Live data from Hacker News

WhatsApp end-to-end encrypted backups security assessment

research.nccgroup.com

61–70 of 121 posts

Re: WhatsApp end-to-end encrypted backups security assessment

#61

I’m actually quite impressed that WA has allowed this report to be released publicly. They did not have any obligation to do that, but it sure makes them look more trustworthy.

They’re probably trying to win back trust after the privacy changes fiasco.

Re: WhatsApp end-to-end encrypted backups security assessment

#62

Why on earth do people trust a closed source messenger owned by Facebook, which backs up to Google? Signal and Matrix are open source and full-featured.

I think Signal and Matrix are more trustworthy and auditable.

However I also think more people are on WhatsApp than those two (and possibly more) combined and people want to just use it probably for that reason.

I saw some of my contacts sign up to Signal firstly after the privacy fiasco then again in smaller quantity after the major outage. I deleted WhatsApp a while ago but I decided to re-install it again recently or basically risk losing contact with some old friends. In fairness I did try and convert people to Signal; I managed to convince a couple - so not all was lost.

Re: WhatsApp end-to-end encrypted backups security assessment

#63

I came across this twitter thread during the last Facebook outage. Apparently something very wrong is happening there with their backups. I would definitely check similar cases. Confirmed by multiple people :/ I quote the author: This is really weird. In #WhatsApp, I started to see messages that I know 100% that I deleted 2 days ago?! WTF is happening there? I think this is a really big violation of privacy! I see th…

this happen to me, I can still see messages that I delete yesterday.

Re: WhatsApp end-to-end encrypted backups security assessment

#67
post #7

Earlier quoted context omitted.

Wrong. 1. Backups are opt-in - just as they have always been. 2. The E2EE backups do not rely on HSM's - they rely on a client-side only key derived by the WhatsApp client, on the user's phone. 3. The client-side key backup does not rely solely on HSM's - naturally, the client-side key must be backed up in case the user loses their phone. This key is itself encrypted and stored remotely (whether this is on third-part…

Last time I looked at it, WhatsApp backup key was simply stored server side. Also, backup encryption key never changes, basically. I tell you this because I needed to extract an old backup that I did on Android years ago to recover some messages: well it was as simple as extracting the key from another phone where I was signed into (need root privileges, but of course you can just access the account from an emulator,…

How and where did you have a chance to "look at" server side, may I ask?

Re: WhatsApp end-to-end encrypted backups security assessment

#68
post #45

I came across this twitter thread during the last Facebook outage. Apparently something very wrong is happening there with their backups. I would definitely check similar cases. Confirmed by multiple people :/ I quote the author: This is really weird. In #WhatsApp, I started to see messages that I know 100% that I deleted 2 days ago?! WTF is happening there? I think this is a really big violation of privacy! I see th…

How is this a violation of privacy… that’s not how e2e encryption works.

Whatsapp also shows certain messages as "forwarded many times".

Re: WhatsApp end-to-end encrypted backups security assessment

#69
post #23

Earlier quoted context omitted.

encrypt with in-memory nonce

Still hit the issue with large media that doesn't fit in memory and your gain is still minor (resist a compromised filesystem.. maybe.. if they didn't compromise the binary too)

How does that hit an issue with large media that doesn't fit in memory? The encrypted media is on flash. The key is in memory. The key is small.

Re: WhatsApp end-to-end encrypted backups security assessment

#70
post #17

Earlier quoted context omitted.

Most likely because their contacts don't want to switch. I've migrated extended family off WhatsApp to Signal but it was a nontrivial effort since their contacts don't want to use anything but WhatsApp.

Just imagine the world we live in, how numb average joe is. I said same things to most of my closer people and in the end they tell me “well they have all our data anyway”. And all they have to do is just download an application.

Isn't it more like changing email? You'd keep checking your old one for quite a while.
Post reply on HN