Live data from Hacker News

Attack of the Week: Group Messaging in WhatsApp and Signal

blog.cryptographyengineering.com

31–36 of 36 posts

Re: Attack of the Week: Group Messaging in WhatsApp and Signal

#32
post #19

I wrote a brain dump about my thoughts on that here: https://www.cryptologie.net/article/437/on-real-world-crypto... tl;dr is "I'd say the problem is in the reaction, not in the published analysis."

The problem once again are the journalists making up stuff for clicks. Remove the journalists from the equation and you will see there's no problem.

The article is by a cryptographer at Johns Hopkins, not a journalist.

Re: Attack of the Week: Group Messaging in WhatsApp and Signal

#34
Seems like this could be fixed fairly easily with a set of gatekeeper options. When a group gets created, you could have the option of making the group Public (anyone can join), Invite-Only (anyone can join with an invitation from someone already in the group), or Vetted (requires an invitation to join and the person who made the group must approve each person who tries to join).

That way, you account for varying levels of paranoia.

Re: Attack of the Week: Group Messaging in WhatsApp and Signal

#35
post #6

"This means the privacy of your end-to-end encrypted group chat is only guaranteed if you actually trust the WhatsApp server." "This undermines the entire purpose of end-to-end encryption." "And yet, the entire point of end-to-end encryption is to remove the server from the trusted computing base." "The challenge here is that since WhatsApp itself determines who the administrators are, this isn't quite so simple." No…

Hyperbolic much? This is a weakness that not only requires WhatsApp to be malicious but to not care about the trivial visibility of an exploit (the client would still display the extra person being added to the group chat).

Malicious can happen through server compromise, too.
Post reply on HN