Live data from Hacker News

WhatsApp whitepaper removed sentence about never having access to private keys

twitter.com

61–70 of 111 posts

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#61
post #49

Earlier quoted context omitted.

You mean Signal which was created by Moxie Marlinspike and other legit cryptogaphers and security researchers? Who rolled Telegram's crypto? No idea. Why should we trust them? No idea. I think I'll go with the people who have been contributing to the field for years and are highly respected.

I'd rather go with cryptanalysis and/or audits than big names. Both protocols are old enough now to have had ample opportunity. And I can't tell if Moxie really means to improve the status quo or works for some three letter agency and builds just enough metadata opportunities into popular messengers and opportunistic encryption into WhatsApp to be helpful without being suspicious. To avoid redundancy, I posted these…

> And I can't tell if Moxie really means to improve the status quo or works for some three letter agency and builds just enough metadata opportunities into popular messengers and opportunistic encryption into WhatsApp to be helpful without being suspicious.

Moxie is an anarchist (or near to it) and has been so for a long time. Secretly working for the NSA would be a stupendously long con.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#62
post #60
post #49

Earlier quoted context omitted.

I'd rather go with cryptanalysis and/or audits than big names. Both protocols are old enough now to have had ample opportunity. And I can't tell if Moxie really means to improve the status quo or works for some three letter agency and builds just enough metadata opportunities into popular messengers and opportunistic encryption into WhatsApp to be helpful without being suspicious. To avoid redundancy, I posted these…

> And I can't tell if Moxie really means to improve the status quo or works for some three letter agency and builds just enough metadata opportunities into popular messengers and opportunistic encryption into WhatsApp to be helpful without being suspicious. As if Moxie having opinions that you don’t agree with is evidence for some covert NSA operation or some such. What nonesense.

Yeah it's more of a hyperbole than something I truly suspect. It's just that their opinions are in line with the hacker community 50% of the time, and in line with surveillance organisations the other 50% of the time. Of course, he always has some reason for having the opinion, it's all covered up just fine, so it could also be perfectly legit. It's just weird to argue both sides at the same time.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#63

I have a question to people who said Telegram is worse than WhatsApp in every possible way for privacy. Do you still hold this belief? At least Telegram is holding its promise, if you start secret chat only you and your peer knows encryption keys

> if you start secret chat only you and your peer knows encryption keys

The moment a product is "secure by exception" rather than "secure by default," a huge benefit of E2E encryption is immediately thrown out the window. Sometimes the simple knowledge of which conversations are secure, and which aren't, is more valuable than the content of those conversations.

Furthermore, when everything is E2E encrypted, mass surveillance of message content is essentially quashed.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#64
post #54

Probably because: All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook. ( https://scontent.whatsapp.net/v/t39.856…

Yeah. It is really clear that Facebook is finally getting around to just implementing this feature of effectively having "hosted clients" for companies to be able to more easily--and yes: less securely--build chat bots (a mechanism that I appreciate is maybe less than ideal to encourage, but frankly just doesn't feel that bad and certainly isn't a surprise: Facebook has been taking about this for a year or two now);…

Thanks for posting this. I was considering making the jump to a new messenger but decided to wait and see what others had to say about the changes to the privacy policy and what it actually means from a privacy perspective. The use case for businesses to be able to use it for hosted clients (probably hosted and with messages stored by facebook) makes sense, and doesn't seem as bad as its been made out to be – still get the same level of privacy we've always had between individuals and groups WhatsApp chats.

> but also to less secure messaging protocols like Telegram (or, frankly, Matrix)

Appreciate that Telegram doesn't have a good rep in the security community, but whats wrong with Matrix?

Also, this is off-topic, but I just wanted to say thank you for all the work you've done in the past with Cydia. I was a 1st gen iPhone user, and got a lot of use from services such as Cydia (in fact i'm convinced the App Store was inspired by services like Cydia).

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#65
post #49

Earlier quoted context omitted.

I'd rather go with cryptanalysis and/or audits than big names. Both protocols are old enough now to have had ample opportunity. And I can't tell if Moxie really means to improve the status quo or works for some three letter agency and builds just enough metadata opportunities into popular messengers and opportunistic encryption into WhatsApp to be helpful without being suspicious. To avoid redundancy, I posted these…

> And I can't tell if Moxie really means to improve the status quo or works for some three letter agency and builds just enough metadata opportunities into popular messengers and opportunistic encryption into WhatsApp to be helpful without being suspicious. Moxie is an anarchist (or near to it) and has been so for a long time. Secretly working for the NSA would be a stupendously long con.

Might not have been planed from the get go. But let me quote myself from a sibling comment:

> it's more of a hyperbole than something I truly suspect. It's just that their opinions are in line with the hacker community 50% of the time, and in line with surveillance organisations the other 50% of the time. Of course, he always has some reason for having the opinion, it's all covered up just fine, so it could also be perfectly legit. It's just weird to argue both sides at the same time.

His being an alleged anarchist, how does that hold with the prohibition for forks to use Signal's servers? Or the insistence that Google is the only place you should get the apk from? Shouldn't we all build from source, not trust a central distribution point? They argue both sides and I find it hard to tell what they really believe in.

That said, I definitely see your point and, as said, he does plenty things to improve the status quo. It's just his rejection of other things that would be even better.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#66
post #56

Earlier quoted context omitted.

Unfortunately, your interpretation of facebook's motives require trusting that they'll only do what their PR says they'll do, and not what they're able to do. Or, even if that is their current reasoning, one then has to trust that they won't then take advantage of said ability in the future. For many of us, facebook's past actions are more than enough to prove that they do not deserve the benefit of the doubt in this…

In addition, if this is indeed the backstory, then Facebook’s product management team failed miserably by not owning the story and instead deferring to anonymous internet commenters to explain their changes.

Remember when Facebook Security added SMS 2-factor verification and promised to never use the phone number for anything else, but then they were overridden and it was fed into the social graph, leading to their CISO resigning ?

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#69
post #54

Probably because: All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook. ( https://scontent.whatsapp.net/v/t39.856…

Yeah. It is really clear that Facebook is finally getting around to just implementing this feature of effectively having "hosted clients" for companies to be able to more easily--and yes: less securely--build chat bots (a mechanism that I appreciate is maybe less than ideal to encourage, but frankly just doesn't feel that bad and certainly isn't a surprise: Facebook has been taking about this for a year or two now);…

Yes, everyone is in complete hysterics exactly because Facebook is evil (by the definition "harmful or tending to harm" (OED) or "morally reprehensible" (Merriam-Webster)). Just remember the recent(-ish) Oculus controversy, where they forced everyone who bought their hardware to sign in with Facebook and in some cases (soft-)bricked users devices because their Facebook accounts did not have enough activity [1]. Especially because Palmer Luckey (founder of Oculus) when answering questions about the acquisition in 2014 said that Facebook would not do such a thing [0].

I personally am scared because the language being used here is not at all specific to the scenario mentioned here ("hosted clients"). I understand that anything more specific would probably be rejected by their legal team. I am afraid that some 5 years down the line they'll be able to do something worse without notifying users because the TOCs and privacy policies are written in this ambiguous language.

Regarding alternatives, I can't really speak on the security/privacy of any of them but from what I can gather, Matrix does have E2E-encryption functionality [2] so I'm not quite sure how it is less secure than Signal (provided you host your own server and/or have a reasonable degree of trust in the server-operator of your conversation-partner).

[0] https://www.cgmagonline.com/2020/08/19/oculus-founder-facebo...

[1] https://www.eurogamer.net/articles/2020-10-15-oculus-quest-2...

[2] https://matrix.org/blog/2020/05/06/cross-signing-and-end-to-...

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#70
post #38

Earlier quoted context omitted.

Please stop bringing up this "never roll your own crypto" argument. It's a guideline, not a hard rule. Signal actually rolled their own crypto and aren't constantly criticized for that, on the contrary. Signal is praised for rolling it's own crypto. Don't get me wrong, the Telegram crypto can (and should) definitely be criticized. But please criticize that they use "bad crypto" or "strange crypto" or "unreviewed cryp…

I am no expert, but "Signal rolling their own crypto" isn't the same as "X rolling their own crypto": 1. Folks spear-heading the Noise Protocol Framework (upon which Signal's protocol is based) are cryptographers [0]. 2. They built upon existing standards for one specific purpose: Creating two-way secure channels [1]. [0] https://signal.org/docs/ [1] https://www.youtube-nocookie.com/embed/3gipxdJ22iM

As far as I know, the Signal protocol was developed for TextSecure back in 2013. Noise actually references the Double Ratchet Algorithm by Moxie and Trevor Perrin as an inspiration. Not the other way around.

At some point in time, all now well-established cryptographers will have developed their first own cryptosystem, without already having established a good reputation. Whether or not someone develops a cryptosystem without being famous for cryptography work is simply not a good argument for discussing a cryptosystem. The properties of a cryptosystem are a good argument for discussing it.

Post reply on HN