4 ms·
The article says: "With end-to-end encryption in place, not even WhatsApp’s employees can read the data that’s sent across its network." But according to the d
by raulk 11y ago
The article says:
"With end-to-end encryption in place, not even WhatsApp’s employees can read the data that’s sent across its network."
But according to the diagram:
http://www.wired.com/wp-content/uploads/2016/04/Whatsapp_Encryption_Proxima-1024x600.jpg http://www.wired.com/wp-content/uploads/2016/04/Whatsapp_Enc...
... A's message is encrypted with Whatsapp's public key, which means that Whatsapp's private key can (and has to) decrypt it on the server side to encrypt it in turn with B's public key.
If the diagram is truthful, the claims the article makes are incorrect.
- sajid 11y agoThe message is encrypted with the public key belonging to user B.
- wcummings 11y agoWhat in the diagram gives you the impression the public key belongs to WhatsApp? Presumably WhatsApp is handling PKI.
- raulk 11y ago"Public key from server" is an ambiguous phrase. I took "from" to denote possession, not source. After reading the other sources of information, it's clear it is a secure protocol. More so when designed by the Snowden-approved Open Whisper Systems team.
- codemac 11y agoIt's the user's public key, not WhatsApp's.
- jmilum 11y agoit use the public key of the other user, not whatsapp. in effect, whatsapp is just acting as a key server. now they could have that users private key, but that's another matter
- sickbeard 11y agoSo in theory they could help by intercepting these keys and handing them to authorities without actually decryption the data themselves
- jmilum 11y agothe client generates a public/private key pair and only sends the public one to the whatsapp server. the server should never be able to access the private key. but unless the source of the client is available for review, who knows?
- dogma1138 11y agoWhy are people downvoting this? While the "public key" is not "WhatsApp's" it is served from their server hence in theory they can provide you with any public key they want, decrypt the message, store it, and re-encrypt it with the "correct" private key and send it off to the user. With PKI the ability of the user to verify that they received and used the correct public key is critical and while I have to admit that I haven't read that much about WhatsApp's E2EE setup I haven't seen anything that shows how this issue can be mitigated in a way that would be useful for most users.
- M4v3R 11y agoThat's true, but they provide means to verify the fingerprint of the other party, so you can verify that your app is encrypting messages using legitimate public key and that there's no MITM going on.
- dogma1138 11y agoYeah but again there are quite a few questions here (not an WA user). How foolproof is the verification system, how susceptible is it to downgrade attacks (while E2EE isn't not universally deployed) is there are 3d party verification of signatures, is there a community trust signing, can whats app disable E2EE in it's application without a noticeable UX change to either party, how does this work with multi user messages, how does this work with multiple devices, how does this work with historic messages that were encrypted using different keys etc. I would say that there are sufficient "unknowns" at this point to take the security of this entire solution with some skepticism especially if you remotely planning to use this for anything that could put your life at any risk.
- SAI_Peregrinus 11y agoDowngrade attacks should be difficult. As the article mentions once a client has communicated with another once using encryption all future communications to that client will be encrypted. So a downgrade attack would require either spoofing a new client for a user (eg a phone they didn't have before) which is likely noticeable. The whitepaper (https://www.whatsapp.com/security/WhatsApp-Security-Whitepaper.pdf https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...) goes into more detail. That said, they could push out an update that changes the UI to disable E2EE without notifying the user, and that would be difficult to notice since the app is closed source. For this reason Signal is more secure, despite using the exact same protocol.
- throw7 11y agoActually, it's the private key that needs to be kept secret... I'm not sure how that's guaranteed or how we can actually verify that the private key is secure. Knowing that whatsapp is built by spying and uploading all your contacts and phone numbers to their servers, well, do you trust them to not upload the private key also?