Live data from Hacker News

WhatsApp whitepaper removed sentence about never having access to private keys

twitter.com

71–80 of 111 posts

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#71

I have a question to people who said Telegram is worse than WhatsApp in every possible way for privacy. Do you still hold this belief? At least Telegram is holding its promise, if you start secret chat only you and your peer knows encryption keys

This is a false dichotomy. It isn't Telegram vs WhatsApp. Even if it was, the answer, in light of this new discovery, would be neither.

At this point, Matrix, Threema, and Signal are some of the more popular cross-platform solutions left to ponder about. Telegram nor WhatsApp are answers to any privacy question anyone may have.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#72
post #29
post #8

Can anybody remember the story, I think it was a few years ago, when a journalist warned in an article that messaging apps like Whatsapp are vulnerable because they rely on a server for key exchange, and all the security researchers requested that the story should be retracted because it would lead people to use SMS which is even less secure? I may be misremembering some details.

https://www.theguardian.com/technology/2017/jan/13/whatsapp-... HN Comments - https://news.ycombinator.com/item?id=13389935 https://indianexpress.com/article/technology/tech-news-techn...

Thanks!

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#73
post #54

Earlier quoted context omitted.

Yeah. It is really clear that Facebook is finally getting around to just implementing this feature of effectively having "hosted clients" for companies to be able to more easily--and yes: less securely--build chat bots (a mechanism that I appreciate is maybe less than ideal to encourage, but frankly just doesn't feel that bad and certainly isn't a surprise: Facebook has been taking about this for a year or two now);…

Yes, everyone is in complete hysterics exactly because Facebook is evil (by the definition "harmful or tending to harm" (OED) or "morally reprehensible" (Merriam-Webster)). Just remember the recent(-ish) Oculus controversy, where they forced everyone who bought their hardware to sign in with Facebook and in some cases (soft-)bricked users devices because their Facebook accounts did not have enough activity [1]. Espec…

And when Facebook is doing something evil, I actively blast them for it; in particular, I have been extremely vocal with everyone I know about many aspects of the Oculus account issue, which I consider to be extremely evil when combined with their closed store model and DRM setup with developer account revocation (etc. I am somewhat famous for being a broken record on some topics, so I will try to avoid going into too much depth ;P).

Obviously, though, (but maybe not to you?!?) this is a completely unrelated issue to the WhatsApp "changes" this week: trying to use "Facebook is evil, so everything they do is evil" is not only ridiculously disingenuous--to the point of undermining the ability to make these kinds of arguments at all and still be taken seriously :(--but doesn't even satisfy basic questions like "ok, and do you also consistently use this frame with Apple and Google?" (both of whom are also evil to the point of being morally reprehensible).

As for Matrix: they do not have a solution for metadata yet, and even have gone so far as to claim that maybe they will never figure it out (due to being a federated system). Your metadata just ends up getting semi-permanently logged on various machines, and there is nothing you can do about it at this time. AFAIK, Signal has implemented solutions to this (even, I believe, fixing the subtle thing I used to complain about where their server technically had a temporary in-memory metadata log for rate limiting).

https://github.com/matrix-org/synapse/issues/2188

https://github.com/matrix-org/synapse/issues/4565

(I have now provided a bit more quoted detail in this other comment, which i will link to rather than cause a lot of replication spam.)

https://news.ycombinator.com/item?id=25687395

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#74
post #55
post #53

Earlier quoted context omitted.

> And I can't tell if Moxie really means to [...] Not a fan of Moxie either but you got a source for that?

Sorry, was still editing in a bit of context, please see the current version. If there is anything in particular feel free to ask, but the whole analysis is more of a submission of its own that I'm not sure I'm up to writing today.

No this is fine. I fully agree with your points and that's precisely why I'm not a fan of his. But yeah, Signal is the shiniest turd we have for secure messaging that's normie (as in not someone in tech) friendly.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#76
post #64
post #54

Earlier quoted context omitted.

Yeah. It is really clear that Facebook is finally getting around to just implementing this feature of effectively having "hosted clients" for companies to be able to more easily--and yes: less securely--build chat bots (a mechanism that I appreciate is maybe less than ideal to encourage, but frankly just doesn't feel that bad and certainly isn't a surprise: Facebook has been taking about this for a year or two now);…

Thanks for posting this. I was considering making the jump to a new messenger but decided to wait and see what others had to say about the changes to the privacy policy and what it actually means from a privacy perspective. The use case for businesses to be able to use it for hosted clients (probably hosted and with messages stored by facebook) makes sense, and doesn't seem as bad as its been made out to be – still g…

Matrix is pretty open about how it hasn't been able to do anything about metadata leakage (which they have even at some times claimed is somewhat inherent to its federated nature; I think that is an overstatement, but is something that even they seem to believe).

https://matrix.org/blog/wp-content/uploads/2017/02/2017-02-0...

> Matrix does not protect metadata currently; server admins can see who you talk to & when (but not what). If you need this today, look at Ricochet or Vuvuzela etc.

> Protecting metadata is incompatible with bridging.

> However, in future peer-to-peer home servers could run clientside, tunnelling traffic over Tor and using anonymous store-and-forward servers (a la Pond).

> But for now this is sci-fi.

https://github.com/matrix-org/synapse/issues/2188

https://github.com/matrix-org/synapse/issues/4565

Signal, in contrast, put a lot of effort into metadata reduction--critical as they are a single giant hosted relay service--and in the process (I am very sure) even fixed the issue I used to complain about wherein their server was technically keeping around a temporary-ish in-memory metadata log for rate limiting.

https://signal.org/blog/sealed-sender/

If you are going to switch to something, switch to Signal (...though I sadly can't in good faith ever really recommend anyone do that, due to how Signal has crippled the ability to do chat backups; more info on this in the other thread going on today re Signal/WhatsApp).

https://news.ycombinator.com/item?id=25686475

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#77
post #59
post #54

Earlier quoted context omitted.

Yeah. It is really clear that Facebook is finally getting around to just implementing this feature of effectively having "hosted clients" for companies to be able to more easily--and yes: less securely--build chat bots (a mechanism that I appreciate is maybe less than ideal to encourage, but frankly just doesn't feel that bad and certainly isn't a surprise: Facebook has been taking about this for a year or two now);…

How is Matrix less secure? As far as I'm aware, all the Element clients now implement E2EE by default.

https://news.ycombinator.com/item?id=25687395

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#78
post #54

Earlier quoted context omitted.

Yeah. It is really clear that Facebook is finally getting around to just implementing this feature of effectively having "hosted clients" for companies to be able to more easily--and yes: less securely--build chat bots (a mechanism that I appreciate is maybe less than ideal to encourage, but frankly just doesn't feel that bad and certainly isn't a surprise: Facebook has been taking about this for a year or two now);…

Yes, everyone is in complete hysterics exactly because Facebook is evil (by the definition "harmful or tending to harm" (OED) or "morally reprehensible" (Merriam-Webster)). Just remember the recent(-ish) Oculus controversy, where they forced everyone who bought their hardware to sign in with Facebook and in some cases (soft-)bricked users devices because their Facebook accounts did not have enough activity [1]. Espec…

It was carefully explained to me that Facebook only wishes they could be as evil as Google is, now, or as Microsoft used to be able to be. Nowadays, even Microsoft and Russia wish they could afford to be as evil as Google; and even the spooks have had to outsource theirs.

(I use "evil" in the technical sense: not necessarily intending to exterminate humanity, but wanting to be able to -- or anything short of that -- if they did.)

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#79
post #7

A TD:DR; for people. The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions: "At no time does the WhatsApp server have access to any of the client's private keys." [1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...

Instead, they added the following on page 13:

> The WhatsApp server has no access to the client’s private keys, (...)

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#80
post #30

The WhatsApp client is a closed source, so why is this news ? Is this some kind of promise from the company that the client will not have access to private keys ?

WhatsApp promises end to end encryption, with no access to the content of your messages, just like iMessage and signal. This tweet doesn't establish otherwise.

The app can still provide end-to-end encryption while simultaneously piping your private keys direct to FB. They're not really related.
Post reply on HN