A TD:DR; for people. The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions: "At no time does the WhatsApp server have access to any of the client's private keys." [1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...
Instead, they added the following on page 13: > The WhatsApp server has no access to the client’s private keys, (...)
WhatsApp whitepaper removed sentence about never having access to private keys
91–100 of 111 posts
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#92Earlier quoted context omitted.
It doesn't mean they don't either. It's the removal of the previous claim that's worrying. But honestly, it doesn't matter anyway since Whatsapp is somehow able to backup all your data on Google Drive and restore it on separate phones. How are they able to do that without backing up the private key? https://faq.whatsapp.com/android/chats/how-to-restore-your-c...
The backups are unencrypted as highlighted in the UI (if I recall correctly). They re-generate the keys when you switch phones / re-install / clear data. That's when you get to see the "XYZ's security code changed" service message
> For example, if you use a data backup service integrated with our Services (like iCloud or Google Drive), they will receive information you share with them, such as your WhatsApp messages.
https://www.whatsapp.com/legal/updates/privacy-policy/?lang=...
Looks like you're right, it must be unencrypted.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#93A TD:DR; for people. The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions: "At no time does the WhatsApp server have access to any of the client's private keys." [1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...
Instead, they added the following on page 13: > The WhatsApp server has no access to the client’s private keys, (...)
>All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook.
Not sure if the facebook exception was there in the previous version.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#94Earlier quoted context omitted.
Yes, everyone is in complete hysterics exactly because Facebook is evil (by the definition "harmful or tending to harm" (OED) or "morally reprehensible" (Merriam-Webster)). Just remember the recent(-ish) Oculus controversy, where they forced everyone who bought their hardware to sign in with Facebook and in some cases (soft-)bricked users devices because their Facebook accounts did not have enough activity [1]. Espec…
And when Facebook is doing something evil, I actively blast them for it; in particular, I have been extremely vocal with everyone I know about many aspects of the Oculus account issue, which I consider to be extremely evil when combined with their closed store model and DRM setup with developer account revocation (etc. I am somewhat famous for being a broken record on some topics, so I will try to avoid going into to…
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#95Earlier quoted context omitted.
Services hosted outside the US offer less protection against US intelligence agencies, not more.
Somehow I don’t buy it. Care to explain? One would think that being hosted on US soil makes it more likely to get backdoored by NSA type agencies.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#96Earlier quoted context omitted.
Thanks for posting this. I was considering making the jump to a new messenger but decided to wait and see what others had to say about the changes to the privacy policy and what it actually means from a privacy perspective. The use case for businesses to be able to use it for hosted clients (probably hosted and with messages stored by facebook) makes sense, and doesn't seem as bad as its been made out to be – still g…
Matrix is pretty open about how it hasn't been able to do anything about metadata leakage (which they have even at some times claimed is somewhat inherent to its federated nature; I think that is an overstatement, but is something that even they seem to believe). https://matrix.org/blog/wp-content/uploads/2017/02/2017-02-0... > Matrix does not protect metadata currently; server admins can see who you talk to & when (…
Not trying to push Matrix or anything, i've been using Signal for some time already anyway, but thought i'd see what alternatives there are. The lack of chat backups is a real drawback, though since the Android version has a backup option, i'm hoping it's something they'll eventually implement?
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#97Earlier quoted context omitted.
Services hosted outside the US offer less protection against US intelligence agencies, not more.
Somehow I don’t buy it. Care to explain? One would think that being hosted on US soil makes it more likely to get backdoored by NSA type agencies.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#98Earlier quoted context omitted.
Instead, they added the following on page 13: > The WhatsApp server has no access to the client’s private keys, (...)
Good point. Here is the full text >All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook. Not sure if the facebook…
This is craftily ambiguous.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#99Earlier quoted context omitted.
WhatsApp promises end to end encryption, with no access to the content of your messages, just like iMessage and signal. This tweet doesn't establish otherwise.
The app can still provide end-to-end encryption while simultaneously piping your private keys direct to FB. They're not really related.
It would also completely invalidate their "we don't have the keys" defence to law enforcement requests.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#100Earlier quoted context omitted.
Good point. Here is the full text >All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook. Not sure if the facebook…
> “The _WhatsApp_ server has no access to the client’s private keys” This is craftily ambiguous.