Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

151–160 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#151

- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Te…

[deleted]

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#152

- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Te…

A back door means losing trust forever. It doesn't matter if it was 7 years ago.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#153

Earlier quoted context omitted.

> I am quite aware how un-ergonomic such a messenger would be so I know that Telegram does little more than TLS protection of the network socket. And that's fine with me and with millions of others. The amount of people who understand this certainly isn’t in the millions. The fact is that most Telegram users have no idea that their conversations aren’t encrypted, most people incorrectly assume that it’s more secure t…

> This is complete nonsense. Whatsapp uses the Signal Protocol. Their claims of end-to-end encryption are true (and easily verifiable! just pull out the debugger of your choice) I don't dispute this but apparently there's still a way for Facebook to give FBI et. al. un-encrypted chats, no? So is that truly encrypted? > I think your (perfectly understandable) misinterpretation was corrected in a rather polite manner,…

>but apparently there's still a way for Facebook to give FBI et. al. un-encrypted chats, no?

I’d love to see a source for this.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#154

Earlier quoted context omitted.

> I am quite aware how un-ergonomic such a messenger would be so I know that Telegram does little more than TLS protection of the network socket. And that's fine with me and with millions of others. The amount of people who understand this certainly isn’t in the millions. The fact is that most Telegram users have no idea that their conversations aren’t encrypted, most people incorrectly assume that it’s more secure t…

> This is complete nonsense. Whatsapp uses the Signal Protocol. Their claims of end-to-end encryption are true (and easily verifiable! just pull out the debugger of your choice) I don't dispute this but apparently there's still a way for Facebook to give FBI et. al. un-encrypted chats, no? So is that truly encrypted? > I think your (perfectly understandable) misinterpretation was corrected in a rather polite manner,…

[deleted]

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#155

> PitM attack I see we've arrived at the point where we're re-naming commonly established acronyms in order to remain politically correct.

Eh, you don't get to control the language of others. If someone wants to say PitM, that's their business.

You can also call it SITC (someone in the centre) attack if you will, but the point still stands - it impedes communication.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#156

Earlier quoted context omitted.

> This is complete nonsense. Whatsapp uses the Signal Protocol. Their claims of end-to-end encryption are true (and easily verifiable! just pull out the debugger of your choice) I don't dispute this but apparently there's still a way for Facebook to give FBI et. al. un-encrypted chats, no? So is that truly encrypted? > I think your (perfectly understandable) misinterpretation was corrected in a rather polite manner,…

>but apparently there's still a way for Facebook to give FBI et. al. un-encrypted chats, no? I’d love to see a source for this.

Me too, but after Snowden I doubt we'd be able to even if it were true.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#157
post #95

Earlier quoted context omitted.

Sending plaintext in a secure transport is not what they do either. They do have e2e encrypted secret chat on day one, and the ends are bound to the devices, so even if you login from your desktop app, you won't see the secret chats on your phone, unlike Signal. Seriously, please educate yourself first.

> They do have e2e encrypted secret chat on day one I was specifically replying to your complaint that non-E2E encrypted chats should not be called unencrypted because they had encryption in transit to the server. You're now shifting the conversation back to the E2E encryption they do have.

Non-E2E encrypted chats should not be called unencrypted because they had encryption in transit to the server.

The contradiction is right there in the sentence.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#158

Earlier quoted context omitted.

Interesting. I just created a 900MB backup of a chat history, on my iOS WhatsApp, that appears to have all messages and all data.

Being an iOS device it probably doesn’t ‘backup’ to Google Drive so this story may not apply

yeah, on ios whatsapp backs up the data to icloud

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#159

Earlier quoted context omitted.

>but apparently there's still a way for Facebook to give FBI et. al. un-encrypted chats, no? I’d love to see a source for this.

Me too, but after Snowden I doubt we'd be able to even if it were true.

I don’t get it, this claim should be fairly easy to prove by reverse engineering the app.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#160

Earlier quoted context omitted.

> They do have e2e encrypted secret chat on day one I was specifically replying to your complaint that non-E2E encrypted chats should not be called unencrypted because they had encryption in transit to the server. You're now shifting the conversation back to the E2E encryption they do have.

Non-E2E encrypted chats should not be called unencrypted because they had encryption in transit to the server. The contradiction is right there in the sentence.

This is stupid pedantry.
Post reply on HN