Earlier quoted context omitted.
How is this a violation of privacy… that’s not how e2e encryption works.
Whatsapp also shows certain messages as "forwarded many times".
WhatsApp end-to-end encrypted backups security assessment
71–80 of 121 posts
Re: WhatsApp end-to-end encrypted backups security assessment
#72I can tell you first hand, anytime a company pays a third party to do a security assessment, the result is purely what the company wants you to see. Independent does not mean that it wasn't influenced, just that it wasn't done by the company itself.
This is false. The security company has its own reputation to mind, and its people their own conscience. (There may be cases like you're saying, but "anytime" and "purely" is completely wrong.) This is first-hand as well. But I'm not the one making a universal claim.
Re: WhatsApp end-to-end encrypted backups security assessment
#73I can tell you first hand, anytime a company pays a third party to do a security assessment, the result is purely what the company wants you to see. Independent does not mean that it wasn't influenced, just that it wasn't done by the company itself.
We value our independence highly. It is what ultimately brings in business. It would be very bad business if one our customers gets hacked, when it was an easy vulnerability for us to find.
This is the same for the NCC group here. If in a few weeks the WhatsApp e2e encryption on backups was cracked, they would look like fools. And that is not good for business.
Re: WhatsApp end-to-end encrypted backups security assessment
#74I can tell you first hand, anytime a company pays a third party to do a security assessment, the result is purely what the company wants you to see. Independent does not mean that it wasn't influenced, just that it wasn't done by the company itself.
This doesn’t tally with my own experience and I’ve worked with many including NCC Group.
Re: WhatsApp end-to-end encrypted backups security assessment
#75Earlier quoted context omitted.
Because the number of people who can actually validate the security of the open source options is vanishingly small and assessments like this provide sufficient evidence that WhatsApp's claims are not bunk.
You just need one. Vanishingly small or not.
Re: WhatsApp end-to-end encrypted backups security assessment
#76Earlier quoted context omitted.
NCC Group is a legit outfit, a public company in fact, so this comment is not warranted.
There is no proof what they tested was actually what's in people's phones. It's most likely a separate "cleaned-up" build/codebase for looks. And chances are against users.
Re: WhatsApp end-to-end encrypted backups security assessment
#77Earlier quoted context omitted.
Signal doesn't get credit for being open source.
Are you saying it’s not getting enough credit or that it shouldn’t? The Signal code was closed source for longer than a year (from April 2020) when no commits were done in the public repo because . Some months ago the public repo got a barrage of commits after that long gap. It wasn’t that the Signal platform and client had no updates during this time. There were many, but the code wasn’t released. Signal may be open…
Re: WhatsApp end-to-end encrypted backups security assessment
#78I can tell you first hand, anytime a company pays a third party to do a security assessment, the result is purely what the company wants you to see. Independent does not mean that it wasn't influenced, just that it wasn't done by the company itself.
As a pentester at a security company doing assessments for customers, I can say that this is definitely false. We value our independence highly. It is what ultimately brings in business. It would be very bad business if one our customers gets hacked, when it was an easy vulnerability for us to find. This is the same for the NCC group here. If in a few weeks the WhatsApp e2e encryption on backups was cracked, they wou…
Re: WhatsApp end-to-end encrypted backups security assessment
#79Why on earth do people trust a closed source messenger owned by Facebook, which backs up to Google? Signal and Matrix are open source and full-featured.
Because the number of people who can actually validate the security of the open source options is vanishingly small and assessments like this provide sufficient evidence that WhatsApp's claims are not bunk.
Re: WhatsApp end-to-end encrypted backups security assessment
#80Earlier quoted context omitted.
I completely forgot about this issue :) I'm glad someone was interested in looking at how those backups work. Perhaps my complaints also contributed to this investigation :)))
These look like messages being re-sent from the service to the client. This is not surprising - when you ask someone else to route messages for you, even encrypted messages, you are giving them the (encrpyted) payload and asking them to route it for you. If you have a large network with billions of users, it's reasonable that some of the users' phones may be offline some of the time. Should the service just drop mess…