5 ms·
It makes WhatsApp effectively not E2E encrypted. All messages can be recovered by Facebook. How is that NOT a backdoor?
by dromen 10y ago
It makes WhatsApp effectively not E2E encrypted. All messages can be recovered by Facebook. How is that NOT a backdoor?
- Johnny_Brahms 10y agoAll messages, sent while a person is offline. It is bad, but not nearly as bad as "all messages"
- foxylion 10y agoIt is in fact all messages. They can simply not deliver the first message and force a resend record that mesaage. Afterwards force again a resend with the old encryption key and deliver that mesaage. No one would get a notification.
- morsch 10y agoI can see how you would leave the receiver in the dark by sending them the original, deferred message, but how would asking the sender's device to resend with a different key not result in a notification? Furthermore, as soon as the sender attempts to deliver another message to the recipient, they would get another notification (because the encryption key changed back to the real key); alternatively the attacker could continue blocking (and reading) messages to the recipient, but the lack of delivery would be noticeable. You could escalate it into a MITM rather easily, though, by attacking both ends; but again, a key change notification should be displayed to both parties. Assuming the closed sourced app works as advertised, obviously.
- foxylion 10y agoYes, you are right. But I think most people did not enable the security option so they wouldn't detect any interception of messages.
- Johnny_Brahms 10y agoWell, what you are describing is a regular MITM attack. Unless you validate fingerprints, this is a risk with _all_ public key-based protocols.
- adsche 10y agoCan't they (WhatsApp) simulate a user being offline?
- disgusting_guy 10y agoNo, all messages cannot be recovered by Facebook. Read the article - messages that are not yet delivered can potentially be read; if it has been delivered it cannot be retrieved.
- belovedeagle 10y agoYou go read the article. The deciding factor is not whether the message has been delivered, but whether WhatsApp servers report to the device that the message has been delivered. There's nothing stopping them from claiming that no messages have been delivered and thus recovering all messages (as long as they had been preselected for false delivery reports) despite true delivery status.
- Jarwain 10y agoSo they can recover the messages, right? However, wouldn't these messages still be encrypted? Sure, they force a key change, and the messages are encrypted using the new key and sent. Theoretically, an attacker could have multiple copies of the same message, but these messages would still be encrypted under a variety of different keys right? Wouldn't the content of the messages still be secure? Unless the key-change forces the user to be using an insecure key-pair, but is that actually happening?
- ycmbntrthrwaway 10y agoNew encryption (public) key is selected by the attacker, so he knows the decryption (private) key. Basically attacker just puts real device offline and registers his own device.
- Jarwain 10y agoWouldn't the attacker need to be authenticated as the user of the real device for this to work?
- ycmbntrthrwaway 10y ago