4 ms·
You know, I've always liked your writing a whole lot. However your behavior in reaction to this story seems bizarre to me. I see all these people come in defen
by RodericDay 10y ago
You know, I've always liked your writing a whole lot. However your behavior in reaction to this story seems bizarre to me.
I see all these people come in defense of WhatsApp using bizarre statistics about domestic violence (big correlation with hacking?). Then someone (tptacek?) was going around saying not a single crypto expert disagrees with their consensus (trucking all over the original source, Tobias Boelter). Then there are all these jokey "Is WhatsApp Backdoored Yet?" expressions. It's a frenzy.
There seem to be a whole bunch of people who take The Guardian article as "omg, after this article, people will drop WhatsApp and use something like Messenger instead!". Which, sure enough, maybe a common scenario, and worse. However, the article was obviously meant to push people outside of Facebook gardens, and into a more secure alternative. It's supposed to make you go "WhatsApp is unsafe, I will use Signal instead". One of those "trade-offs" you're talking about in the first place, just like the security vs. purity one. In this case, erring on the side of activism.
As a sideline observer with very little crypto knowledge, I think Boelter presented an interesting case, while the anti-Guardian crowd reacted like crazy people, pulling fire alarms, hurling insults, and Streisand-effect-ing the story into a huge controversy.
I mean, the EFF article itself, in defense of WhatsApp and against The Guardian, says:
https://www.eff.org/deeplinks/2017/01/google-launches-key-transparency-while-tradeoff-whatsapp-called-backdoor https://www.eff.org/deeplinks/2017/01/google-launches-key-tr...
> If you are a high-risk user whose safety might be compromised by a single revealed message, you may want to consider alternative applications. As we mention in our Surveillance Self-Defense guides for Android and iOS, we don't currently recommend WhatsApp for secure communications.
It goes on to qualify this statement by saying that's a rare threat model. However, that right there, is enough to justify the original piece. The idea, I think, is that everyone should be on something like Signal, so that merely using Signal wouldn't be taken as a reason for suspicion. If you disagree, your argument could surely be better than jokes about white text.
Just my two cents as a nobody.
- idlewords 10y agoI'm not sure why you're taking the white text example as a joke.
- RodericDay 10y agoWeird to have such a bad interaction with one of my minor personal heroes. Shucks I guess!
- baybal2 10y agoHow unethical is this, for this group of so-so around sensationalist bloggers led by Zeynep Tufekci (tptacek?) whom I would not dare to call real cryptography specialists (and this is whom they are in my eyes, none of them is a person with a worthy math/crypto research background) to solicit opinions of reputable bodies on this crypto hole, and then twist and editorialize all of that to suit their message that this crypto hole is not a crypto hole