WhatsApp whitepaper removed sentence about never having access to private keys
21–30 of 111 posts
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#22A TD:DR; for people. The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions: "At no time does the WhatsApp server have access to any of the client's private keys." [1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...
Would you have a link to the previous version?
https://www.academia.edu/36044237/WhatsApp_Encryption_Overvi...
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#23Probably because: All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook. ( https://scontent.whatsapp.net/v/t39.856…
Probably not because that doesn't say whatsapp will have the private keys, just that the vender will. In fact the next sentence you left out of the quote is > However, these private keys will still not be stored on the WhatsApp chat server.
I guess it wasn't clear, but I was trying to refute the claim implied by the Twitter post (by showing that the document still claims that WhatsApp servers don't have access to the private keys).
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#24After Facebook bought what’s app, I’ve never for a moment believed it was secure. I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.
I have heard something similar to this but just assumed it was a coincidence. Has this every been proven with verified results ?
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#25Re: WhatsApp whitepaper removed sentence about never having access to private keys
#26After Facebook bought what’s app, I’ve never for a moment believed it was secure. I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.
I've also heard many people claim this with Facebook and other platforms. I would love to see a study on this because I'm unsure of the evidence so far. Humans can make mistakes. They can forget typing something into Google, Facebook, etc. I can't even remember the Google searches I did yesterday!
They have a social graph that indicates who your probable friends are, regardless of actual Facebook/Instagram/Whatsapp friend status; using Bluetooth & Wifi identifiers based on physical closeness.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#27After Facebook bought what’s app, I’ve never for a moment believed it was secure. I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.
Chances are that you're either more predictable than you expected, or it's just random chance and correlation bias. Billions of people use these services, there have to be some freaky coincidences happening all the time. We need something a lot more solid than "I've heard people" to make any conclusion.
But the general point still holds, it's a closed source app made by a company that thrives on data mining, of course it should be considered insecure by default.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#28A TD:DR; for people. The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions: "At no time does the WhatsApp server have access to any of the client's private keys." [1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...
Would you have a link to the previous version?
A copy I had downloaded on 29 July 2020
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#29Can anybody remember the story, I think it was a few years ago, when a journalist warned in an article that messaging apps like Whatsapp are vulnerable because they rely on a server for key exchange, and all the security researchers requested that the story should be retracted because it would lead people to use SMS which is even less secure? I may be misremembering some details.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#30The WhatsApp client is a closed source, so why is this news ? Is this some kind of promise from the company that the client will not have access to private keys ?
This tweet doesn't establish otherwise.