We were surprised to read this story and are not aware of discussions that would force us to change our product. We believe people have a fundamental right to have private conversations. End-to-end encryption protects that right for over a billion people every day. We will always oppose government attempts to build backdoors because they would weaken the security of everyone who uses WhatsApp including governments th…
If so, sounds like someone from FB Legal and the SEC should have Words with Bloomberg. Wouldn't be the first time they've intentionally maliciously misrepresented/lied about an infosec issue to the detriment of a company in order to move the market (Supermicro "grain of rice"...)
Facebook, WhatsApp Will Have to Share Messages With U.K.?
571–580 of 591 posts
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#572Earlier quoted context omitted.
In (at least) the US this wouldn't hold up in court if they went after you: https://cr.yp.to/softwarelaw.html . Of course if WhatsApp detected an abnormal or tampered version of the app, they can suspend or disable your account. I'm sure security labs that do reverse engineering of this sort probably do it on test handsets with burner numbers and identities so it wouldn't affect any personal accounts they use.
Perhaps, I just thought it was an odd thing for the head of WhatsApp to say: You don't have to take our word on this - just do this thing that we prohibit in our terms of service.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#573Earlier quoted context omitted.
> it's possible enough to tear through our binaries No, it's not "possible enough" and I strongly suspect you fully realize that. A backdoor doesn't need to be in a form of an IF statement or something comparably obvious and silly. It can be a weakly seeded PRNG that would allow a "determined party" to brute-force the key exchange in a reasonable time. That would take man-years to fish out from a binary, and that's w…
Juniper reveled the Screen OS backdoor with a quiet patch over Christmas. Within a month the backdoor was fully understood.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#574Earlier quoted context omitted.
I disagree that it would take man-years to fish that out from a binary. Black hat and white hat hackers do this all the time.
I agree. The crypto used is industry standard, and the actual process all the way from random number generation to deriving a key is relatively easy to follow. Active ways to attack the client to make it leak the key are far more worrying - but even an open source project wouldn't protect against that.
Good luck finding even this without a fine comb. And that's us just getting started with code flow obfuscation.
No source = no trust. It's as simple as that.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#575Earlier quoted context omitted.
Conceptually you can't because you can put as a citizen any requirement to make a canary that the law cant compel you to do. For example, you can pay to publish the canary: the state can't compel you to spend money on it. Or you can make a small petty crime with it (say, an IP Violation). In places where there are limits to what the government can do to an with you, its possible to resist.
Why are you arguing about what is conceptually possible? The reality is such that people can absolutely be compelled to lie in public, especially for "national security" means. It happens all the time. Failing to update could signal something, but continuing to update means nothing. "Resistance" and other such concepts don't hold up to scrutiny against shareholders and 40 year sentences.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#576Earlier quoted context omitted.
But the FBI could advise the canary poster that not continuing to post the canary notice could lead to legal action (esp. since that person has willfully put him/herself into the situation). Then it would be up to the recipient of the NSL to decide if it’s worth that risk, which is as stated above, untested. It’s a fine line between telling them to lie versus telling them the ruse could be in violation of the gag ord…
Conceptually you can't because you can put as a citizen any requirement to make a canary that the law cant compel you to do. For example, you can pay to publish the canary: the state can't compel you to spend money on it. Or you can make a small petty crime with it (say, an IP Violation). In places where there are limits to what the government can do to an with you, its possible to resist.
We know that the legal bar for forcing someone to speak or not speak is high (compelling state interest), but national security has usually been held to pass such a bar.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#577Earlier quoted context omitted.
Why are you arguing about what is conceptually possible? The reality is such that people can absolutely be compelled to lie in public, especially for "national security" means. It happens all the time. Failing to update could signal something, but continuing to update means nothing. "Resistance" and other such concepts don't hold up to scrutiny against shareholders and 40 year sentences.
Because thinking otherwise is saying that nothing really matters, the government can do anything at any time and you are toast no matter what.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#578Earlier quoted context omitted.
No, you don't. This is a fundamental rule of how encryption works. You can't design around it. If there is a key which decrypts everything, then there is a risk it can be stolen or guessed and used to decrypt anyone's messages. This risk does not exist in current, properly designed systems. Any government which wishes to add a backdoor to an E2E encrypted messaging system must understand that they will be HEAVILY und…
I think you are the one not understanding at this point. This has nothing to do with "how encryption works". Whatsapp decided to go for E2E encryption for commercial and marketing purposes following all those privacy scandals. They did not have to. They could have gone with P2P encryption, i.e. that their databases could have stored messages in cleartext. That way authorities would not have needed to ask for any back…
Okay. Let's just get rid of E2E entirely and let Facebook mine not only our metadata but also the content of our messages. Nice plan.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#579Earlier quoted context omitted.
Why are you arguing about what is conceptually possible? The reality is such that people can absolutely be compelled to lie in public, especially for "national security" means. It happens all the time. Failing to update could signal something, but continuing to update means nothing. "Resistance" and other such concepts don't hold up to scrutiny against shareholders and 40 year sentences.
Because thinking otherwise is saying that nothing really matters, the government can do anything at any time and you are toast no matter what.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#580Earlier quoted context omitted.
Why are you arguing about what is conceptually possible? The reality is such that people can absolutely be compelled to lie in public, especially for "national security" means. It happens all the time. Failing to update could signal something, but continuing to update means nothing. "Resistance" and other such concepts don't hold up to scrutiny against shareholders and 40 year sentences.
Because thinking otherwise is saying that nothing really matters, the government can do anything at any time and you are toast no matter what.