4 ms·
I'm stepping out of my domain knowledge on this one to start a discussion, I hope to have my points corrected where I'm wrong. Another note, I'm not advocating
by Timpy 6y ago
I'm stepping out of my domain knowledge on this one to start a discussion, I hope to have my points corrected where I'm wrong. Another note, I'm not advocating for FB's methods I'm strictly interested in some cryptography aspects.
As I understand it, in order to have real end-to-end encryption (the real stuff, not some marketing term) each device has to generate a long set of keys and with each message sent, they cycle through to the next key. If WhatsApp is doing what it reports it's doing and it actually is end-to-end encrypted then the web application needs to use your phone because it needs that set of keys. I'm not sure if it specifically sends through your phone or if it sends via the webapp, but you have to use the keys in the correct order or the device you're contacting won't be able to decrypt the next message.
- rkangel 6y agoYes, WhatsApp is doing encryption that is E2E between two devices. That's a good security model. There's no particular reason that that has to be two phones though - could be desktop, wifi tablet etc.. That limitation is a result of a 'product' decision where your identity on WhatsApp is a mobile phone number. That decision was a big part of what allowed WhatsApp to scale quickly (people didn't need to create an account, just install the app and start messaging people whose numbers they had).
- joshspankit 6y agoExactly to the point: They can implement E2E encryption in-browser, on dedicated desktop apps, with supported routers, and basically anywhere. Even $5 microcontrollers can generate and use the same encryption protocol.
- evgen 6y agoBut they don't because modern phones have (semi-)secure enclaves that can hold encryption keys and protect them from most hacking attempts. Desktops and browsers lack this, so any conversation you have via these other platforms in the computing environments of 99.999% of the population (please spare me the 'I use qubes, so ha!' speech) has a much lower level of security/privacy. Since most people want conversation sync among the desktop and mobile versions this means your security drops to become the lowest common denominator among all platforms. It can be done, but it shouldn't be done if you actually care about security or privacy.
- joshspankit 6y agoThere are valid arguments on all sides of this: - That desktop browsers can be less secure - That software can work around that - That mobile can be more secure - That mobile can also be false security as "0 days" are currently in the wild and mobile phones are typically always online - Etc. If you truly want security, there's a really compelling argument for live-booting a distro like https://tails.boum.org/ https://tails.boum.org/ and then rebooting when you're done. On the other side there are compelling phones such as the Libre 5 (assuming there are no current 0 days).
- evgen 6y agoTails and purism phones are the same 'I run qubes' fantasy that I expressly ignored. No one uses these, and they are not going to ever use those systems. There are fewer 0-days and CVEs in the mobile environment and for at least the next five years or so the mobile environment will always be more secure than desktops. Right now the single biggest step any 'normal' person can take to secure their digital life is to throw out their desktop and live completely on mobile devices and consoles for gaming.
- lukeschlather 6y agoUnless you're buying a new flagship every 2 years you're probably not meaningfully more secure than you would be on a desktop. And buying a new flagship every two years is probably less realistic for most people than running purism or Tails. Those at least only will cost you time.
- Closi 6y agoAn additional product decision would be that I will assume headaches are caused if a user starts on desktop and then decides to move to mobile (Your PC must be on in order to use this mobile app!).
- kevincox 6y agoThe real solution here is to generate a second key for (or securely transmit the original key to) the mobile device. Now the PC needs to be on to set up the second device. Once online they are completely independent. However whatsapp currently assumes that each user has one (primary) device and only handles encryption and delivery to one device. It isn't impossible to fix (example Matrix) but it does require effort and slightly more server resources (you need to store messages for longer on average)
- arximboldi 6y agoThey could allow you to login without a smartphone using a SMS confirmation code, as many other services do. But I guess they consider dumbphone users with computers too much of a niche.