google searches I did yesterday!

Even then, a lot of the "I was talking about something with a friend and never even Googled it then got an ad for it" can be explained by Facebook leveraging their social graph to target ads if your friend googled something.

They have a social graph that indicates who your probable friends are, regardless of actual Facebook/Instagram/Whatsapp friend status; using Bluetooth & Wifi identifiers based on physical closeness.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#27

After Facebook bought what’s app, I’ve never for a moment believed it was secure. I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.

I'm very skeptical of WhatsApp's security but I'm also very skeptical of these ad claims. We've seen a tone of those over the years, these companies would have a lot to lose if they did that.

Chances are that you're either more predictable than you expected, or it's just random chance and correlation bias. Billions of people use these services, there have to be some freaky coincidences happening all the time. We need something a lot more solid than "I've heard people" to make any conclusion.

But the general point still holds, it's a closed source app made by a company that thrives on data mining, of course it should be considered insecure by default.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#28
post #7

A TD:DR; for people. The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions: "At no time does the WhatsApp server have access to any of the client's private keys." [1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...

Would you have a link to the previous version?

https://files.catbox.moe/fopl6w.pdf

A copy I had downloaded on 29 July 2020

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#29
post #8

Can anybody remember the story, I think it was a few years ago, when a journalist warned in an article that messaging apps like Whatsapp are vulnerable because they rely on a server for key exchange, and all the security researchers requested that the story should be retracted because it would lead people to use SMS which is even less secure? I may be misremembering some details.

https://www.theguardian.com/technology/2017/jan/13/whatsapp-...

HN Comments - https://news.ycombinator.com/item?id=13389935

https://indianexpress.com/article/technology/tech-news-techn...

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#30

The WhatsApp client is a closed source, so why is this news ? Is this some kind of promise from the company that the client will not have access to private keys ?

WhatsApp promises end to end encryption, with no access to the content of your messages, just like iMessage and signal.

This tweet doesn't establish otherwise.

Post reply on HN