Live data from Hacker News

WhatsApp's Signal Protocol integration is now complete

whispersystems.org

331–340 of 386 posts

Re: WhatsApp's Signal Protocol integration is now complete

#331

Earlier quoted context omitted.

> What's the next step? Is there any work on encrypting group chat sessions?

Please read the articles. It already says that those are encrypted, as well as voice calls. Apparently once everyone is upgraded, nothing will be unencrypted. Their white paper also describes the protocols used in quite a lot of detail.

It doesn't seem to say anything about the Web client, though.

Re: WhatsApp's Signal Protocol integration is now complete

#332
post #82

Earlier quoted context omitted.

Doesn't everyone in the chat have to have the new version of the app before it's all e2e?

I guess? Hence the indicator. It would be nice to know if someone switched phones and e2ee turned off, for example.

Once your number had e2e support0, you can't switch to a phone without e2e. Notifications on key changes are switched off by default, but I hope they still warn you in the chat history. We'll see.

Re: WhatsApp's Signal Protocol integration is now complete

#333
post #301

What is the incentive for Facebook to add encryption here to WhatsApp? Don't they want to mine every piece of data about every person that they can? I can't imagine there is that much customer demand?

Facebook Messenger is the thing where everything is minded and you'll get all the AI bots etc.

WhatsApp instead is their chat app for users how don't like Facebook. WhatsApp has way more users than Facebook Messengers. And now they have the PR and even don't have to deal with wiretapping requests anymore.

Re: WhatsApp's Signal Protocol integration is now complete

#334
post #59

What the article fails to mention: 1) I would assume Facebook still gets unencrypted access to my address book for use with their shadow profiles 2) We have zero control over what key the client encrypts the messages for. Is it only the other peer's phone? Or is it for the peer's phone plus Facebook for analysis of the messages? Especially 2) is of some concern to me (against 1 I can't protect myself anyways because…

> whatever you're sending over WhatsApp is likely going to be used by FB The article links to the technical white paper[0] which explains why your points are invalid. > I'm still inclined to trust apple's iMessage a bit more Do you have any proof why iMessage is more secure or is that statement also baseless? [0]: https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...

The white paper doesn't say anything about additional public keys messages are encrypted for.

It states that:

- The private keys remain on the devices (which is good, but they don't need them to read your messages)

- The messages can't be read by WhatsApp (they don't say anything about their parent company Facebook or governments though).

If you read all the whitepapers and alert messages, you can totally read them in a way that allows Facebook to see, store and analyze the clear-text of every message you're sending, without anybody lying anywhere.

Re: WhatsApp's Signal Protocol integration is now complete

#335
post #20

This is really excellent. A few thoughts: 1) They seem to have replaced TLS/SSL between client and server with "Noise Pipes". Based on a couple of minutes Googling this seems to be a brand new one-man protocol from Trevor Perrin (the same guy who did Axoltl on which Signal is based). At least, I'd never heard of it. I wonder if this is the first inkling of a post-TLS future? http://noiseprotocol.org/noise.html 2) It'…

> They seem to have replaced TLS/SSL between client and server with "Noise Pipes". WhatsApp was already using a custom protocol instead of TLS. We worked with them to transition over to Noise Pipes, which has some advantages over what they were doing before. Also, we've renamed Axolotl to Signal Protocol: https://whispersystems.org/blog/signal-inside-and-out/

For me the biggest thing is - how do we have any idea that WhatsApp is actually using this wonderful crypto tech under the hood? For example my WhatsApp is claiming my messages to my friend are encrypted, whereas his phone is claiming they are not. This is not exactly conducive to trust!

Re: WhatsApp's Signal Protocol integration is now complete

#336

Earlier quoted context omitted.

Because words coming from Nahuatl are cool! (coyotl, mesquitl, tomatl, ahuacatl, etc.) See more from https://en.wikipedia.org/wiki/List_of_English_words_from_ind... They’re distinctively spelled, don’t collide with existing search terms, often have available domains, etc. Most importantly, they anticipated the web 2.0 trend of ending words with two consonants in a row. ;) Finally, just look at this guy: https://uploa…

> Because words coming from Nahuatl are cool! (coyotl, mesquitl, tomatl, ahuacatl, etc.) > Most importantly, they anticipated the web 2.0 trend of ending words with two consonants in a row. ;) But those words (coyote, mesquite, tomato, and avocado, unless I seriously miss my guess) all end in a vowel.

> But those words (coyote, mesquite, tomato, and avocado, unless I seriously miss my guess) all end in a vowel.

Because they were adopted by Spanish speakers. English products using these names could either adopt the Spanish form, or as the GP suggest follow the 2.0 trend and recover the original form, publishing their webpage in the East Timor .tl domain.

Re: WhatsApp's Signal Protocol integration is now complete

#337
post #97

Earlier quoted context omitted.

> What's the next step? Imho one thing that the Signal project suffers from -- and that a lot of open-source projects suffer from -- is poor documentation. They need document their protocol better, to make it easier for third parties to integrate with their system. Signal still lacks a working desktop client (no, the one that you can use if you're running Chrome doesn't count), and I'm sure tons of people would be ea…

I agree about the documentation and a number of other things, but why doesn't the Chromium extension count as a desktop client? You don't need to use Chromium for anything else if you don't want.

I suppose the main reason is that it links to your existing Signal installation on iOS/Android, and does not work standalone.

Re: WhatsApp's Signal Protocol integration is now complete

#338
post #218

Earlier quoted context omitted.

It looks like Noise leaves an implementer with more than enough rope to hang themselves with - for example, it allows unauthenticated Diffie-Hellman, it appears to permit user-selected handshake sequences, has 16(!) different official handshake sequences with subtly different properties, each of which allow payloads to be attached to any message in the handshake process that in turn have different levels of reduced s…

You're describing Noise. WhatsApp uses Noise Pipes, which is one of many instances of the Noise framework. You're right that it's not a good idea for generalists to pick up Noise and go to town with it. Noise isn't misuse-proof.

> You're right that it's not a good idea for generalists to pick up Noise and go to town with it. Noise isn't misuse-proof.

Nor is SSL. Couldn't an opinionated SSL library (supporting exactly one protocol version, one cipher only, etc) provide the same simplicity of use while remaining interoperable and reusing an already-validated protocol?

Re: WhatsApp's Signal Protocol integration is now complete

#339

This is really excellent. A few thoughts: 1) They seem to have replaced TLS/SSL between client and server with "Noise Pipes". Based on a couple of minutes Googling this seems to be a brand new one-man protocol from Trevor Perrin (the same guy who did Axoltl on which Signal is based). At least, I'd never heard of it. I wonder if this is the first inkling of a post-TLS future? http://noiseprotocol.org/noise.html 2) It'…

> It's a shame to see key words be killed off by internationalisation concerns. I think it's actually a solid decision from WhatsApp since the majority of their users are from non English speaking countries[0]. [0]: http://www.statista.com/statistics/291540/mobile-internet-us...

The question isn't really what country they're from though. How many of those users can't speak English?

Re: WhatsApp's Signal Protocol integration is now complete

#340

Earlier quoted context omitted.

For my part: because "Axolotl" is one of the most widely name-dropped terms in hipster cryptography, and because it's been adopted by other projects, and because it's distinctive, and because they basically own the term. In a stroke, everyone doing secure key ratchets would have been using their product . It's also just a cool name.

I always liked "Axolotol" because axolotols are a type of salamander with the amazing ability to regenerate parts of their bodies (including their brains!), and the Axolotol protocol, like OTR, is "self-healing", meaning it's capable of recovering from a compromised session key ( https://whispersystems.org/blog/advanced-ratcheting/ ).

Axolotls are also cool because they're not really a species in their own right --- they're actually just the juvenile form of a salamander. But they can breed while in their juvenile form! It's as if tadpoles could lay eggs without having to turn into frogs first.

In fact, axolotls only metamorphose into salamanders if triggered by the external environment. If you don't stimulate them in the right way, they stay axolotls. For a long time they were thought of as two different types of creature completely.

There's a story of one of the very early researchers looking at his vivarium one day and discovering that it was now full of salamanders rather than the axolotls he was expecting. I would love to have heard the conversation...

Post reply on HN