Live data from Hacker News

WhatsApp data leak: 500M user records for sale

cybernews.com

101–109 of 109 posts

Re: WhatsApp data leak: 500M user records for sale

#102
post #97

Earlier quoted context omitted.

In the case of the above, you're not trusting the server, you're only trusting the CPU manufacturer. Attestation happens within the secure enclave inside the CPU, at which point having physical access to the machine doesn't (well, shouldn't, if it's correctly implemented) give you any insight into what code it's running or what data it's operating upon.

How can you know which CPU is running? Also, the software could easily change the output of the security chip (secure enclave is only on apple devices).

Part of the attestation process involves receiving a cryptographic signature from the CPU vendor. They can only fake it if they break the cryptography. And enclaves (or "trusted execution environments") aren't only on Apple chips, AMD and Intel have their own implementations.

Re: WhatsApp data leak: 500M user records for sale

#103
post #49

Earlier quoted context omitted.

Export each (or the most important) chats as zip files.

How? when I try to backup my chats, whatsapp says my only option is to send them to google (i dont want to do that even if they're encrypted)

There'll be an option to Share to iCloud Drive (or some other file manager like Documents or File Explorer) or AirDrop to a Mac etc.

Re: WhatsApp data leak: 500M user records for sale

#105
post #49

Earlier quoted context omitted.

How? when I try to backup my chats, whatsapp says my only option is to send them to google (i dont want to do that even if they're encrypted)

There'll be an option to Share to iCloud Drive (or some other file manager like Documents or File Explorer) or AirDrop to a Mac etc.

When I try export to chat it just gives me an error “unable to export chat”.

Re: WhatsApp data leak: 500M user records for sale

#106
post #102

Earlier quoted context omitted.

How can you know which CPU is running? Also, the software could easily change the output of the security chip (secure enclave is only on apple devices).

Part of the attestation process involves receiving a cryptographic signature from the CPU vendor. They can only fake it if they break the cryptography. And enclaves (or "trusted execution environments") aren't only on Apple chips, AMD and Intel have their own implementations.

But the CPU is first sending the signature to the OS, thuse enabling the OS to send you something else.

Re: WhatsApp data leak: 500M user records for sale

#107

So... what advise is there for technology comfortable people who want to mitigate the effects of data leaks like these? It seems like data provided is will be exposed eventually and company size doesn't seem correlate with data safety. For example should people be advised to rotate phone numbers every N amount of time?

People should be advised to not use phone numbers at all. There was a joke "all phone numbers leaked" list that just listed everything from 000-000-0000 to 999-999-9999. If there is no other information associated (names, pictures, emails, anything) then this leak is of almost comparable severity.

We used to have these things called Phone Books, that literally, contained everyone's phone numbers.

We didn't call those leaks.

Re: WhatsApp data leak: 500M user records for sale

#108

Earlier quoted context omitted.

People should be advised to not use phone numbers at all. There was a joke "all phone numbers leaked" list that just listed everything from 000-000-0000 to 999-999-9999. If there is no other information associated (names, pictures, emails, anything) then this leak is of almost comparable severity.

We used to have these things called Phone Books, that literally, contained everyone's phone numbers. We didn't call those leaks.

There's an important difference between people being able to do inefficient paper-based one-off `SELECT ... LIMIT 1` queries when needed and the entire world being able to find new and exciting ways to search, join and mix data at great speed—the latter tends to enable new and exciting ways for the data to be used both for commercial gain, criminal purposes, and abusive trolling. (See: the history of internet harassment for the last 20 years.)

Pointing out that we used to put all the phone numbers in a book published by the phone company and now we don't is historically true but practically unimportant, just as "hey, sorry to hear your house got broken into, but you know, people in IDYLLIC_RURAL_HAMLET don't even lock their front doors like you BIG_CITY folks do" isn't useful unless giving up living and working in BIG_CITY and moving to IDYLLIC_RURAL_HAMLET is actually a practical option, which most likely it isn't (and if that were to happen en masse, IDYLLIC_RURAL_HAMLET would suddenly find they'd also need to lock their front doors if their population increased by a factor or two).

Who could have predicted that technological change might lead to shifts in social attitudes? Or, indeed, that the rules, principles and institutions we collectively create to make society bearable have to adapt to said changes?

Post reply on HN