4 ms·
Closed source WhatsApp is a problem. And a backdoor is possible. However, it's still detectable, albeit not easily. I'm sure researchers are closely looking at
by ash 6y ago
Closed source WhatsApp is a problem. And a backdoor is possible. However, it's still detectable, albeit not easily. I'm sure researchers are closely looking at WhatsApp binaries. WhatsApp backdoor would be a scandal.
Sure, open source WhatsApp would be better. However, we are comparing detectable potential backdoor with totally undetectable existing access to all non E2E chats on Telegram servers. Telegram developers can already see everything right now. (By the way, opt-in E2E encryption is almost useless. Encryption should be the default, and enabled for group chats too.)
Between these two options WhatsApp situation is clearly better.
- AndriyKunitsyn 6y agoYour comment is based on two assumptions: - That backdoors are routinely detectable in closed-source applications. They are not just "not easily" detectable, they are impossible to detect without a good amount of luck, and even so, the knowledge about a new backdoor will come after years, after all of the damage was done. Numerous discovered RCEs in Windows, some of which laid there for more than a decade after being found, confirm this. - That there are incentives for security researchers to routinely disassemble WhatsApp binary and provide results of their inspection to the public, and not just report to employers or use the knowledge about a Facebook-authored backdoor to blackmail Facebook. There are none. If you discard these two assumptions, you can see that Telegram model is better because it gives users clear choice between passing data to Telegram (in exchange for chat sync) and using E2E, with strong guarantees of E2E that are backed by reproducible builds, not by trusting Facebook or "oh, but that would be a scandal". The "almost useless" E2E of Telegram (I don't see how it's almost useless, it's there, it's working, and it provides value for users) is better than the completely useless E2E of WhatsApp. (But yeah, group chats have no option of E2E in Telegram, that sucks.)
- ash 6y agoThank you for summarizing my assumptions, but it was not fully correct: - I'm not saying backdoors are "routinely" detectable, I'm simply saying it's possible to detect them. In contrast, we have zero possibility to find out if Telegram is doing something nasty with your chats. Telegram may well do it already, and we may never learn. - Regarding the incentives - security researchers often disclose vulnerabilities to the public. Obviously they have the incentives to do it. As for the optional nature of Telegram E2E encryption - Signal and WhatsApp successfully demonstrated it's possible to make E2E the default (and only) option. There's no competition here. I wonder what proportion of Telegram users understand the ramifications. Many people migrating from WhatsApp to Telegram probably don't.