Live data from Hacker News

WhatsApp backdoor allows snooping on encrypted messages

theguardian.com

221–230 of 334 posts

Re: WhatsApp backdoor allows snooping on encrypted messages

#221
This is not a backdoor. It is a vuln, and it'd be nice if it wasn't there, but this is not a backdoor.

There is no reason to assume this was "snuck in" with an intent to deceive users. Retransmission has been known and discussed repeatedly, months ago, and Facebook acknowledged it. What happened here is a choice of UX over security, specifically, choosing not to break existing WA users as they move them over to the otherwise great Signal protocol.

When a key changes, you can just keep trying, notify the user, or drop everything on the floor. If you want the latter, use Signal.

It would be nice if WhatsApp made 2 the default, and 3 optional. Right now 1 is the default and 2 is the option. The trick is to get the UX somewhere where normal people can do something useful with that information.

If you are at all upset about this, you are not a target WhatsApp user. It'd be nice if they changed this, but for the love of all that is good and holy, stop calling it a backdoor, because it isn't. Words mean things.

Re: WhatsApp backdoor allows snooping on encrypted messages

#222
post #190

Earlier quoted context omitted.

Good point, but there is an explanation: blocking WhatsApp would lead to more intense backlash. See what happened in Brazil. Not to say it isn't both, but the price of blocking (one of) the most popular messaging apps is higher to a government than blocking one in the low low percentiles of usage.

Can you make an unblockable app?

No, but blocking it could piss off a large part of your population.

It all depends on how far you are willing to push the blocking and how much you are willing to disable so you can block anything.

Signal atm are using domain fronting. (iirc the app will soon test the network conditions before attempting to use domain fronting, but for now it checks the country code of your phone number)

It will open a HTTPS connection to google.com but after the connection is made sends a host request for something.appspot.com In order to block that you need to MITM the connection or block google.com (Not sure if DPI could be used to get the host header never really looked into it personally. I know that SNI Sends the host is part of the handshake so the webserver knows which cert to present you with. Could it be extracted, checked agasinst a list and then have the connection reset preventing connection? Dunno never played with it, but its an idea off the top of my head).

(Now for some mild rambling :-p)

Lets say you can't MITM/DPI s you can just block google then they would have to use another CDN, so you block that one too. How many you going to go though before your citizens get pissed off at you and do something?

But lets say you people really hated GMail anyway and put up with not having Google just so this message app was blocked (and the creators don't just change CDN's) then you just force your people to install your own Root Cert or they don't get any encrypted web traffic. Will people complain or just install the Cert and get their facebook back?

So people switch to using personal networks (bluetooth and WiFi hotspots when in a crowd of people) just jam Cell/2.4ghz/5ghz. Will people complain they can't use their phones?

And it just escalates to the point you need a Doctors note and a permission slip signed by your mum before you are allowed to make a phone call.

All the time who actually want to encrypt their messages use math they can do at a desk away from a computer or phone and just use whatever method the Goverment do allow / they can get away with (Standard SMS but who and when can be got from the telco's, dead drops, IRL meetings) but sacrifice their metadata in the process.

Re: WhatsApp backdoor allows snooping on encrypted messages

#223
post #12

No matter what IM service you use: As long as they manage the public keys for their users, they will be vulnerable to exactly this problem. This isn't just WhatsApp. This applies to iMessage and Signal too. In all cases, we rely on the word of the service provider that they don't sneak additional public keys to encrypt for into the clients and in all cases we hear that doing so would cause a message dialog to appear,…

I'd be curious to hear HN's thoughts on what messaging apps they use/trust. I've tried in the past to get friends to switch over to Telegram, but there are issues since they rolled their own encyption protocol. I've looked into using Mumble for voice, it seems quite secure because you host it yourself, and it's open source. There's also a good list from the EFF: https://www.eff.org/node/82654

[deleted]

Re: WhatsApp backdoor allows snooping on encrypted messages

#224
post #217
post #150

I'm not a crypto guy, but I'm trying to understand how this backdoor could be used by governments or WhatsApp/Facebook itself. I'm not entirely sure how such an attack based on this backdoor would work. The article says that WhatsApp servers have the ability to trigger the clients to generate new keys, but even with new keys how can the server read the messages at all? Has the server got a copy of the new generated k…

I'm trying to understand this same thing. I don't see why triggering a client to generate new keys is a problem. Giving the client keys to use is a problem, but that's not what it's saying. Edit: it is described much better here: https://tobi.rocks/2016/04/whats-app-retransmission-vulnerab... The idea is that in addition to the keys being regenerated, the recipient phone is spoofed (a key point not mentioned). So the…

Thank you, now I understand.

Re: WhatsApp backdoor allows snooping on encrypted messages

#226

Earlier quoted context omitted.

All messages, sent while a person is offline. It is bad, but not nearly as bad as "all messages"

It is in fact all messages. They can simply not deliver the first message and force a resend record that mesaage. Afterwards force again a resend with the old encryption key and deliver that mesaage. No one would get a notification.

I can see how you would leave the receiver in the dark by sending them the original, deferred message, but how would asking the sender's device to resend with a different key not result in a notification?

Furthermore, as soon as the sender attempts to deliver another message to the recipient, they would get another notification (because the encryption key changed back to the real key); alternatively the attacker could continue blocking (and reading) messages to the recipient, but the lack of delivery would be noticeable.

You could escalate it into a MITM rather easily, though, by attacking both ends; but again, a key change notification should be displayed to both parties.

Assuming the closed sourced app works as advertised, obviously.

Re: WhatsApp backdoor allows snooping on encrypted messages

#227
Nothing to worry about according to Gizmodo:

  > The supposed “backdoor” the Guardian is describing is
  > actually a feature working as intended, and it would
  > require significant collaboration with Facebook to be 
  > able to snoop on and intercept someone’s encrypted
  > messages, something the company is extremely unlikely
  > to do.
http://gizmodo.com/theres-no-security-backdoor-in-whatsapp-d...

I, for one, certainly cannot imagine Facebook collaborating to such an extent with the government.

Re: WhatsApp backdoor allows snooping on encrypted messages

#228
post #47

Well, I kind of feel that I have to repost my comment on this old thread[1] with regards to the government of Egypt blocking Signal application: "Isn't it "weird" that they chose to block Signal app and not the signal-protocol based Whatsapp? If Whatsapp really implements the same kind of security and privacy measures that Signal does, why is Whatsapp allowed to continue operating? If signal is preventing them spy on…

Simple explanation would be that activists use Signal. [1] They don't trust WhatsApp and rely on Signal for secure messaging. Blocking Signal means they are able to target activists without impacting much of the rest of the population. [1] Many of the people I know who are activists in countries where they need to protect their identities use Signal

There is no logical way to verify that all activists (or even a majority of them) use Signal over WhatsApp. The perception that activists use Signal may have been enough to block them, but having a huge backdoor in WhatsApp is reason enough to not take action.

Re: WhatsApp backdoor allows snooping on encrypted messages

#229

Earlier quoted context omitted.

Simple explanation would be that activists use Signal. [1] They don't trust WhatsApp and rely on Signal for secure messaging. Blocking Signal means they are able to target activists without impacting much of the rest of the population. [1] Many of the people I know who are activists in countries where they need to protect their identities use Signal

I wouldn't trust whatsapp even before this revelation. I would never trust a closed source messaging app if I was an activist, regardless of what encryption they claim to implement.

Good point. At least as a technical person, I would like to use an open-source messaging application.

Of course I'm not going to read the source code but at least I'm sure developers behind the app do not open a backdoor for someone else.

Re: WhatsApp backdoor allows snooping on encrypted messages

#230
post #188
post #168

Earlier quoted context omitted.

If a user loses their phone, I think they have a lot more to worry about than a few missed WhatsApp messages anyway. I don't think this is a "common sense" compromise that WhatsApp made here, especially in the context of them promising end-to-end encryption. It's kind of like that other nonsense tech companies are doing these days, by supporting U2F auth, but then requiring you also set-up SMS auth in parallel, so th…

If I lose my phone, I expect my new phone to have proper continuity on the messages. I'd rather have that than any encryption, to be honest. I don't care if the government spies on me. I do care if something someone sent me gets lost.

You should at least have a backup of your private key so you can import it on your new phone rather than having the sender re-encrypt to whatever key your new phone decides to generate.
Post reply on HN