Live data from Hacker News

WhatsApp end-to-end encrypted backups security assessment

research.nccgroup.com

31–40 of 121 posts

Re: WhatsApp end-to-end encrypted backups security assessment

#31

Earlier quoted context omitted.

Wrong. 1. Backups are opt-in - just as they have always been. 2. The E2EE backups do not rely on HSM's - they rely on a client-side only key derived by the WhatsApp client, on the user's phone. 3. The client-side key backup does not rely solely on HSM's - naturally, the client-side key must be backed up in case the user loses their phone. This key is itself encrypted and stored remotely (whether this is on third-part…

It may be my fault, but I have always set it to no backups, but 2am it'll more or less freeze with a "backing up..." message

I've seen the same thing, and I've never enabled backups. I'd really like to know what it's doing.

Re: WhatsApp end-to-end encrypted backups security assessment

#34
I can tell you first hand, anytime a company pays a third party to do a security assessment, the result is purely what the company wants you to see. Independent does not mean that it wasn't influenced, just that it wasn't done by the company itself.

Re: WhatsApp end-to-end encrypted backups security assessment

#36
post #10

Earlier quoted context omitted.

Wrong. 1. Backups are opt-in - just as they have always been. 2. The E2EE backups do not rely on HSM's - they rely on a client-side only key derived by the WhatsApp client, on the user's phone. 3. The client-side key backup does not rely solely on HSM's - naturally, the client-side key must be backed up in case the user loses their phone. This key is itself encrypted and stored remotely (whether this is on third-part…

what's the threat this hsm is adding protection against ? i don't mean to be ironic, i genuinely couldn't understand after reading the paper.

I was surprised to read that OPAQUE. uses/generates deterministic asymmetric keypairs based on a secret seed. I'd posit the HSM stores this seed so that it can use various derivations to verify whether a given key asserted by a client was generated by that seed. (https://www.ietf.org/id/draft-irtf-cfrg-opaque-07.html)

I have only used key derivation in symmetric protocols, so tbh I don't know how you do deterministic asymmetric key generation, or even which primitive uses it.

Re: WhatsApp end-to-end encrypted backups security assessment

#37

Why on earth do people trust a closed source messenger owned by Facebook, which backs up to Google? Signal and Matrix are open source and full-featured.

I can think of one UN sanctioned country where whatsapp _works_, but signal is banned.

Re: WhatsApp end-to-end encrypted backups security assessment

#38
post #17

Earlier quoted context omitted.

Most likely because their contacts don't want to switch. I've migrated extended family off WhatsApp to Signal but it was a nontrivial effort since their contacts don't want to use anything but WhatsApp.

Just imagine the world we live in, how numb average joe is. I said same things to most of my closer people and in the end they tell me “well they have all our data anyway”. And all they have to do is just download an application.

TBF that's not really all they have to do. They also have to use that new application, which means (further) diving their communications stream. And it means an additional onboarding step when they set up a new device.

I understand these aren't huge obstacles, but I am generally reluctant to add additional communication channels for these reasons - they aren't trivialities to everyone.

Re: WhatsApp end-to-end encrypted backups security assessment

#39

Why on earth do people trust a closed source messenger owned by Facebook, which backs up to Google? Signal and Matrix are open source and full-featured.

> Why on earth do people trust a closed source messenger owned by Facebook, which backs up to Google?

Those are some of the few companies that are large enough to oppose governments.

> Signal and Matrix are open source

The main advantage of which is to enable audits like this, which WhatsApp is doing.

Of course you can't actually build WhatsApp from the audited source or pin it to the audited version... but you can't do that with Signal either. Not to mention that you're stuck with closed-source Google Play Services (or closed-source iOS) anyway.

Re: WhatsApp end-to-end encrypted backups security assessment

#40

I can tell you first hand, anytime a company pays a third party to do a security assessment, the result is purely what the company wants you to see. Independent does not mean that it wasn't influenced, just that it wasn't done by the company itself.

This is false. The security company has its own reputation to mind, and its people their own conscience. (There may be cases like you're saying, but "anytime" and "purely" is completely wrong.)

This is first-hand as well. But I'm not the one making a universal claim.

Post reply on HN