Live data from Hacker News

WhatsApp whitepaper removed sentence about never having access to private keys

twitter.com

81–90 of 111 posts

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#81
post #52

Earlier quoted context omitted.

You mean Signal which was created by Moxie Marlinspike and other legit cryptogaphers and security researchers? Who rolled Telegram's crypto? No idea. Why should we trust them? No idea. I think I'll go with the people who have been contributing to the field for years and are highly respected.

I’d rather take the service which is not hosted on US servers over one that is, given that I can verify neither of their server code.

Services hosted outside the US offer less protection against US intelligence agencies, not more.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#82
post #73

Earlier quoted context omitted.

Yes, everyone is in complete hysterics exactly because Facebook is evil (by the definition "harmful or tending to harm" (OED) or "morally reprehensible" (Merriam-Webster)). Just remember the recent(-ish) Oculus controversy, where they forced everyone who bought their hardware to sign in with Facebook and in some cases (soft-)bricked users devices because their Facebook accounts did not have enough activity [1]. Espec…

And when Facebook is doing something evil, I actively blast them for it; in particular, I have been extremely vocal with everyone I know about many aspects of the Oculus account issue, which I consider to be extremely evil when combined with their closed store model and DRM setup with developer account revocation (etc. I am somewhat famous for being a broken record on some topics, so I will try to avoid going into to…

Extremely evil was when an entire population was wiped off the earth in the industrial genocide of the Third Reich. Facebook or WhatsApp changing its TOS is irritating but it is not "extremely evil" I just realised that this is the same absolute language that incited the violence we saw on Wednesday. If something is "extremely evil" then there are very few constraints short of the Geneva convention and probably not that you should be bound by in your response. The point is language matters and so enough with calling everything we disagree with "evil".

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#83
post #52

Earlier quoted context omitted.

I’d rather take the service which is not hosted on US servers over one that is, given that I can verify neither of their server code.

Services hosted outside the US offer less protection against US intelligence agencies, not more.

Somehow I don’t buy it. Care to explain? One would think that being hosted on US soil makes it more likely to get backdoored by NSA type agencies.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#84
post #76
post #64

Earlier quoted context omitted.

Thanks for posting this. I was considering making the jump to a new messenger but decided to wait and see what others had to say about the changes to the privacy policy and what it actually means from a privacy perspective. The use case for businesses to be able to use it for hosted clients (probably hosted and with messages stored by facebook) makes sense, and doesn't seem as bad as its been made out to be – still g…

Matrix is pretty open about how it hasn't been able to do anything about metadata leakage (which they have even at some times claimed is somewhat inherent to its federated nature; I think that is an overstatement, but is something that even they seem to believe). https://matrix.org/blog/wp-content/uploads/2017/02/2017-02-0... > Matrix does not protect metadata currently; server admins can see who you talk to & when (…

Those slides are from 2017. P2P Matrix was released in June 2020. A lot of work is being done on Dendrite, the latest commit was posted two hours ago as of this writing. From the GitHub page for Dendrite: "As of November 2020 we're at around 58% CS API coverage and 83% Federation coverage, though check CI for the latest numbers."

So, yes, for now the metadata leakage is a real issue. However this is likely to change in the near future.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#85
post #43
post #8

Can anybody remember the story, I think it was a few years ago, when a journalist warned in an article that messaging apps like Whatsapp are vulnerable because they rely on a server for key exchange, and all the security researchers requested that the story should be retracted because it would lead people to use SMS which is even less secure? I may be misremembering some details.

Warning that it's vulnerable because it relies on a server for key exchange is like warning that water is wet and you shouldn't let it loose in your house to prevent water damage. It's correct, but redundant. The very definition of end to end encryption is not trusting the server, so you need to verify the exchanged keys. This is a requirement in Signal, Wire, Threema, Jami, Briar, Element/Matrix, Keybase, OTR, and a…

Right. WhatsApp/iMessage etc end-to-end encryption is meaningless because a single firm can turn it off invisibly any time they like. In fact we only have their assurance that it even exists at all, given the difficulty of reverse engineering their protocols and checking everyone has the same clients.

I've felt very uncomfortable about the way Valley firms jumped on board the end-to-end bandwagon. The intentions are good and ones I wholeheartedly support, but the claims made for it are just not true. The WhatsApp paper is at least slightly less deceptive than it once was, and I guess that's progress of sorts, but the damage is done already. One day Facebook will discover some sort of burning reason why a WhatsApp user has to be decrypted, it will come out that this has been done, and trust will be irrevocably burned.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#86

Has anyone tried getsession.org? Seems one step further to signal and telegram..

In spite of what their website says, I'm pretty sure they removed multi-device support a good while ago, which makes it less useful.

I just tried out version 1.4.4 for desktop, and device linking is nowhere to be found anymore.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#88

Probably because: All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook. ( https://scontent.whatsapp.net/v/t39.856…

> .. The WhatsApp server has no access to the client’s private keys ..

обманывать

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#89

Has anyone tried getsession.org? Seems one step further to signal and telegram..

In spite of what their website says, I'm pretty sure they removed multi-device support a good while ago, which makes it less useful. I just tried out version 1.4.4 for desktop, and device linking is nowhere to be found anymore.

Issue from April 2020 says “We only allow one linked device currently”:

https://github.com/loki-project/session-desktop/issues/1104

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#90
post #7

A TD:DR; for people. The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions: "At no time does the WhatsApp server have access to any of the client's private keys." [1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...

[deleted]
Post reply on HN