Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

1–10 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#2
The most backdoor-looking feature for me in supposedly encrypted systems are cloud backups. They are “optional” yet most users will agree (especially when given software constantly nags about it until you give up) and their backups will leak both sides of conversations, despite all end-to-end encryption attempts.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#3

The most backdoor-looking feature for me in supposedly encrypted systems are cloud backups. They are “optional” yet most users will agree (especially when given software constantly nags about it until you give up) and their backups will leak both sides of conversations, despite all end-to-end encryption attempts.

This is something i don't understand (at least for me/my use case):

Are historic chats that important to have them backed up? To me, if there's anything of value, i'll save it via other means...

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#4
post #3

The most backdoor-looking feature for me in supposedly encrypted systems are cloud backups. They are “optional” yet most users will agree (especially when given software constantly nags about it until you give up) and their backups will leak both sides of conversations, despite all end-to-end encryption attempts.

This is something i don't understand (at least for me/my use case): Are historic chats that important to have them backed up? To me, if there's anything of value, i'll save it via other means...

For me, chat history has a huge value.

How many times things looks like meaningless when they are said but have a lot of values at a later date?

For example, sometimes you wonder, "when was it that time when XXX event happened". Or "I remember that one day someone told me that he had the same problem as me, but who was it and what was his solution?"

Otherwise, we are used to share thousands of links and snippets with my friends that we usually discuss. A lot of time, after a very long time (sometimes years), for some reason we remember that something or link about a topic was discussed long time ago, and then it is convenient to look into the history with keywords to find back the links and what was said at that time!

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#6
If any clients had been logging that nonce, we could retrospectively catch any person in the middle.

Far too few services do strategic logging of data useful to catch attackers like this. Many attackers won't attack if they know traces will be left which can point to them.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#7
post #4
post #3

Earlier quoted context omitted.

This is something i don't understand (at least for me/my use case): Are historic chats that important to have them backed up? To me, if there's anything of value, i'll save it via other means...

For me, chat history has a huge value. How many times things looks like meaningless when they are said but have a lot of values at a later date? For example, sometimes you wonder, "when was it that time when XXX event happened". Or "I remember that one day someone told me that he had the same problem as me, but who was it and what was his solution?" Otherwise, we are used to share thousands of links and snippets with…

Sure, but wouldn't you want to have control over these backups yourself? Not only do you get increased privacy from it, you also won't be in for a nasty surprise when the service decides to remove old logs/stop doing business.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#8

The most backdoor-looking feature for me in supposedly encrypted systems are cloud backups. They are “optional” yet most users will agree (especially when given software constantly nags about it until you give up) and their backups will leak both sides of conversations, despite all end-to-end encryption attempts.

WhatsApps cloud backup on Android sits on Google drive by default.

It is encrypted with a per user key known to WhatsApp.

That means for a third party to access the chats, they need Google to hand over the data, and Facebook to hand over the key.

The logical next step to add would be for Google to additionally encrypt the data with the users logon password or something derived from it. Google won't do this anytime soon for business reasons.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#9
post #7
post #4

Earlier quoted context omitted.

For me, chat history has a huge value. How many times things looks like meaningless when they are said but have a lot of values at a later date? For example, sometimes you wonder, "when was it that time when XXX event happened". Or "I remember that one day someone told me that he had the same problem as me, but who was it and what was his solution?" Otherwise, we are used to share thousands of links and snippets with…

Sure, but wouldn't you want to have control over these backups yourself? Not only do you get increased privacy from it, you also won't be in for a nasty surprise when the service decides to remove old logs/stop doing business.

An average user doesn't commonly want to have control over anything themselves :P.
Post reply on HN