Live data from Hacker News

WhatsApp backdoor allows snooping on encrypted messages

theguardian.com

171–180 of 334 posts

Re: WhatsApp backdoor allows snooping on encrypted messages

#171

Is anyone surprised? Facebook owns them, and Facebook has been in the back pocket of the intelligence agencies for at least half a decade.

Are there some landmark issues around this assertion? We know Yahoo backdoored email, and their head of security resigned as it happened behind his back. This doesn't mean agencies are successful at coercing every company by default.

Re: WhatsApp backdoor allows snooping on encrypted messages

#172
post #111

Earlier quoted context omitted.

There are certainly people who want to use Signal without Google services. I don't know how legitimate a complaint it is since Moxie et al have said that they would accept a well written pull request which provides similar functionality. But this just hasn't been forthcoming. What I dislike about Signal mentions on HN is that aggressive posters conflate a number of different issues people have with Signal - lack of f…

I don't have a lot of skin in the game, but I am genuinely curious as to what you mean. How else other than "lump[ing] them in together", would you comprehensively criticize it? I mean, two things good about Signal is that it let's you chat with friends and family in a secure manner. There are these following issues though: I doesn't federate, it relies on Google Push, it doesn't support SMS. Also, I don't like how S…

You're correct. That would be a fine way to make a comprehensive criticism.

I was trying to express frustration with posters who start out with a nebulous complaint like "Signal is bad and OWS is evil". If called on this they come back with "It allows Google to spy on you", if countered they come back with "it doesn't allow freedom to federate" and so on.

Rather than being a multi pronged criticism it's more like a bait and switch, with each new argument being deployed when the previous one is rendered invalid.

Re: WhatsApp backdoor allows snooping on encrypted messages

#173
post #81
post #66

Earlier quoted context omitted.

Even if you don't install Gapps, large parts of Android/CyanogenMod are from Google as well. How does installing Gapps make the security worse?

Good question. Stock Android does not, by inspecting network traffic, contact Google servers. Google play services and other GApps, do, and they can be exploited in this traffic, or told by Google to activate other backdoors. Signal with GApps, Google can know which phones, and which users, are using Signal, thats a security vulnerability. Google can infer from their Google-messaging thing, that notifications are sen…

>Stock Android does not, by inspecting network traffic, contact Google servers.

It does to check for internet access upon connecting to wifi.

https://github.com/copperhead/bugtracker/issues/194

Re: WhatsApp backdoor allows snooping on encrypted messages

#174
> in many parts of the world, people frequently change devices and Sim cards. In these situations, we want to make sure people’s messages are delivered, not lost in transit.

That quote sounds even more alarming to me than the description of the backdoor. Because, as I read it: the unencrypted message is not stored on the device, but somewhere else. How else would they be able to still deliver a message, using a new encryption key, even after the sender switched to a new phone?

Re: WhatsApp backdoor allows snooping on encrypted messages

#175
post #47

Well, I kind of feel that I have to repost my comment on this old thread[1] with regards to the government of Egypt blocking Signal application: "Isn't it "weird" that they chose to block Signal app and not the signal-protocol based Whatsapp? If Whatsapp really implements the same kind of security and privacy measures that Signal does, why is Whatsapp allowed to continue operating? If signal is preventing them spy on…

Simple explanation would be that activists use Signal. [1] They don't trust WhatsApp and rely on Signal for secure messaging. Blocking Signal means they are able to target activists without impacting much of the rest of the population. [1] Many of the people I know who are activists in countries where they need to protect their identities use Signal

> Simple explanation would be that activists use Signal.

But why do activists simply not use WhatsApp, instead of Signal? If both were suppose to be fully encrypted and secure, why not use the tool that is available. I assume the needing encryption is to prevent the government snooping and eavesdropping on your plans rather than "liking the UI/UX of one system over the other"?

Maybe the activists know something we did not, and are right to be paranoid...

Re: WhatsApp backdoor allows snooping on encrypted messages

#176

Earlier quoted context omitted.

I'd go further and say Moxie is complicit by way of negligence. It's unethical to assist in the implementation of your protocol when you can't guarantee its privacy protections will actually stand. Otherwise it's free PR for Facebook to tout "Snowden-approved crypto". I have no doubt Moxie acted in good faith and wanted to expand encryption to a large number of users, but this is just another example of why proprieta…

On a completely unconnected note, what was the name of that technique that GCHQ uses to disrupt online forums and subtly undermine peoples reputations?

https://theintercept.com/2014/02/24/jtrig-manipulation/

Re: WhatsApp backdoor allows snooping on encrypted messages

#177
post #20

It doesn't matter whether you use WhatsApp, Facebook Messenger "Secret Conversations" or even Signal app (or PGP or any public key based communications system)!. If you are not verifying key fingerprints out of band, then you are potentially vulnerable to a malicious server MITMing new sessions. If you want secure end-to-end messaging, verify keys out of band, do not solely trust a 3rd party for key exchange!

And you have to verify the software is using those verified keys for every message you send.

Re: WhatsApp backdoor allows snooping on encrypted messages

#178
post #130

I remember receiving the downvote brigade[1], when Moxie himself said that I should trust WhatsApp without having the source code and the ability to put it on my device. We (even a "smart" community like HN) clearly do not have the ability to think critically about security, and even when our leaders are sincere -- and I really don't mean to suggest Moxie/Signal was complicit in this move -- we still rush to defend o…

I'd go further and say Moxie is complicit by way of negligence. It's unethical to assist in the implementation of your protocol when you can't guarantee its privacy protections will actually stand. Otherwise it's free PR for Facebook to tout "Snowden-approved crypto". I have no doubt Moxie acted in good faith and wanted to expand encryption to a large number of users, but this is just another example of why proprieta…

> Moxie is complicit by way of negligence.

I just want to voice my opinion that maybe 1 in 100 people have Moxie's integrity and ethics.

Re: WhatsApp backdoor allows snooping on encrypted messages

#179

The key part is this, and it was apparently reported back in April 2016 with Facebook replying it's "expected behavior", it's not something a general attacker can do but it would enable WhatsApp/Facebook to read conversations: > WhatsApp has the ability to force the generation of new encryption keys for offline users, unbeknown to the sender and recipient of the messages, and to make the sender re-encrypt messages wi…

I don't think this is as serious as it seems, this exploit only applies to undelivered messages, which granted is not great, but is at least something. And any WhatsApp update could potentially include code to snoop on decrypted messages so exploits that can only be performed from the WhatsApp server side - i.e the example in the article about snooping entire conversations - are not really that relevant. Having said…

It's possible for any message that is not marked as delivered.

All Facebook has to do is not mark messages as delivered, i.e. lieing to the device, which can probably be done easily. So they could ask a device to regenerate keys and send the same message again, over and over again.

Re: WhatsApp backdoor allows snooping on encrypted messages

#180

Earlier quoted context omitted.

Good point, but there is an explanation: blocking WhatsApp would lead to more intense backlash. See what happened in Brazil. Not to say it isn't both, but the price of blocking (one of) the most popular messaging apps is higher to a government than blocking one in the low low percentiles of usage.

What you say makes blocking Signal pointless. If they blocked Signal just because it was less of a trouble to block compared to WhatsApp, then all the people that were on Signal will easily switch to WhatsApp... What you have at this point, is a government paying the price of blocking a less popular messaging app they cannot control, while the people they are after can just switch to a MASSIVELY used messaging app th…

I wouldn't overestimate government authorities either. A report on a person of interest crosses the desk of a deputy minister that says the person uses Signal could be enough to get the application blocked in the country.

Elected officials and political appointees demand action on things that are counter to their interests all the time, the people that execute those orders (if they appreciate that the order is counter-productive in the first place) have to decide what measures are worth fighting and which ones are not.

Post reply on HN