Earlier quoted context omitted.
I'd assume the keys are generated on device.
Presumably the device generates a keypair and then needs to exchange with the remote device somehow? I assumed both devices connect to WhatsApp and it delivers what is ostensibly the pub keys from each of the parties to each of them?
WhatsApp Security Vulnerability
41–50 of 71 posts
Re: WhatsApp Security Vulnerability
#42Earlier quoted context omitted.
Unfortunately, if WhatsApp did defend against this, it would be such a big hassle that users would disable it. How many people do you know that wouldn't just click "accept" on "this user's keys changed", or wouldn't just ask the attacker "hey did you get a new phone?" "yes" "oh okay"? People love to blame WhatsApp, but what can anyone realistically do?
No, this is why I disagree with Moxie, the right UI design wouldn't have to create fatigue. It could just block by default, and then allow you to change the default with an appropriate warning. At least that way, everyone will become aware at least once and make their choice.
Re: WhatsApp Security Vulnerability
#43Earlier quoted context omitted.
Unfortunately, if WhatsApp did defend against this, it would be such a big hassle that users would disable it. How many people do you know that wouldn't just click "accept" on "this user's keys changed", or wouldn't just ask the attacker "hey did you get a new phone?" "yes" "oh okay"? People love to blame WhatsApp, but what can anyone realistically do?
It does not need to be a modal form - a notification message, embedded in the the chat log, just before a "Hey, could you send me some money", could make some people think twice before transferring: "Wow, he is asking me in excess of USD500 just after WhatsApp warned me his cell phone has changed. Weird". The simple alert shown in moxie's own blog post [1], perhaps less cryptically written, would probably do the job.…
Re: WhatsApp Security Vulnerability
#44Earlier quoted context omitted.
No, this is why I disagree with Moxie, the right UI design wouldn't have to create fatigue. It could just block by default, and then allow you to change the default with an appropriate warning. At least that way, everyone will become aware at least once and make their choice.
Everyone (talking about non-technical users here) won't understand why they can't message a particular person any more and will blame WhatsApp "It's broken again". Block by default would kill growth and they don't want that.
Re: WhatsApp Security Vulnerability
#45Re: WhatsApp Security Vulnerability
#46While people discuss about a possible state-actor stronghanding WhatsApp and the semantics of backdoor, the "design feature" of not showing the key changes are making real victims, at least in Brasil: The attacker first try to duplicate the mobile phone number of the first victim, probably by social engineering their phone company. This part may look difficult to do, but it is not hard if you realize you do not need…
Seriously, even for good friends and family, I'd expect a phone call when asked for money, not a message. It's basically a matter of respect.
Re: WhatsApp Security Vulnerability
#47I didn't quite grasp why attacking entity (e.g. government) has the ability to read messages. What does "WhatsApp has the ability to force the generation of new encryption keys for offline users" mean? Does it mean that WhatsApp backend has the ability to force sender to use pregenerated compromised key provided by attacker? In terms of WhatsApp security whitepaper, does that mean that attacker can force sender to us…
Let's say WhatsApp wants to read the next message sent to user X: 1) WhatsApp makes user X appear offline 2) User Y sends user X a message 3) WhatsApp sends user Y an indication that user X's key has changed, along with the public key for which they have the corresponding private key With these steps, user Y's message will be resent with the new key that WhatsApp knows, and so they can read the message. There is a co…
Re: WhatsApp Security Vulnerability
#48I didn't quite grasp why attacking entity (e.g. government) has the ability to read messages. What does "WhatsApp has the ability to force the generation of new encryption keys for offline users" mean? Does it mean that WhatsApp backend has the ability to force sender to use pregenerated compromised key provided by attacker? In terms of WhatsApp security whitepaper, does that mean that attacker can force sender to us…
Re: WhatsApp Security Vulnerability
#49Earlier quoted context omitted.
Everyone (talking about non-technical users here) won't understand why they can't message a particular person any more and will blame WhatsApp "It's broken again". Block by default would kill growth and they don't want that.
It also absolutely would create fatigue, I don't know why WhitneyLand thinks it wouldn't.
Re: WhatsApp Security Vulnerability
#50While people discuss about a possible state-actor stronghanding WhatsApp and the semantics of backdoor, the "design feature" of not showing the key changes are making real victims, at least in Brasil: The attacker first try to duplicate the mobile phone number of the first victim, probably by social engineering their phone company. This part may look difficult to do, but it is not hard if you realize you do not need…
Unfortunately, if WhatsApp did defend against this, it would be such a big hassle that users would disable it. How many people do you know that wouldn't just click "accept" on "this user's keys changed", or wouldn't just ask the attacker "hey did you get a new phone?" "yes" "oh okay"? People love to blame WhatsApp, but what can anyone realistically do?
Literally everyone not tech savvy, this what happens on signal.