8 ms·
We were surprised to read this story and are not aware of discussions that would force us to change our product. We believe people have a fundamental right to
by wcathcart 7y ago
We were surprised to read this story and are not aware of discussions that would force us to change our product.
We believe people have a fundamental right to have private conversations. End-to-end encryption protects that right for over a billion people every day.
We will always oppose government attempts to build backdoors because they would weaken the security of everyone who uses WhatsApp including governments themselves. In times like these we must stand up both for the security and the privacy of our users everywhere. We will continue do so.
Will, Head of WhatsApp
- spuz 7y agoSo are you saying the backdoors will or won't be introduced to WhatsApp?
- wcathcart 7y agoWill not. We are completely opposed to this. Backdoors are a horrible idea and any government who suggests them is proposing weakening the security and privacy of everyone.
- spuz 7y agoThanks.
- benevol 7y agoAs much as would like to believe all promises coming from corporate execs - Facebook has been caught lying more than enough. So thanks for trying, but I have uninstalled WhatsApp and I'm happy with Threema.
- ripdog 7y agoHave you considered Riot (Matrix) or Signal? Both are open source so it's possible to verify claims made on their website, which is a lot less possible with proprietary software like Threema.
- ttctciyf 7y agoAnd with Matrix apps you can choose to run your own server. Not sure what legal ramifications that has, but practically speaking it allows the possibility of eliminating another potential weakness.
- spac 7y ago... but probably opening many new ones, unless one has a really strong security team in place.
- feanaro 7y agoThese vulnerabilities would then at least be bespoke, particular to a specific server, preventing mass surveillance. At least if you're not talking about potential vulnerabilities in synapse (Matrix server software), but then a strong security team wouldn't help that much.
- mirimir 7y agoThanks for the clarity. So will WhatsApp refuse to comply, if this goes forward? And is that even possible? I do appreciate that Facebook has the resources to fight. To fight an NSL, even. But IANAL, and have no clue.
- vuln 7y agoFacebook give the government this and the government in acts regulations to “protect” Facebook. I’m sure Facebook is salivating at the thought at getting even more access to your sensitive data. Once the backdoor is installed who knows who’ll have access.
- deleted 7y ago[deleted]
- badrabbit 7y agoWill you pull out of UK and US? Seems very unrealistic. You have no choice but to obey the law,even if the law is ridiculous. Have you considered architectural changes that will allow for the app to be compiled and deployed by an affiliate corp outside of these jurisdictions?
- marmaduke 7y agoWill you have something like a warrant canary [1] to let users know in case there ever is a compromise of security? [1] https://en.wikipedia.org/wiki/Warrant_canary https://en.wikipedia.org/wiki/Warrant_canary
- deleted 7y ago[deleted]
- soulofmischief 7y agoA warrant canary isn't proof of anything.
- conanbatt 7y agoA lack of one is.
- Spare_account 7y agoI've often wondered whether or not a sufficiently well worded warrant could require that the warrant canary remains published unchanged, rendering the warrant canary useless.
- drdaeman 7y agoThe idea behind the canaries is that they expire, and that one cannot legally force someone to sign false statements. So if no new canary is published when the old one expires, that's a red flag.
- gvfff 7y agoPlease. A receipt for a $10 wrench and any IT guy will crumble. That wouldn’t even be illegal, since they never hit you with a wrench - you just imagined they were about to go xkcd on you
- aoeusnth1 7y ago
- technics256 7y agoDo you currently have any backdoors installed?
- wcathcart 7y agoWe do not. You don't have to take our word on this -- I wouldn't want you to. As others on this thread have pointed out it's possible enough to tear through our binaries that if we did have a backdoor it would be discovered.
- huhtenberg 7y ago> it's possible enough to tear through our binaries No, it's not "possible enough" and I strongly suspect you fully realize that. A backdoor doesn't need to be in a form of an IF statement or something comparably obvious and silly. It can be a weakly seeded PRNG that would allow a "determined party" to brute-force the key exchange in a reasonable time. That would take man-years to fish out from a binary, and that's without considering that you may (be forced to) distribute an altered binary on demand and to specific targets only. So in the end all we have - realistically - is in fact just your word. There's no way for you to prove that you are trustworthy by pointing at some random binary. The only option is to distribute reproducible builds from an audited open source.
- buzzert 7y agoI disagree that it would take man-years to fish that out from a binary. Black hat and white hat hackers do this all the time.
- londons_explore 7y agoI agree. The crypto used is industry standard, and the actual process all the way from random number generation to deriving a key is relatively easy to follow. Active ways to attack the client to make it leak the key are far more worrying - but even an open source project wouldn't protect against that.
- rdl 7y agoIf so, sounds like someone from FB Legal and the SEC should have Words with Bloomberg. Wouldn't be the first time they've intentionally maliciously misrepresented/lied about an infosec issue to the detriment of a company in order to move the market (Supermicro "grain of rice"...)
- mapgrep 7y agoIf you read the (short) story to the end, you will see it was first reported by the New York Times.
- dbbk 7y agoThe reporting is accurate.
- 2arrs2ells 7y agoLooks like more crappy security reporting from Bloomberg: https://twitter.com/alexstamos/status/1178308065268920320 https://twitter.com/alexstamos/status/1178308065268920320
- wruza 7y agoIs it true for US or for every country? How does WhatsApp legally operate in Russia?
- wcathcart 7y agoIt's true in every country. We are a global service, and our policy on backdoors is the same everywhere: we do not have them and we vigorously oppose them. Sometimes this leads to us being blocked. We were blocked in Brazil, for example, but that block was overturned in the courts.
- wruza 7y agoThanks! What is your opinion on a rumor that FSB doesn’t have any complaints because they found unintentional/unknown vulnerability that allows them to read WhatsApp messages? Should WhatsApp users be concerned about that?
- e12e 7y agoWe do know that phones and tablets are vulnerable - so it's not like we're unaware of any backdoor that may also be used to subvert whatsapp. It'd indeed be interesting to know if the FSB had some kind of baseband vulnerability that they'd used willy-nilly to facilitate dragnet surveillance. I suspect William Binney was right though - blanket surveillance is just expensive and hides your needles in a mountain of hay; you really want high quality in the data you store in order to ease extraction of meaningful information / intelligence. (that's not to say that aggregate meta data isn't interesting - just that with actual content noise is a problem)
- alfiedotwtf 7y agoThanks for your words, but unfortunately I think your hands are tied on this one. Australia was the first pin to fall within then Five Eyes, and I think the rest will soon follow.
- CriticalCathed 7y agoGlad you have the packs of the people when the Government doesn't.
- snissn 7y ago"are not aware of discussions that would force us to change our product." It reads like your product is already compatible with govt ease dropping
- samstave 7y ago>people have the fundamental right to have private conversations Any comment on this? https://www.theguardian.com/world/2013/sep/11/nsa-americans-personal-data-israel-documents https://www.theguardian.com/world/2013/sep/11/nsa-americans-...
- nubela 7y agoAnd? That is what you feel. What guarantees do we have?
- deleted 7y ago[deleted]
- 100tarik 7y agoKeep the government out, we do not live in China. Priti Patel is trying to create a name for her self, using children as excuse
- hassanim 7y agoPerhaps, but that legal theory has never been tested in US federal court (as far as we know). It's entirely possible that the judicial branch wouldn't allow the executive branch to force private citizens into actively making false statements. Hassan https://www.clipart.email/ https://www.clipart.email/