Live data from Hacker News

WhatsApp whitepaper removed sentence about never having access to private keys

twitter.com

101–110 of 111 posts

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#102

Earlier quoted context omitted.

Good point. Here is the full text >All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook. Not sure if the facebook…

> “The _WhatsApp_ server has no access to the client’s private keys” This is craftily ambiguous.

The Facebook server does 0=)

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#103

Has anyone tried getsession.org? Seems one step further to signal and telegram..

In spite of what their website says, I'm pretty sure they removed multi-device support a good while ago, which makes it less useful. I just tried out version 1.4.4 for desktop, and device linking is nowhere to be found anymore.

I like their idea though. Encryption without a server.

I independently implemented similar ideas over the holidays and then discovered that there were people with similar ideas.

Code:

https://github.com/adsharma/zre_raft/blob/main/zre_raft/zre_...

Usage:

https://github.com/adsharma/zre_raft/commit/b6f897539d1bef10...

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#104
post #73

Earlier quoted context omitted.

Yes, everyone is in complete hysterics exactly because Facebook is evil (by the definition "harmful or tending to harm" (OED) or "morally reprehensible" (Merriam-Webster)). Just remember the recent(-ish) Oculus controversy, where they forced everyone who bought their hardware to sign in with Facebook and in some cases (soft-)bricked users devices because their Facebook accounts did not have enough activity [1]. Espec…

And when Facebook is doing something evil, I actively blast them for it; in particular, I have been extremely vocal with everyone I know about many aspects of the Oculus account issue, which I consider to be extremely evil when combined with their closed store model and DRM setup with developer account revocation (etc. I am somewhat famous for being a broken record on some topics, so I will try to avoid going into to…

> Your metadata just ends up getting semi-permanently logged on various machines, and there is nothing you can do about it at this time.

Sealed sender means that an eavesdropper who can introspect into RAM inside Signal's AWS infrastructure is no better off than a network eavesdropper who passively sniffs ingress/egress.

That doesn't mean they can't build a reasonably accurate metadata database covering most people--people who communicate from a limited number of mobile ips to a limited number of mobile ips.

Signal is way better than matrix, but let's not pretend it has totally solved the metadata problem.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#105

I have a question to people who said Telegram is worse than WhatsApp in every possible way for privacy. Do you still hold this belief? At least Telegram is holding its promise, if you start secret chat only you and your peer knows encryption keys

Didn’t Telegram roll their own crypto?

Telegram rolled their own crypto, backdoored it and got caught https://t.co/YTmXqgzzzg?amp=1

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#106
It really depends on what you use whatsapp for.

The US usage patterns seem different, but where I am everyone has whatsapp and it's basically used as a sms system that actually works. If you compare whatsapp's security and features to sms security and features, you stop caring.

If you really want trustable end to end encryption, there are other apps for that :)

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#107
post #65

Earlier quoted context omitted.

> And I can't tell if Moxie really means to improve the status quo or works for some three letter agency and builds just enough metadata opportunities into popular messengers and opportunistic encryption into WhatsApp to be helpful without being suspicious. Moxie is an anarchist (or near to it) and has been so for a long time. Secretly working for the NSA would be a stupendously long con.

Might not have been planed from the get go. But let me quote myself from a sibling comment: > it's more of a hyperbole than something I truly suspect. It's just that their opinions are in line with the hacker community 50% of the time, and in line with surveillance organisations the other 50% of the time. Of course, he always has some reason for having the opinion, it's all covered up just fine, so it could also be p…

"Or the insistence that Google is the only place you should get the apk from?"

No, you can but are not forced to. There is compiled apk (that autoupdates) which you can get directly from their website.

https://signal.org/android/apk/

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#108

Earlier quoted context omitted.

There's no need to continue litigating Telegram's crypto. (the criticisms are well enough known that people either aren't going to listen or can just go read them)

I’ve not heard of Telegram’s crypto criticisms, and I follow tech. Why would I know to just go read it? It’s almost as if your cognitive time series is not the same as everyone’s. (why the parens)?

Instead of Don't get me wrong, the Telegram crypto can (and should) definitely be criticized. But please criticize that they use "bad crypto" or "strange crypto" or "unreviewed crypto", not that it's their own. (And of course, substantiate such claims with references that can be discussed.) the people bringing it up can just provide you with a link to one of the many discussions of it.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#109

I've deleted my WhatsApp account today. It was the only product I've ever used from Facebook, and it will be the last. Say no to this spyware machine.

Yep. Probably the recent WhatsApp hype was overblown, and the situation after 08-02-2021 will not be so different from the situation now.

But that situation is still that WhatsApp profits, and is produced and maintained by, one of the most morally bankrupt companies on earth.

So to ditch it is still a good thing.

Re: WhatsApp whitepaper removed sentence about never having access to private keys

#110
So if I understand correctly, when a business uses WhatsApp, to maintain E2EE WhatsApp must "emulate" as if all customer reps of that business were sending WhatsApp messages through one phone. To do that, all reps connect to what is essentially one WhatsApp instance in a Docker container. This container holds the private key. And if a business tells Facebook to host that container, this means Facebook has possession of the private key?
Post reply on HN