Live data from Hacker News

WhatsApp encryption is useless

wccftech.com

21–23 of 23 posts

Re: WhatsApp encryption is useless

#21

Earlier quoted context omitted.

> Is there really only "perfect" or "useless" with nothing in-between? Are you suggesting that the ability to completely circumvent a system doesn't make that system broken? If the goal of WhatsApp encryption is to protect against surveillance, and there's a way to surveil users using WhatsApp, then it's broken, full stop. Are you going to place your trust in a home security system that works pretty well, but only ag…

Yes, to all your questions except the last one. That's the whole point. If I intend to overthrow president Trump, I won't use WhatsApp. Most other purposes, seems pretty fine now.

> Yes, to all your questions except the last one.

I'm sorry, but I don't understand. You are okay with a provably vulnerable system protecting some of life's most important assets.

Could you elaborate?

> That's the whole point. If I intend to overthrow president Trump, I won't use WhatsApp.

You made a blanket statement about the integrity of purportedly secure systems. These exact arguments can apply just as well to other systems, like Tor, or SSH, or HTTP over TLS.

Re: WhatsApp encryption is useless

#22

Earlier quoted context omitted.

> Are you suggesting that the ability to completely circumvent a system doesn't make that system broken? A system can be broken without being useless. >If the goal of WhatsApp encryption is to protect against surveillance You skipped an import word from the post you replied to: "mass". Even with a hole in SS7, it makes it impractical to collect messages from everyone, even if it's practical to collect messages from s…

> A system can be broken without being useless. Sure, just as a completely insecure system can be useful. I'm not arguing that. But not useful for the purpose of protecting users against surveillance. > You skipped an import word from the post you replied to: "mass". skrebbel made a blanket statement, which I was replying to.

>But not useful for the purpose of protecting users against surveillance.

I'd argue that it can be useful for that purpose without being perfect. If it stops my communication from being caught in a mass dragnet, then it's useful for protecting me against surveillance even when it's possible to circumvent the security on the scale of individuals (rather than populations).

> skrebbel made a blanket statement, which I was replying to.

Right, they did. They made the statement that even flawed security makes mass surveillance much more difficult than an unencrypted system would (or words to that effect). It seems like "stop mass-scale surveillance" is a separate goal from "stop individual-scale surveillance". I feel like you set up a strawman, rather than actually addressing what skrebbel originally said.

Re: WhatsApp encryption is useless

#23

Earlier quoted context omitted.

> A system can be broken without being useless. Sure, just as a completely insecure system can be useful. I'm not arguing that. But not useful for the purpose of protecting users against surveillance. > You skipped an import word from the post you replied to: "mass". skrebbel made a blanket statement, which I was replying to.

>But not useful for the purpose of protecting users against surveillance. I'd argue that it can be useful for that purpose without being perfect. If it stops my communication from being caught in a mass dragnet, then it's useful for protecting me against surveillance even when it's possible to circumvent the security on the scale of individuals (rather than populations). > skrebbel made a blanket statement, which I w…

> It seems like "stop mass-scale surveillance" is a separate goal from "stop individual-scale surveillance". I feel like you set up a strawman, rather than actually addressing what skrebbel originally said.

My point was that security is often black-and-white because a crack can turn out to be a crater, and often is.

With regards to state-sponsored, dragnet surveillance: those are the most skilled attackers, and they've exploited far more subtle issues than the one being discussed here; they're the ones that you need to be worried about for undisclosed vulnerabilities, letalone terribly obvious flaws like this one.

Post reply on HN