4 ms·
Do they manage the private keys? I always thought that they only managed the public keys. I thought that your backup is stored in iCloud or Google Drive unenc
by calt 5y ago
Do they manage the private keys?
I always thought that they only managed the public keys.
I thought that your backup is stored in iCloud or Google Drive unencrypted. Facebook doesn't have direct access to that. You phone must be already logged in to those services.
- cesarb 5y agoAFAIK, there are two kinds of private keys here. There's one key used to encrypt the backups, which can be either local (on the device) or sent to Google's or Apple's servers; that key is AFAIK kept by Facebook (unlike Signal which asks you to write it down), but it's useless without the backup files, which most probably Facebook cannot access directly. The other key is the ratcheting end-to-end encryption key, and AFAIK that's only kept by the device itself; if you have the right option enabled, you can see whenever someone you're talking to installs WhatsApp or Signal on a new device, since you'll be warned that the key has changed.
- wyldfire 5y agoThey broker the public key exchanges and IIRC the clients trust the broker when it claims that the previous key owner (definitely not Eve) has generated a new keypair. There is a setting (opt-in!) to even see when this occurs but once it does your oh-so-compliant client has already re-encrypted the old messages with the recipient's new pub key and sent them along. This behavior is by design. Some folks will tell me "but it's end-to-end!" and it feels kinda like they're telling me that it's "what plants crave." EDIT: if you don't believe me, turn on the setting, have a friend reinstall the app and watch the re-keying happen. It's indistinguishable from an attack unless you trust the broker. If you trust the broker, then why claim it's "end to end"? Also refer to the various articles that describe this behavior that WhatsApp says is by design. Double EDIT: why is it this way by design? Because it would be a PITA if every time you replaced your lost phone your buddies got a warning that looked like "Either Dave has got a new phone or the NSA is attacking you. Resend ten years of hilarious memes and intimate conversations to whoever is on the other end?" Real cryptography comes with real inconveniences when you lose your keys. It's the same kind of headache with securing cryptocoins - if you lose the secrets you lose the money. Trusting an agent is the only way to escape, but it comes at a significant cost. Cryptocoin custodians like exchanges get attacked all the time. And communication broker/relays get lawful intercepts all the time.
- cesarb 5y ago> Resend ten years of hilarious memes and intimate conversations to whoever is on the other end? AFAIK, it won't resend already received messages; if the other end didn't have a backup, these ten years of old messages are lost for that end. I don't know whether it will resend sent but not yet received messages, and it certainly will use the new key for new messages (but at that point, you already received the "key changed" alert).