5 ms·
Yeah, it is likely that he was just checking up on the competition. I wouldn't be surprised if turned the narrative on this by saying something like the followi
by deadmutex 6y ago
Yeah, it is likely that he was just checking up on the competition. I wouldn't be surprised if turned the narrative on this by saying something like the following:
"I was curious to check it out.. it wasn't very good, so I reverted back to Messenger/Whatsapp."
IIRC, he made similar comments when he was spotted using G+.
Disclaimer: My views are my own (and not necessarily shared by my employers).
- uoaei 6y agoIt doesn't seem like you are aware that WhatsApp hired Moxie Marlinspike, the creator of the Signal encryption protocol, to re-implement it for WhatsApp. AFAIK it is still used in WhatsApp today. I will take this moment also to mention that "re-implement" isn't exactly right in that they modified the protocol slightly to allow for someone in control of the administration server to change a user's private key without their knowing, so that the admin can decrypt the E2E communications using the known key.
- 7a1c9427 6y ago> I will take this moment also to mention that "re-implement" isn't exactly right in that they modified the protocol slightly to allow for someone in control of the administration server to change a user's private key without their knowing, so that the admin can decrypt the E2E communications using the known key. Do you have a source for that claim?
- secfirstmd 6y agoYeh that's a big claim. Love to know source
- EGreg 6y agoI would also like to mention that information is encrypted and cannot be proven.
- lxgr 6y agoGP is probably referring to this: https://boelter.blog/2016/04/whats-app-retransmission-vulnerability/ https://boelter.blog/2016/04/whats-app-retransmission-vulner...
- 7a1c9427 6y agoI think that is a very charitable assumption about the GP claim. The linked article describes a very specific implementation vulnerability around handling of offline messages that would appear to be routed in user experience being ranked higher than operational security by WhatsApp (understandably). In this case it also does notify the user once they are online, and the original phone is logged out alerting the compromised user. The GP claim is far broader that all E2E communication can be compromised without user awareness permitting ongoing communication between two unaware parties to be monitored.
- uoaei 6y ago> I think that is a very charitable assumption about the GP claim. The linked article describes a very specific implementation vulnerability around handling of offline messages that would appear to be routed in user experience being ranked higher than operational security by WhatsApp (understandably). Both points (security vulnerability and user experience prioritization) can be true simultaneously. This is the root of all plausible deniability when it comes to installing vulnerabilities in technologies. I don't see why we should care at all about WhatsApp's intentions with the change when the effects are so pernicious. Facebook et al. definitely do not deserve the benefit of our doubt anymore.
- 7a1c9427 6y agoThis is true. But I would suggest your operational security has bigger issues than this potential vulnerability if you are using WhatsApp. Regardless - you still haven't given a source for you original claim. "not deserving benefit of the doubt" does not qualify. If the linked article is in fact you source then in the future please do not exaggerate such claims as you have done. I would have expected a claim from the article to read (along with a link to the source!): > WhatsApp have modified the protocol slightly auspiciously for user experience but this allows a third party attacker to intercept messages sent offline only alerting the sender after they have been disclosed.
- anticensor 6y ago> they modified the protocol slightly to allow for someone in control of the administration server to change a user's private key without their knowing, so that the admin can decrypt the E2E communications using the known key. You mean, no-longer-E2EE.
- Grustaf 6y ago> Disclaimer: My views are my own (and not necessarily shared by my employers). Who is your employer? It's not mentioned in your profile...
- rataata_jr 6y agoMaybe its mentioned in one of his earlier comments on this platform.
- 908B64B197 6y agoWhat are the odds that Zuckerberg knows a lot of people in the tech business and some of them are Signal users?