3 ms·
Binaries which have a client-server architecture certainly are. Is the claim the full WhatsApp stack is open to regular indepedent third party security audits
by iwlbebnd 10y ago
Binaries which have a client-server architecture certainly are.
Is the claim the full WhatsApp stack is open to regular indepedent third party security audits from multiple firms?
- CiPHPerCoder 10y agoYou don't need to know what the server does with your data if the client is encrypting it properly. The client-server architecture is irrelevant here. Read this, then flip the roles: https://paragonie.com/blog/2016/03/client-authenticity-is-not-server-s-problem https://paragonie.com/blog/2016/03/client-authenticity-is-no... Reverse engineer the client-side app. You now know what the client-side app (the part that people want to be open source) is doing. You don't need to know what the server's code is doing.
- iwlbebnd 10y agoWhich is exactly the issue? At any time the server can request a key reset and have messages resent. I don't see how it is at all irrelevant since it is exactly what the cause is here.
- CiPHPerCoder 10y agoThe issue is that the client software being open source (rather than closed source) would do nothing to change the risk profile, so it's not worth bringing up. If the client is open source: What the server is doing is irrelevant as long as the client is secure. If the client is closed source: What the server is doing is irrelevant as long as the client is secure. If the server can compromise the client, whether or not the client is open source does not matter. People who believe that open source is a prerequisite for security are disregarding the entire discipline of reverse engineering which is a large chunk of software security expertise.
- iwlbebnd 10y agoInteresting how the goal posts keep moving, meanwhile I get down votes and my comments are being removed. Look you're wrong, you're wrong for multiple reasons and this happens all the time, especially in politics, where the so called experts reject the common sense of hobbyists, amateurs, and mere working stiffs like me who is merely a lowly sys admin. Open source software allows anyone at anytime to conduct a security audit without advanced warning, open source allows you to access server and client side code equally, open source software doesn't require the additional work of de obsuficanting binaries, open source code can be forked and modified and tested easily, there are no additional barriers and anyone can pick it up and do it at any time, that makes open source software inheritly easier to test and verify. Also large open source projects are more difficult to inflitrate with a back door, all a closed source project needs to do is modify some server side behavior that no one gets to see. Most closed source software lives on closed servers. Sure closed source programs can be secure, can be trusted, and can be verified, but to pretend it isn't harder, sometimes impossible, and trivial to backdoor is to ignore history and common sense. You're wrong, it's okay to be wrong and if you need to take out your anger by flagging my remarks so they aren't seen then so be it.