8 ms·
WhatsApp Security Advisories
- muxator 6y ago> We do not store private messages on our servers _once we deliver them_ Doesn't this mean that messages exist in plaintext on Facebook's servers for at least the time it takes to deliver them? To me this is equal to saying that everything is clear text anyway, since there is no way to ensure someone lawfully or unintentionally taps the text stream and diverts it somewhere. Am I misunderstanding?
- AaronFriel 6y agoI think what they're saying, and they ought to clarify this, is that they don't store unencrypted messages, and they may temporarily store encrypted messages as part of the Signal protocol to deliver them later.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- SQueeeeeL 6y agoI was going to write a snarky remark about how WhatsApp doesn't promise to be E2E encrypted, but it totally does https://faq.whatsapp.com/general/security-and-privacy/end-to-end-encryption/?lang=en https://faq.whatsapp.com/general/security-and-privacy/end-to... . Maybe they just store the hash? Definitely sounds shady
- vel0city 6y agoWhen you send someone a message, you upload the encrypted message to the server addressed for them. The user checks in with the server asking "any messages for me?" The server then delivers the message and deletes its cache of messages. The server "stores" the message for that period of time when the user uploaded it and before the receiver confirmed the download. Allegedly, it stores it in the encrypted form as its advertised as end to end so they would not have the key to decrypt it.
- TwoBit 6y agoProbably just means the encrypted messages are in holding on the server until delivered. There's not much alternative to that unless peers are enabled to talk directly to each other, which would likely be a poor experience due to reliability and connectivity issues.
- vlovich123 6y agoIt would probably be much more ideal to have peers send messages to each other directly & only use the server for store + forward if the send fails.
- deleted 6y ago[deleted]
- bzb5 6y agoIt is not the nineties anymore, everybody is behind at least one NAT. Especially mobile phones.
- cesarb 6y agoOn the other hand, mobile phones often also have an IPv6 address, which is not behind a NAT.
- GekkePrutser 6y agoIt would be good in some ways but could cause tracking by malicious peers by becoming aware of the target's ip address
- danielheath 6y agoThat assumes that you want your phone radio running at full power 100% of the time, which would drain your battery in about 2 hours.
- paxys 6y agoTrue P2P isn't really possible today in the vast majority of ISP networks (especially mobile ones), so at most traffic will be relayed by a TURN server which is also centralized.
- josalhor 6y agoI think you're misunderstanding. Storing a message does not imply storing it in plaintext. In fact, the previous paragraph talks about E2E encryption.
- saagarjha 6y agoI think the interpretation is meant to be "we store private messages and we stop storing them after delivering them" rather than "we make them not private before delivering them".
- fareesh 6y ago"We do not store private messages on our servers" Are all messages "private" messages? Or is this intended to distinguish group chats from one-to-one chats?
- ianlevesque 6y agoIt’s fully documented: https://faq.whatsapp.com/general/security-and-privacy/end-to-end-encryption/ https://faq.whatsapp.com/general/security-and-privacy/end-to...
- saagarjha 6y ago> Due to the policies and practices of app stores, we cannot always list security advisories within app release notes. Yeah, right. Here's your three latest release notes for the iOS app: 2.20.92 Aug 25, 2020 Bug fixes. 2.20.91 Aug 24, 2020 Bug fixes. 2.20.90 Aug 19, 2020 Bug fixes. Surely you can do better than that?
- amatecha 6y agoIMO these walled-garden app stores that are supposed to be "so good for the users" should require quality release notes that describe the exact "performance improvements and bug fixes" that the respective apps apparently receive.
- dudus 6y agoI'm on the other end of the spectrum. Since the updates are constant, often required and automatic it makes little sense to provide these in the store itself. The user doesn't really have a choice of not updating most of the time. It's not a decision they should make I'd rather see release notes outside the stores, for more technically inclined users only.
- iso8859-1 6y agoUsers would be scared by reading technically accurate release notes. So for apps as ubiquitous as WhatsApp, it makes sense to have two kinds of release notes, one for techies, and one for commoners, who only want to know whether features were added or not.
- bzb5 6y agoWhat surprises me about the list of CVEs is how many of them affect both Android and iOS. One would assume they are two completely independent codebases.
- infogulch 6y agoIt could be a bug in the spec.
- rachelbythebay 6y agohttps://news.ycombinator.com/item?id=11599617 https://news.ycombinator.com/item?id=11599617 Not saying it's being used here (I honestly have no idea), but it's not that much of a stretch.
- IncludeSecurity 6y agoMany mobile apps rely on shared components/libs/frameworks that are either developed by the company or are FOSS (libpl_droidsonroids_gif for example). In either case...they are platform agnostic and usually written in C. And as we all know C is full of memory handling problems like overflows. Hopefully in 2020 and beyond people will be developing these shared components in Rust instead.
- laingc 6y agoThis thread thus far has a ton of comments from people who haven't bothered to actually read anything about how WhatsApp works, or how the Signal protocol works. It would make for a better comment thread if everyone did that prior to expressing an opinion.
- dijit 6y agoThis kind of snide comment gets upvoted because everyone sees it as a way of looking down on the 'other comments'. If you have something specific to say to each of the people who "didn't read the spec" then please respond to those people with that, instead of making passive aggressive commentary and making us assume the worst in everyone else in the comments.
- floatingatoll 6y agoIt's completely appropriate to ask the HN community to do more work before posting, instead of posting opinions that haven't been checked against reality. The mods use this same approach when advising us to act better: a single top-level comment, discussing a common misbehavior and asking for it to stop. We should aspire to be a better community, but individually chastising tens of comments for posting unfounded and repetitive comments would pollute the discussion with needless repetition of the same core point.
- nateberkopec 6y agoWhy was this submitted? The newest WhatsApp CVE is more than 6 months old.
- rocqua 6y agohttps://nvd.nist.gov/vuln/detail/CVE-2020-1894 https://nvd.nist.gov/vuln/detail/CVE-2020-1894 This was yesterday I think? With code-exec through a stack over flow in push to talk. Unless the date-format is out of whack. and 09/03 is 9 march not 3 september
- ccktlmazeltov 6y agodepends if it's the American date format or the rest-of-the-wold date format
- crtasm 6y ago> If you lose access to your WhatsApp account, the messages you previously received will remain on your phone and will not be available elsewhere. As I understand it, if you give in to the android app's repeated prompts to enable backing up to your google account then your messages are stored elsewhere, and without encryption. Could someone confirm if this is still the case?
- paxys 6y agoThat is correct. Same for iCloud backup on iPhones.
- deleted 6y ago[deleted]
- floatingatoll 6y agoCVE numbers are not guaranteed to be issued sequentially by the CVE organization, and not all vendors issue numerically sequential blocks of CVEs.