Live data from Hacker News

WhatsApp backdoor allows snooping on encrypted messages

theguardian.com

271–280 of 334 posts

Re: WhatsApp backdoor allows snooping on encrypted messages

#271

Earlier quoted context omitted.

The GFW is able to recognise Tor usage. > The firewall searches for a bunch of bytes which identify a network connection as Tor. If these bytes are found the firewall initiates a scan of the host which is believed to be a bridge. In particular the scan is run by seemingly arbitrary Chinese computers which connect to the bridge and try to “speak Tor” to it. If this succeeds, the bridge is blocked. http://www.cs.kau.se…

With all the things GFW does I wonder if they have some secret conferences or industry journals related to the firewall's algorithms and infrastructure.

Don't see why not? In Jason scotts talk The Mysterious Mr Hokum [0] he talks about an owner of an early ISP who not long after selling it was found dead. Iirc During his time as owner he would often have regular meetings with FBI agents to basically discuss what was going on the net.

Problem was after he died his Was actually on the run on fruad charges. I think Jason presumes he set up the ISP as another scam but he started it at the perfect time and started actually making legit money instead. So (again trying to recall the talk from memory, I must actually watch it again as I enjoyed it) this isp owner was having meetings with the FBI about his ISP all the while the FBI also wanted him on fraud charges. So yeah if the FBI don't mind having chats with ISP's just to see what's going on, I wouldn't be at all surprised if China had meetings with their ISP's too. From what I have read I about the GFW it seems that it's infrastructure differs from isp to isp. Dunno if that's cause it's left to the ISP to implement or if The Gov issue "black boxes" to do the firewall work and it's just different versions of hardware / software depending on when the boxes were issued.

But yeah I do like the idea of a secret defcon but kinda in reverse that discuses the tricks and infrastructure and the bypasses they discovered in the past year but in order to better run the GFW. In my imaginary con they are all still getting drunk and hacking into the hotel signage for the shits and giggles of it though.

[0] https://youtu.be/UTzQmhmgLC0

Re: WhatsApp backdoor allows snooping on encrypted messages

#272
post #175

Earlier quoted context omitted.

Simple explanation would be that activists use Signal. [1] They don't trust WhatsApp and rely on Signal for secure messaging. Blocking Signal means they are able to target activists without impacting much of the rest of the population. [1] Many of the people I know who are activists in countries where they need to protect their identities use Signal

> Simple explanation would be that activists use Signal. But why do activists simply not use WhatsApp, instead of Signal? If both were suppose to be fully encrypted and secure, why not use the tool that is available. I assume the needing encryption is to prevent the government snooping and eavesdropping on your plans rather than "liking the UI/UX of one system over the other"? Maybe the activists know something we di…

Facebook owns WhatsApp and has been increasingly hospitable to government intrusion on users' privacy. That seems like a good enough reason given that Facebook violated its pledge not to combine user data.

Re: WhatsApp backdoor allows snooping on encrypted messages

#273

Earlier quoted context omitted.

Simple explanation would be that activists use Signal. [1] They don't trust WhatsApp and rely on Signal for secure messaging. Blocking Signal means they are able to target activists without impacting much of the rest of the population. [1] Many of the people I know who are activists in countries where they need to protect their identities use Signal

I wouldn't trust whatsapp even before this revelation. I would never trust a closed source messaging app if I was an activist, regardless of what encryption they claim to implement.

I wouldn't trust anything owned by Facebook. Period.

Re: WhatsApp backdoor allows snooping on encrypted messages

#274
post #259

Earlier quoted context omitted.

Yes, well done.

I feel bad now. I'm just highly frustrated that everyone is not actuated by the idea "if they _can_ spy on you, then they _will_". Any appeal to morals/integrity/laws are essentially moot in this area. We have the ability to protect ourselves and we should be using it. https://www.eff.org/deeplinks/2017/01/obama-expands-surveill...

> We have the ability to protect ourselves and we should be using it.

I don't doubt that the technology exists, I just doubt the ability of the average person to be able to protect themselves. As someone who works in a technical field with decent computer literacy, I still have a hard time approaching this problem. Perhaps I'm just not as literate as I think I am.

Re: WhatsApp backdoor allows snooping on encrypted messages

#275
post #268

Earlier quoted context omitted.

Simple explanation would be that activists use Signal. [1] They don't trust WhatsApp and rely on Signal for secure messaging. Blocking Signal means they are able to target activists without impacting much of the rest of the population. [1] Many of the people I know who are activists in countries where they need to protect their identities use Signal

WhatsApp is used by over a billion people. I'm sure some activists in Egypt use WhatsApp, too. That said, I think WhatsApp was blocked in Egypt, too, at least for a while. I don't know if they later "fixed" that or not, and how they did it.

A lot of Americans don't understand why messengers like WhatsApp are so popular around the world. The reason is that most carriers still extort users by charging text message fees.

In the US, everyone texts (or think they are using texts when running iMessage) because most plans give unlimited voice and texts, and charge by the GB of data.

Re: WhatsApp backdoor allows snooping on encrypted messages

#276

Earlier quoted context omitted.

I'd go further and say Moxie is complicit by way of negligence. It's unethical to assist in the implementation of your protocol when you can't guarantee its privacy protections will actually stand. Otherwise it's free PR for Facebook to tout "Snowden-approved crypto". I have no doubt Moxie acted in good faith and wanted to expand encryption to a large number of users, but this is just another example of why proprieta…

On a completely unconnected note, what was the name of that technique that GCHQ uses to disrupt online forums and subtly undermine peoples reputations?

> On a completely unconnected note

You are not being sincere. You are implying that GP is a paid troll of spooks.

Re: WhatsApp backdoor allows snooping on encrypted messages

#277

Earlier quoted context omitted.

No, all messages cannot be recovered by Facebook. Read the article - messages that are not yet delivered can potentially be read; if it has been delivered it cannot be retrieved.

You go read the article. The deciding factor is not whether the message has been delivered, but whether WhatsApp servers report to the device that the message has been delivered. There's nothing stopping them from claiming that no messages have been delivered and thus recovering all messages (as long as they had been preselected for false delivery reports) despite true delivery status.

So they can recover the messages, right? However, wouldn't these messages still be encrypted? Sure, they force a key change, and the messages are encrypted using the new key and sent. Theoretically, an attacker could have multiple copies of the same message, but these messages would still be encrypted under a variety of different keys right? Wouldn't the content of the messages still be secure?

Unless the key-change forces the user to be using an insecure key-pair, but is that actually happening?

Re: WhatsApp backdoor allows snooping on encrypted messages

#278
post #47

Well, I kind of feel that I have to repost my comment on this old thread[1] with regards to the government of Egypt blocking Signal application: "Isn't it "weird" that they chose to block Signal app and not the signal-protocol based Whatsapp? If Whatsapp really implements the same kind of security and privacy measures that Signal does, why is Whatsapp allowed to continue operating? If signal is preventing them spy on…

To add to those who have referenced the cost to the government: consider who else uses WhatsApp besides just activists - it's likely many government employees use WhatsApp as well.

Anecdotal tidbit: I worked at the Rio 2016 Olympics. My team consisted of Brazilians, Americans, Britons, and Koreans. WhatsApp was how we communicated[1], I'm sure the same was true for most of the other thousands of people working setup for the Olympics.

When a power-hungry judge forced WhatsApp to be blocked a couple weeks before the opening ceremonies, it was rather problematic for the Olympics staff. My first thought was "uhhh. This isn't going to last for long," and it didn't.

I can't say for sure that it's because the IOC president called up the Brazilian president, and the Brazilian president yelled at the judge, but I like to think that's what happened.

[1] Integrated language translation would be a FANTASTIC feature to add.

Re: WhatsApp backdoor allows snooping on encrypted messages

#279
post #179

Earlier quoted context omitted.

I don't think this is as serious as it seems, this exploit only applies to undelivered messages, which granted is not great, but is at least something. And any WhatsApp update could potentially include code to snoop on decrypted messages so exploits that can only be performed from the WhatsApp server side - i.e the example in the article about snooping entire conversations - are not really that relevant. Having said…

It's possible for any message that is not marked as delivered. All Facebook has to do is not mark messages as delivered, i.e. lieing to the device, which can probably be done easily. So they could ask a device to regenerate keys and send the same message again, over and over again.

This would just result in the same encrypted message being sent over and over, albeit encrypted with different keys each time, right? The only way the content of the message would be vulnerable is if one of the new keys are insecure/compromised, unless there's something I'm missing.

Re: WhatsApp backdoor allows snooping on encrypted messages

#280
post #248

Earlier quoted context omitted.

While I'm totally the same in this regard, this does feel a bit like an open-source version of the bystander effect.

I don't know what the bystander effect is, but I assume we're taking about the same thing: I often feel that everyone is, along with myself, thinking "great - open source! I'm sure someone's checking it." Of course, the counter is that if you publish it you don't risk that someone actually is checking. Open beats closed, but we must be careful not to think it immediately makes the code sound. I've been thinking about…

but we must be careful not to think it immediately makes the code sound

nobody is saying it's automatically sound, but open is the only option that makes any security analysis possible.

Post reply on HN