Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
slashcrypto.org
Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
1–10 of 29 posts
Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
#2Also the vulnerabilty matches perfectly one scenario - when a person is in custody, the LEO cannot open its phone, but they can create account on new device with his sim card and continue "trusted" chats.
Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
#3In other words, this is not a crack because the glass is already broken.
I'm so relieved.
Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
#4If I read the post and came up with the thesis sentence myself, it would be "WhatsApp is vulnerable to MITM attacks because it tries to automate key changes by default"
Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
#5That seems to fit the currently accepted understanding of the word: https://en.wikipedia.org/wiki/Backdoor_(computing)
Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
#6Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
#7Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
#8The linked piece is hard to critique because it's borderline incoherent. The "conclusion" is simply not a conclusion, particularly this passage:
> A provider always has the ability to intercept messages as long as the user does not verify fingerprints. With WhatsApp, it is even harder to make sure, no MitM takes or took place. WhatsApp is closed source, so who can tell, if WhatsApp just displays wrong identity keys and lets the user think that everything is perfectly OK ..?
Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
#9No it is a backdoor. Becuase the app fucks you on purpose, even if you go to great lenghts to verify the keys. Also the vulnerabilty matches perfectly one scenario - when a person is in custody, the LEO cannot open its phone, but they can create account on new device with his sim card and continue "trusted" chats.
I install WhatsApp. How do I roll over my identity?
The way I see it is that WhatsApp is delegating the task of identity verification to the network provider (admittedly a weak link for the security conscious). But it _is_ the easiest way for the average user to continue chats on a new phone.
If the default setting were reversed, HN would stop complaining, but the 90% would.
The most 'secure' means of communication is probably a one-time pad communicated via paper on magic ink that you then burn, or something. There is a cost to ease of use in many cases. I wish the conversation was less about right v wrong, and more about what tradeoffs should be made and where to draw the line.
Re: Why the “WhatsApp-backdoor” is not a WhatsApp-backdoor
#10Let's not get hung up on semantics, and focus on the HARM.