Live data from Hacker News

WhatsApp whitepaper removed sentence about never having access to private keys

twitter.com

41–50 of 111 posts

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#43
post #8

Can anybody remember the story, I think it was a few years ago, when a journalist warned in an article that messaging apps like Whatsapp are vulnerable because they rely on a server for key exchange, and all the security researchers requested that the story should be retracted because it would lead people to use SMS which is even less secure? I may be misremembering some details.

Warning that it's vulnerable because it relies on a server for key exchange is like warning that water is wet and you shouldn't let it loose in your house to prevent water damage. It's correct, but redundant. The very definition of end to end encryption is not trusting the server, so you need to verify the exchanged keys. This is a requirement in Signal, Wire, Threema, Jami, Briar, Element/Matrix, Keybase, OTR, and all other protocols. If you don't do that, then yes, you rely on whoever owns (or "owned") the server.

What might need a warning is that the server can push new keys to your phone at any time and, unless you go into your security settings, you will never notice. Being warned of key changes is opt-in. That's why WhatsApp does, by default, opportunistic encryption.

But Moxie was involved in the implementation and got only a few million for publishing that claim so no worries y'all.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#44

They are talking about public keys though. They just removed the part about not having access to private keys. Omission of the line doesn't actually mean that they now have access to private keys as well.

It doesn't mean they don't either. It's the removal of the previous claim that's worrying. But honestly, it doesn't matter anyway since Whatsapp is somehow able to backup all your data on Google Drive and restore it on separate phones. How are they able to do that without backing up the private key? https://faq.whatsapp.com/android/chats/how-to-restore-your-c...

The backups are unencrypted as highlighted in the UI (if I recall correctly). They re-generate the keys when you switch phones / re-install / clear data. That's when you get to see the "XYZ's security code changed" service message

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#46
post #39

Earlier quoted context omitted.

Didn’t Telegram roll their own crypto?

As did Signal (called Axolotl back then)? All protocols are invented at some point. Telegram did a terrible job marketing this one but it has been a long time now and the only issue I ever heard of was fixed some years ago. It's still not exactly pretty, but then look at TLS and I'm actually quite okay with mtproto. The real issue is that mtproto is never used. It isn't implemented in most clients for no apparent rea…

You mean Signal which was created by Moxie Marlinspike and other legit cryptogaphers and security researchers? Who rolled Telegram's crypto? No idea. Why should we trust them? No idea. I think I'll go with the people who have been contributing to the field for years and are highly respected.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#47

Might be worth a search of court cases to see if there are any cases out there where Facebook provided WhatsApp messages to law enforcement.

Unfortunately I think that would be suppressed by asking the court to seal documents et al

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#48
post #38

Earlier quoted context omitted.

Didn’t Telegram roll their own crypto?

Please stop bringing up this "never roll your own crypto" argument. It's a guideline, not a hard rule. Signal actually rolled their own crypto and aren't constantly criticized for that, on the contrary. Signal is praised for rolling it's own crypto. Don't get me wrong, the Telegram crypto can (and should) definitely be criticized. But please criticize that they use "bad crypto" or "strange crypto" or "unreviewed cryp…

There's no need to continue litigating Telegram's crypto.

(the criticisms are well enough known that people either aren't going to listen or can just go read them)

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#49
post #39

Earlier quoted context omitted.

As did Signal (called Axolotl back then)? All protocols are invented at some point. Telegram did a terrible job marketing this one but it has been a long time now and the only issue I ever heard of was fixed some years ago. It's still not exactly pretty, but then look at TLS and I'm actually quite okay with mtproto. The real issue is that mtproto is never used. It isn't implemented in most clients for no apparent rea…

You mean Signal which was created by Moxie Marlinspike and other legit cryptogaphers and security researchers? Who rolled Telegram's crypto? No idea. Why should we trust them? No idea. I think I'll go with the people who have been contributing to the field for years and are highly respected.

I'd rather go with cryptanalysis and/or audits than big names. Both protocols are old enough now to have had ample opportunity.

And I can't tell if Moxie really means to improve the status quo or works for some three letter agency and builds just enough metadata opportunities into popular messengers and opportunistic encryption into WhatsApp to be helpful without being suspicious. To avoid redundancy, I posted these only yesterday and it includes some of the reasons: https://news.ycombinator.com/item?id=25669531 https://news.ycombinator.com/item?id=25669267

They don't cover everything unfortunately but I'm also getting annoyed with the ephemerality of HN. What's posted last week is forgotten and never looked at again. I can try to find old posts that cover it or type it all out again (and it's a big claim so very few people will even take the time to read a big comment with reasons in the middle of another thread). I'm also not denying he does good stuff, just that there are enough weird opinions (decentralization = evil, anybody but us = evil, bug bounties = evil...) that I carefully look at what he makes and would rather there were better alternatives than their central servers.

Signal is still the only realistic messenger to use for good security and usability, unfortunately. Wire is a good second but Signal is definitely more smooth and I'd still recommend that to the general public, with the asterisk that it's an American company and that they should try Matrix if they're feeling adventurous (Wire falling somewhere in the middle, at that point you might as well try Matrix).

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#50
post #38

Earlier quoted context omitted.

Please stop bringing up this "never roll your own crypto" argument. It's a guideline, not a hard rule. Signal actually rolled their own crypto and aren't constantly criticized for that, on the contrary. Signal is praised for rolling it's own crypto. Don't get me wrong, the Telegram crypto can (and should) definitely be criticized. But please criticize that they use "bad crypto" or "strange crypto" or "unreviewed cryp…

There's no need to continue litigating Telegram's crypto. (the criticisms are well enough known that people either aren't going to listen or can just go read them)

[deleted]
Post reply on HN