Live data from Hacker News

WhatsApp backdoor allows snooping on encrypted messages

theguardian.com

281–290 of 334 posts

Re: WhatsApp backdoor allows snooping on encrypted messages

#281
post #70

Earlier quoted context omitted.

I thought that was the whole point of end-to-end. That you don't need trust in the server because the messages are opaque. If this is an exploit that can be performed by a compromised server, it's very much relevant

So, just to clarify my understanding: Basically, what we have here is a weakness in the client , namely a provision that allows the server to send the client a fresh key and ask for re-encryption and re-sending with the new key. This, in turn, would allow for a good old MITM attack if the server were to be compromised. This re-encryption and re-sending of messages would be without intervention by the user, though a m…

Is the server sending the client a new key to use? Or is the server telling the client to generate a new key?

Re: WhatsApp backdoor allows snooping on encrypted messages

#282
post #178

Earlier quoted context omitted.

I'd go further and say Moxie is complicit by way of negligence. It's unethical to assist in the implementation of your protocol when you can't guarantee its privacy protections will actually stand. Otherwise it's free PR for Facebook to tout "Snowden-approved crypto". I have no doubt Moxie acted in good faith and wanted to expand encryption to a large number of users, but this is just another example of why proprieta…

> Moxie is complicit by way of negligence. I just want to voice my opinion that maybe 1 in 100 people have Moxie's integrity and ethics.

An error in judgment (naiveté) and integrity are not mutually exclusive.

Re: WhatsApp backdoor allows snooping on encrypted messages

#283

Earlier quoted context omitted.

Simple explanation would be that activists use Signal. [1] They don't trust WhatsApp and rely on Signal for secure messaging. Blocking Signal means they are able to target activists without impacting much of the rest of the population. [1] Many of the people I know who are activists in countries where they need to protect their identities use Signal

There is no logical way to verify that all activists (or even a majority of them) use Signal over WhatsApp. The perception that activists use Signal may have been enough to block them, but having a huge backdoor in WhatsApp is reason enough to not take action.

That's assuming it was a macro decision, and not a micro decision. The govt could have had specific intel on a particular activist, or cell that they knew were using Signal, and shut it down to deal with that situation at that time.

Re: WhatsApp backdoor allows snooping on encrypted messages

#284
post #248

Earlier quoted context omitted.

I don't know what the bystander effect is, but I assume we're taking about the same thing: I often feel that everyone is, along with myself, thinking "great - open source! I'm sure someone's checking it." Of course, the counter is that if you publish it you don't risk that someone actually is checking. Open beats closed, but we must be careful not to think it immediately makes the code sound. I've been thinking about…

but we must be careful not to think it immediately makes the code sound nobody is saying it's automatically sound, but open is the only option that makes any security analysis possible.

> open is the only option that makes any security analysis possible

I'm not disputing that. Let me repeat myself:

> Open beats closed

All I'm saying is that it doesn't stop there. Too often there's this complacent 'great, it's open source!' - I'm as guilty of it as anyone.

Re: WhatsApp backdoor allows snooping on encrypted messages

#285
post #284

Earlier quoted context omitted.

but we must be careful not to think it immediately makes the code sound nobody is saying it's automatically sound, but open is the only option that makes any security analysis possible.

> open is the only option that makes any security analysis possible I'm not disputing that. Let me repeat myself: > Open beats closed All I'm saying is that it doesn't stop there. Too often there's this complacent 'great, it's open source!' - I'm as guilty of it as anyone.

You're begging the question.

Re: WhatsApp backdoor allows snooping on encrypted messages

#286
post #242

Earlier quoted context omitted.

There's a there right?

What? You must be some sort of conspiracy theorist. Just be rational and extrapolate from your beliefs: if you admit that Facebook might do this, then why not Google, AT&T, Microsoft? There would be no end to it. Basically it would mean that all businesses are spying on you and handing the information over to the government. I have complete faith that that is untrue based upon just the history of the last 5 years.

Serious question: why do people believe that corporations can somehow beat government/law? The government has absolute power and will always win.

Re: WhatsApp backdoor allows snooping on encrypted messages

#287
post #130

I remember receiving the downvote brigade[1], when Moxie himself said that I should trust WhatsApp without having the source code and the ability to put it on my device. We (even a "smart" community like HN) clearly do not have the ability to think critically about security, and even when our leaders are sincere -- and I really don't mean to suggest Moxie/Signal was complicit in this move -- we still rush to defend o…

The vulnerability was found, published and reported without source and before your previous comment.

Re: WhatsApp backdoor allows snooping on encrypted messages

#288
post #284

Earlier quoted context omitted.

> open is the only option that makes any security analysis possible I'm not disputing that. Let me repeat myself: > Open beats closed All I'm saying is that it doesn't stop there. Too often there's this complacent 'great, it's open source!' - I'm as guilty of it as anyone.

You're begging the question.

Pardon?

Re: WhatsApp backdoor allows snooping on encrypted messages

#289
post #155

Earlier quoted context omitted.

> You're implying that WhatsApp, Inc. gave the Egyptian government the ability to remotely retrigger this backdoor whenever they want to (for those who haven't actually read the article: this backdoor only works when WhatsApp issues a key change for a conversation, and only then in certain circumstances). In other words, you imply that Egypt said "Hey WhatsApp, please actively hack into your Egyptian users' messages…

Yeah, but that's not how the exploit would work. If you read the article, the "backdoor" is that WhatsApp could "generate" a new private key without your knowledge. Except that instead of generating a key, they'd use a well-known key. From there, they could give that key to state actors, or they could decrypt the traffic themselves and give it to state actors. Either way, you need server side control of WhatsApp.

Which you could get by hacking WhatsApp endpoints.

Re: WhatsApp backdoor allows snooping on encrypted messages

#290
post #98
post #8

Earlier quoted context omitted.

Signal is bad as explained previously, it requires Google on your phone to even work. If you think Google is more trustworthy than Facebook, sure go ahead and just use Hangouts or whatever. We cant have nice good encryption and safe communication when geeks push this Signal onto unsuspecting users, when the real option is to keep improving Tox.Chat and bitmessage.

I guess it's worth mentioning that people are currently working on removing the Google services dependency in Signal: https://github.com/WhisperSystems/Signal-Android/pull/5962

Looks like they are waiting for the calling portion of the app to become open source. Any ETA on that?
Post reply on HN