5 ms·
Open source is not a panacea here. The situation is largely the same with Signal: Unless you manually build and install Signal yourself, there is no guarantee
by tshtf 11y ago
Open source is not a panacea here.
The situation is largely the same with Signal: Unless you manually build and install Signal yourself, there is no guarantee that the App Store or Play Store versions are actually built from the source provided by OpenWhisperSystems.
And even if you compile Signal yourself, there's always "Reflections on Trusting Trust".
- simoncion 11y agoBut you do have a significant amount of confidence that -unless their signing keys have been compromised- the versions of the software in the app stores are the versions published by OWS. If you don't trust OWS to fail to publish malicious copies of its software, why would you trust them to fail to subtly sabotage their software?
- tshtf 11y agoIf you don't trust OWS to fail to publish malicious copies of its software, why would you trust them to fail to subtly sabotage their software? I don't believe OWS would do this voluntarily, unless compelled by the government.
- lorenzhs 11y agoOh I don't claim that opening up the source code is a magical way to fix everything. But without the four essential freedoms, it is much harder to be reasonably certain that nothing nefarious is going on.
- ex3ndr 11y agoIf you trust openwhispersystems than on android it is guaranteed to be the same build that was uploaded. All builds are signed by developer unlike apple (where you sign builds to prove that this is your build to apple, not to user).
- ethanbond 11y ago"If you trust OpenWhisperSystems" is a pretty huge condition – the exact condition we're discussing here. The advantage of open source is that you don't have to trust OWS, you have to trust the source code, which you can do by auditing it yourself.
- jMyles 11y ago> The advantage of open source is that you don't have to trust OWS, you have to trust the source code, which you can do by auditing it yourself. No. That is not the advantage of open source. The advantage is that as long as somebody audits the code, you don't have to. And in this case, you don't need to trust OWS to do the right thing, only to refrain from pushing rogue updates (ie, to only sign versions that are actual releases). You can still read the code yourself.
- nl 11y agoAnd in this case, you don't need to trust OWS to do the right thing, only to refrain from pushing rogue updates (ie, to only sign versions that are actual releases). You can still read the code yourself. You've missed the subtleties around the word "trust" in the context. You don't need to trust that the WhatsApp people are nice, or want to do what is right. You need to trust that they and Google haven't been legally compelled to push a "rouge" update - perhaps only to you. Don't forget there is nothing technically stopping a uniquely compiled update being pushed to a single account holder. The only protection against this is 3rd party auditing and checking the signatures yourself, and that the 3rd party is completely located in a jurisdiction where they are unlikely to be legally compelled to comply with an order that applies to WhatsApp and/or Google.
- mtgx 11y agoI think the bigger problem is that Whatsapp doesn't even allow users to verify each other's fingerprints. Whatsapp could disable the end-to-end encryption and you would have no clue that they did that.
- mike_hearn 11y agoI've seen leaked UI screenshots that do have that feature. And Moxie has said that such a feature was always planned. WhatsApp supports an ungodly number of platforms. Probably they don't want to expose encryption in the UI until the feature/platform matrix is complete and there are no edge cases where traffic is unencrypted.
- seanjensengrey 11y agoOne could trace the protocol between the phone and the network to see if it conforms generally. Specifically is another issue.
- mikeash 11y agoKnowing all the details is key, though. For example, it's easy to vastly reduce the entropy of cryptographic keys, but still make them look completely random from the outside. The Debian OpenSSL bug is an extreme example of doing this by accident. It took a year and a half to discover that, and that was with the buggy source code available the whole time.