4 ms·
During 2021.
by Legogris 5y ago
During 2021.
- lifty 5y agoRegardless of e2ee, they might have code bundled in the WhatsApp app that just deletes local video messages based on a hash. That wouldn’t break encryption.
- Legogris 5y agoIt was an event link, think: > The event next week: > https://.... (Neither of us remember if those two lines were distinct messages or two lines in the same message; regardless, neither is there anymore)
- tffgg 5y agoSame message doesn't mean same hash. Usually a nonce is used and if not: WhatsApp uses the Signal Protocol, which uses different keys for each message
- jeroenhd 5y agoThe client can delete the message if the decrypted hash matches a certain blacklist. It doesn't have to happen on the FB servers. Such a mechanism allows governments to turn WhatsApp into a propaganda machine very easily, though, so I'm not sure if I would consider such a mechanism for my app if I were in a similar position.
- tutfbhuf 5y agoYou cannot and should not be able to use a hash or rainbow table for encrypted messages. If that is possible (you don't use a nonce), then your encryption is broken since many common messages can be looked up in a rainbow table and you can use replay attacks.
- mimi89999 5y agoThat would have to happen on the device before encryption or after decryption.
- Mindwipe 5y agoWhatapp's client applications already do this before encryption to check against a list of hashes of child abuse material.
- tutfbhuf 5y agoThis is of course great, but such hash based filters for images or videos can be circumvented easily by just flipping one bit (without corrupting the file). I guess what we really need is some kind of ML trained filter that has a great rate of success and a very low false positive rate.