4 ms·
Caveat: I have never used WhatsApp and do not know anything about its interface or options (default or otherwise). >>[The choice to make these notifications "b
by mos_basik 10y ago
Caveat: I have never used WhatsApp and do not know anything about its interface or options (default or otherwise).
>>[The choice to make these notifications "blocking" (i.e. to require manual verification) would] leak information to the server, etc., etc.
>Why should this option exist at all?
The option does not exist, and should not exist. That's the author's point there. You agree with him and with WhatsApp on that.
All you disagree on is implementation:
Author: "[Non-blocking defaults] provide transparent and cryptographically guaranteed confidence in the privacy of a user's communication, along with a simple user experience."
You: "Enable notifications for everyone and demand verification; if you don't want to verify, just tick "verified" without actually verifying."
How are these two substantially different? They look the same to me in terms of security and WhatsApp's implementation doesn't make you click anything.
- FabHK 10y agoDifference is that the WhatsApp client re-encrypts the message with the new key from the server and re-sends it without user intervention ("non-blocking"), so even if you cared, you can't prevent it. With the alternative, people that don't care could tick "verified" with or without verifying, but you could also click "cancel" (with or without verifying).
- mos_basik 10y agoWhat difference does it make? ALICE When would you like to meet? BOB Tomorrow, 19:00, by the north tennis courts. ALICE Sounds good. !!! BOB's key has changed !!! BOB Actually, could we meet at my place? I'm going to be super busy tomorrow. If Alice and Bob are doing something that needs to remain secure, Alice would be a fool to trust Bob's messages after the key change without manually verifying the new key with Bob. How does withholding messages help, aside from telling the server which people have enabled the setting and which people have not? [edit: I just realized you were talking specifically about the case where manual verification is enforced for all users; disregard the last phrase.] Admittedly one angle I can kind of agree with is that layman users may not understand the implications of a key change and the importance of out-of-band verification, and blocking messages until verification would be a way of signaling the significance of the key change. But... counterpoint to that is that users interested in security are probably already dead in the water in that regard if all they have is a layman's knowledge of how crypto works.
- FabHK 10y agoBOB: Ok, we're all good, we have verified our keys in person, send me the launch keys to the nuclear missile. Good night. [tick mark, tick mark] ALICE: Here they are: 12345678. [tick mark] [Eve on the compromised server to Alice]: Hey ho, new key, please send again. ALICE [with new MITM key, and no way to block this]: Here they are: 12345678. !!! By the way, Bob's key has changed. !!! BOTH: Ooops.
- ycmbntrthrwaway 10y ago> The option does not exist, and should not exist. I also think the option should not exist, but according to The Guardian article [0], the option exists: "In WhatsApp’s implementation of the Signal protocol, we have a “Show Security Notifications” setting (option under Settings > Account > Security) that notifies you when a contact’s security code has changed." [0] https://www.theguardian.com/technology/2017/jan/13/whatsapp-backdoor-allows-snooping-on-encrypted-messages https://www.theguardian.com/technology/2017/jan/13/whatsapp-...
- mos_basik 10y agoThe option The Guardian is describing there is something like this: When my partner's key changes: [ ] Show me a notification (y/n) What I was talking about was an option like this: When my partner's key changes: [ ] Wait for my manual confirmation before delivering any messages from my partner that are dated after the key change (y/n) To me it's up for debate whether or not the existence of the first option or the fact that it's disabled by default are good ideas, in terms of the behavior of the app matching consumer expectations of security. It'd be safer for it to be permanently enabled, but that's neither here nor there. But the second option would be fundamentally broken and leak information to the server about how conscientious a user is about security, which is why the author, whatsapp, and everyone in this sub-thread agrees it's a bad idea. Someone else gave an concise example elsewhere in the thread: https://news.ycombinator.com/item?id=13397118 https://news.ycombinator.com/item?id=13397118 edit N.B.: Requiring manual verification all the time, from everyone, would not leak any information and would be the most secure. Allowing users to choose whether or not they want to manually verify is the leaky bit.
- ycmbntrthrwaway 10y agoWell, there are two options: notification option and confirmation option. Moxie correctly assumes that confirmation option (require manual confirmation to resend if key changes) should either be enabled for everyone or disabled for everyone, as its state can be determined passively by the server. But it depends on the notification option. His conclusion is that confirmation option should be disabled for everyone because if it is enabled, it is possible to leak notification option state. But it is wrong. More secure solution exists: enable notification option for everyone, and then enable confirmation option for everyone. I was complaining about why notification should be an option. Even worse, disabled by default. Wire [0] just shows "resend" button near message when it is not delivered and always shows notifications about key changes if you have verified devices. You can still ignore verification option if you want and get no notifications. Signal blocks with a message when key changes. Both solutions are secure, Wire's is more convenient, Signal is less error-prone. WhatsApp solution is simply insecure. [0] https://wire.com/ https://wire.com/