2 ms·
I am more interested in actual arguments instead of just names. That being said, since you are so interested in names, here is a list by the FSF that includes w
by snakeanus 9y ago
I am more interested in actual arguments instead of just names. That being said, since you are so interested in names, here is a list by the FSF that includes whatsapp https://www.gnu.org/proprietary/proprietary-back-doors.en.html https://www.gnu.org/proprietary/proprietary-back-doors.en.ht... (I am sure that everyone here has heard of the FSF).
> This is the overwhelming consensus of the cryptography and security community
Yeah, having your client (automatically and without a warning to the user first) let a "trusted" 3rd party make it re-send and re-encrypt a message with another unverified public key is the "overwhelming consensus of the cryptography and security community".
This article did not try to debunk what the original article said at all. Instead its main argument seems to be "Sure, whatsapp resends a message encrypted with a different key when the server demands it without even informing the user but this is not bad (because of "usability concerns") and damn you for even daring to inform the users about it!". Its secondary argument seems to be "b-but users will switch away to less safe applications if you inform them about how much whatsapp sucks - even if you suggest signal afterwards!".
> Here’s a difficult attack that could allow a sophisticated, resourceful adversary willing to invest a good deal of effort, some components of which have never been demonstrated in practice, to read a few messages that had been sent but have not yet been read after events like the intended recipient changing phones or SIM cards
It's not a "difficult attack" if the trusted third party (or anyone who can compromise their servers or force them) can perform it at will.
In any case, even if this backdoor did not exist it would not make whatsapp any better as it still is a proprietary software that might perform shady things in the background (or might be updated at any time to do so).
For anyone else seeing this and wants to read more about the story see https://news.ycombinator.com/item?id=13389935 https://news.ycombinator.com/item?id=13389935 and https://news.ycombinator.com/item?id=13394900 https://news.ycombinator.com/item?id=13394900
- deleted 9y ago[deleted]
- tptacek 9y agoI'm confident I understand the intent and implications of the open letter I've cited. People can decide for themselves how persuasive they think either of us are here.