There is no WhatsApp 'backdoor'
31–40 of 437 posts
Re: There is no WhatsApp 'backdoor'
#32Re: There is no WhatsApp 'backdoor'
#33I don't user whatsapp, but a general question to these that do: Can the server change keys twice? Change once to server keys, ask for the entire history retransmission. Change again to revert to original receipient keys. Will the receipient be prompted in that case?
Re: There is no WhatsApp 'backdoor'
#34This main flagrant or off-topic, but something that nags at me when thinking about truly secure messaging apps from the App Store: Even with perfect e2e encryption protocol added, what's preventing WhatsApp developers (FB) from adding in a feature of the app: if local.user is "TargetUser007" { takeDeviceSnap(); sendDeviceSnapshotToFBOverSameEncryption(); } Wouldn't this not be ever verifiable unless you ARE that spec…
You'd also have to make sure they were the only user that received that binary. Otherwise you'd have to hope that no one reverse engineered the binary and noticed the oddly specific comparison there.
Re: There is no WhatsApp 'backdoor'
#35This main flagrant or off-topic, but something that nags at me when thinking about truly secure messaging apps from the App Store: Even with perfect e2e encryption protocol added, what's preventing WhatsApp developers (FB) from adding in a feature of the app: if local.user is "TargetUser007" { takeDeviceSnap(); sendDeviceSnapshotToFBOverSameEncryption(); } Wouldn't this not be ever verifiable unless you ARE that spec…
I'm sure some security researcher somewhere has run the app through a debugger/disassembler to verify exactly this.
Re: There is no WhatsApp 'backdoor'
#36This main flagrant or off-topic, but something that nags at me when thinking about truly secure messaging apps from the App Store: Even with perfect e2e encryption protocol added, what's preventing WhatsApp developers (FB) from adding in a feature of the app: if local.user is "TargetUser007" { takeDeviceSnap(); sendDeviceSnapshotToFBOverSameEncryption(); } Wouldn't this not be ever verifiable unless you ARE that spec…
You'd also have to make sure they were the only user that received that binary. Otherwise you'd have to hope that no one reverse engineered the binary and noticed the oddly specific comparison there.
Re: There is no WhatsApp 'backdoor'
#37This main flagrant or off-topic, but something that nags at me when thinking about truly secure messaging apps from the App Store: Even with perfect e2e encryption protocol added, what's preventing WhatsApp developers (FB) from adding in a feature of the app: if local.user is "TargetUser007" { takeDeviceSnap(); sendDeviceSnapshotToFBOverSameEncryption(); } Wouldn't this not be ever verifiable unless you ARE that spec…
You'd also have to make sure they were the only user that received that binary. Otherwise you'd have to hope that no one reverse engineered the binary and noticed the oddly specific comparison there.
Re: There is no WhatsApp 'backdoor'
#38This main flagrant or off-topic, but something that nags at me when thinking about truly secure messaging apps from the App Store: Even with perfect e2e encryption protocol added, what's preventing WhatsApp developers (FB) from adding in a feature of the app: if local.user is "TargetUser007" { takeDeviceSnap(); sendDeviceSnapshotToFBOverSameEncryption(); } Wouldn't this not be ever verifiable unless you ARE that spec…
You'd also have to make sure they were the only user that received that binary. Otherwise you'd have to hope that no one reverse engineered the binary and noticed the oddly specific comparison there.
Re: There is no WhatsApp 'backdoor'
#39What is the user supposed to do when they get notified of a "safety number changed" message? How do they verify they've not just been MITM? Honest question... I don't use whatsapp or signal at all.
Re: There is no WhatsApp 'backdoor'
#40Color me still-unconvinced. This retort does not address the fundamental point made in the Guardian piece: > “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which u…
I happen to trust Moxie's principles, but not as much as I distrust the relationship-with-government imperatives implied by FB's vast business interests.