3 ms·
> This may have been true pre-fb acquisition but there has been changes to how WhatsApp behaves, especially server side storage. WhatsApp messages are encrypte
by CiPHPerCoder 8y ago
> This may have been true pre-fb acquisition but there has been changes to how WhatsApp behaves, especially server side storage.
WhatsApp messages are encrypted end-to-end between each person using it. The whole point of end-to-end encryption is not having to trust the server-side storage.
Furthermore, WhatsApp uses the Signal Protocol-- the state-of-the-art for secure messaging protocols.
The worst that WhatsApp can see is "who's talking to who?"
Finally, the adoption of the Signal Protocol in WhatsApp came long after the Facebook acquisition.
So, no. It wasn't better off pre-fb.
- nostoc 8y ago> who's talking to who? That can be a problem when you're a whistle blower contacting a journalist.
- CiPHPerCoder 8y agoSure, that can be a problem. However, it's completely irrelevant to the problem of server-side storage, as the comment I replied to was citing. (Server-side storage is a non-issue, due to the encryption protocols in use. It doesn't matter if you distrust Facebook, they aren't going to be able to read your messages. End of.)
- reitanqild 8y agoI avoid WhatsApp but this is correct AFAIK (given that they don't push a malicious client at some point.) The main problems with WhatsApp are as I can see: - they scoop up metadata - they upload the data more or less plaintext to Google for backup. (I personally dislike but trust Google but not everyone trusts them.) - they paid way to much for it to not try to monetize it in all kinds of crazy ways
- TheSpiceIsLife 8y ago> given that they don't push a malicious client at some point How do we know this hasn't happened already? How do we know it won't happen tomorrow?
- Operyl 8y agoBecause there are a number of people constantly reverse engineering these clients to be sure that it doesn’t.
- shshhdhs 8y agoThis doesn’t really help as much as you seem to hope for. As a counterpoint, I would like to introduce you to the Underhanded competitions: http://www.underhanded-c.org http://www.underhanded-c.org https://underhandedcrypto.com https://underhandedcrypto.com
- deleted 8y ago[deleted]
- reitanqild 8y ago> How do we know this hasn't happened already? As has been pointed out here in the chat already: Scott (and others) have reverse engineered it. > How do we know it won't happen tomorrow? Consequences. Even Facebook seems to realize that is the nuclear option. That said there is a number of places this can still go wrong, but they are equally true for any mainstream client (edit:) and non mainstream clients have their own issues. Personally neither like nor trust Facebook at all so I try to minimize contact.
- walshemj 8y agoExactly you would never use electronic means to actually transmit information.
- myth_buster 8y agoThanks for clarifying. Even with E2E wouldn't you still want the code to be open source or an independent audit done? As I said, not an expert.
- CiPHPerCoder 8y agoI'd want it, sure. But I could also just dex2jar + JD-GUI the Android app and study the decompiled Java code to see what they're doing. Edited to add: https://twitter.com/CiPHPerCoder/status/1042870740880637952 https://twitter.com/CiPHPerCoder/status/1042870740880637952
- Angostura 8y agoWhatsApp requires you send the server the entirety of your contact list. No thanks.
- eggsome 8y agoNot true. I use WhatsApp without doing that (on iOS), but it does require other people to contact you first before you can have a conversation.
- Angostura 8y agoReally? So you don’t simply get this? : https://share.icloud.com/photos/0xU-mTEbBSDtCRSgVUGGhp8Kw https://share.icloud.com/photos/0xU-mTEbBSDtCRSgVUGGhp8Kw
- B-Con 8y agoObligatory "don't forget to authenticate the other party. Encryption can be meaningless without authentication if someone MITMs the initial setup. Follow-through on WatsApp's initial verification step using some other channel before you assume the communication is secret.
- briandear 8y agoSo why not just use Signal? Why even remotely trust Facebook?
- zeckalpha 8y agoOr Keybase? Signal has similar weaknesses as WhatsApp
- sfifs 8y ago> The worst that WhatsApp can see is "who's talking to who Not really, given keys are centrally managed, it is fairly straightforward for WhatsApp to setup MITM intercept. In fact they don't even need to push a malicious client etc, they just need to push a different public key than the sender/receiver's actual ones when contacts mutually add each other and this will quite simply allow MITM interception unless the people do key verification in person. If what the whistle blower is trying to do is stay anonymous - would they physically meet the reporter immediately? They could even push new keys to existing mutual contacts and get away with it since most people don't display or again verify key change messages. Lastly, most people turn on message backup in Google drive which is not encrypted - so a warrant or an account hack would suffice. WhatsApp implementation can protect basically from malicious non state actors. That's a great thing in today's world in itself but be aware of the underlying tech.