12 ms·
What is traceability and why does WhatsApp oppose it?
- eric__cartman 5y agoFacebook talking about respecting human rights and privacy... If you want to make a truly secure messaging platform release the client and server side source code or gtfo.
- bilbo0s 5y agoSometimes I wonder if "truly secure" messaging platform and "internet" messaging platform are incompatible. Is the reality that any internet based digital messaging platform is insecure in the long term. Eventually, your messages can be retrieved, traced, even tracked real time. I think if your information needs security, don't put that information on the internet.
- justin_oaks 5y agoThe biggest obstacle to secure messaging is making it friendly to users. All popular end-to-end encrypted messengers manage user's public keys for them. And usually provide the client code too. And may have unencrypted backups. And may have account recovery mechanisms that can be abused. Each of those makes it easy for the user, but degrades security.
- Ellipse0934 5y agoEven if they release their server side source code how can you ensure that the deployed version matches the source ? Eventually there is always a thread of trust. The point however is that the government of India is forcing private corporations to break privacy related measures to suppress civil liberties.
- pointless123 5y agoSo elected govs should listen to corporations. no thanks. i can over throw my gov but not evil facebook
- varispeed 5y agoYou could host software yourself and communicate within your circle only. It seems like this may be the future - someone just has to make it easy for people to create groups that will deploy the server and generate the app. But that would be a matter of time when governments will start to regulate hosting providers and e.g. banning hosting of communication servers.
- axiosgunnar 5y agoI hate Facebook as much as anyone here on HN, but the enemy of my enemy is my friend. If keeping end-to-end-encryption also happens to be in the interest of some faceless multinational corporation, we can use their resources in this fight. We can go back to fighting Facebook once this is over.
- wizzwizz4 5y agoFacebook's big enough that we don't even have to stop fighting them while we support them in this endeavour.
- capableweb 5y agoThis is something I don't understand that continues to happen in politics, technology and many other facets of life. Why do you have to either fully support or fully be against a entity? You can selectively like some things someone does while not liking other things they do, same goes for corporations. You also don't have to justify bad things by listing good things they've also done, you can just like the good thing and hate the bad thing. People are so black and white. Don't think it's a new thing, but the internet has made it very popular to be black and white in our thinking.
- Ellipse0934 5y agoMost political systems tend to converge into a two-party system. I think the internet has made people more vocal but access to opposing and nuanced viewpoints has made a lot of people grey. I know that's the case for me, not sure if it encapsulates the majority.
- Koenvh 5y agoDo you have a source for that? Coming from a country where there are 16 different parties in parliament (the Netherlands), neighboured by two countries which each have at least five parties in parliament (Belgium and Germany), I find that statement difficult to believe.
- nashashmi 5y agoI dont see the argument posed here. If a user sends a new message to 2nd user, and 2nd user forwards the message to a government agent, and agent asks for the origin of the message, there is a way to both encrypt the message and trace it. It's called convergent encryption. And I thought this was how whatsapp was tracking messages that were forwarded multiple times. By checking their base hash.
- nashashmi 5y agoFYI convergent encryption is hashing the original message, using hash as key to encrypt message, and sending hash key to user via 2nd encryption. The hash encrypted message will generate a second hash which will be used to track the spread of a message.
- baby 5y agoInteresting, do you have resources to learn more on that?
- nashashmi 5y agohttps://en.wikipedia.org/wiki/Convergent_encryption https://en.wikipedia.org/wiki/Convergent_encryption
- dman 5y agoAs a user I find this section very intriguing. ************************* "Can WhatsApp work with law enforcement without traceability? WhatsApp respects the important work law enforcement does to keep people safe. Our dedicated team reviews and responds to valid law enforcement requests. We respond to valid requests by providing the limited categories of information available to us, consistent with applicable law and policy. We also have a team devoted to assisting law enforcement 24/7 with emergencies involving imminent harm or risk of death or serious physical injury. We consistently receive feedback from law enforcement that our responses to requests help solve crimes and bring people to justice. It’s also important to understand that depending upon the nature of their investigations, law enforcement officials have multiple investigative tools, and may obtain information from many sources, including different companies, other governments, or from users’ devices. More information about how we work with law enforcement can be found here." ************************* Can Facebook clarify what these limited categories of information are? While reading this article I had the following reaction - Facebook would like to prevent traceability to preserve user privacy. That makes complete sense. Oh wait - they say they do have means of helping law enforcement and governments, wait a minute, in a fully encrypted system end to end how are they able to help governments in emergencies at all? So my question here is that in a hypothetical scenario where terrorists are using whatsapp to coordinate an evil plot, which to most people would fit a scenario where Facebook can and should help the government - what is it that Facebook can do to help a government? The only way I can see them being able to help the government is if they have the ability to selectively turn off end to end encryption for specific numbers (probably based on a warrant from a court). Will Facebook confirm if this is the case?
- Cantinflas 5y agoNo need to break end to end encryption, they already control both ends. And the unencrypted backups
- swiley 5y agoThis is something people are just not talking about for some reason. WhatsApp/signal style apps cannot be secure to this sort of attack. You would think now that a public mass attack has been successfully carried out (encrochat) people would get it. I don't know if it's submarine marketing or what but people think the current situation is just fine.
- nicoburns 5y agoIt's such a shame that Facebook was allowed to buy WhatsApp (and Instagram). WhatsApp itself seems truly pro-privacy, but that counts for diddly-squat when it's owned by Facebook.
- ProAm 5y agoWhat do you mean 'allowed' (Im not being snarky, honestly curious please take the question as not an attack)? The creators just sold it, private company, private service they could have sold it to anyone they wanted. I think in hindsight they regret selling it to FB, but it's really hard to turn down billions of dollars.
- bidirectional 5y agoM&A is regulated, it's not a totally free market. If company A buys company B, the government allowed them to do so. There are plenty of scenarios where they won't.
- ProAm 5y agoI agree with that but a independent messaging app seems perfectly safe for FB to purchase. Instagram a little different but I never saw the government being concerned or potentially not allow this one to go through. That is why I was curious about the OPs perspective because maybe they did see something (not counting hindsight and that FB is a terrible company, but only in the moment)
- pegasus 5y agoIt's simple: OP's perspective is that even though the purchase was not stopped, it should have been. That to you it seemed a perfectly safe purchase is completely irellevant to his argument.
- ProAm 5y agoI would like to know why he thinks it should have been stopped. At the time of that purchase I think any messaging platform could have been sold to anyone and not been stopped (imo).
- verytrivial 5y agoSlightly off-topic, but for European readers: Is how Facebook is trying to off-load cookie control onto the user's browser configuration anything close to compliant with law? This is the only instance of a company I have seen not bothering with 'Accept' vs some other complicated choice dialog (and I only saw this because I was annoyed by WhatsApp forcing the TOS change and, lo, they seem to be forcing 'Allow all' for cookies too?)
- deleted 5y ago[deleted]
- Havoc 5y agoYes, same here.
- smichel17 5y agoTelling my browser my privacy preferences and then requiring sites to follow that seems like the holy grail of privacy to me. Next up: Do Not Track. If it's set, skip the dialog and follow my preference instead. Along with that, browsers should make it into a drop-down with [do not track | do track | do not express a preference], so that people who prefer personalization also don't need to suffer the dialogs.
- choeger 5y agoCompanies like Facebook have a very simple way to protest the current crypto laws. They could publicly announce they are going to disable any crypto for each and every politician and their family members when they vote or act against it.
- carlob 5y agoI don't think any politician worth their salt uses whatsapp, not even for private communication.
- GekkePrutser 5y agoYou'd be surprised... I know most higher-up people, even the ones in tech who should really know better, still make very questionable decisions around digital security. Often totally in breach of policy they themselves introduced. And get away with it due to their leverage. I worked in IT a long time and it's been so many times that I saw the 'please turn off the annoying security restrictions for us, we're the bosses so we know better' coming around. They often have a huge security awareness gap: themselves. Though to be fair: Most of us have that gap. I know I do. But they have the clout to override policy. Don't expect someone to be sensible just because they're at the top somewhere.
- Ellipse0934 5y agoCan't whatsapp pull off a big brain time and disallow forwarding ? Then users must copy and paste messages, links and media. Hence every message is a source message.
- spoonjim 5y agoThe "Forwarded" note helps identify misinformation. If there's a message that says "2 Muslims came to my house yesterday, stole my baby, and ate her" and it comes from your friend you might actually believe it. If it says "Forwarded" you have a better signal that it's fake.
- bgdam 5y agoThe same 'Forwarded' tag can be easily attached to a message that is copy-pasted verbatim (atleast from another whatsapp message). Anecdotal evidence suggests that 'Forwarding' is just way too easy as compared to copy pasting an entire message to each person you want to send to. So forcing people to do this would indeed reduce the amount of misinformation being spread via unvetted forwards (at the cost of 'valid' forward messages - which I think are too few to matter).
- elzbardico 5y agoGonna start using plain old letters. At least the government needs a court order to open it.
- dt3ft 5y agoDon't be so sure they even have to open it... (https://abcnews.go.com/Technology/scientists-read-300-year-letters-opening/story?id=76284416 https://abcnews.go.com/Technology/scientists-read-300-year-l...)
- unyttigfjelltol 5y agoThat's akin to x-raying a package. If they could instead just sniff the contents, you might, or might not, be onto something.
- ytpete 5y agoThat kind of "search" might still need a warrant. For example, there was a court decision some years ago which determined that using IR cameras to detect marijuana grow lights inside a home requires a warrant, since people have an expectation of privacy that no one can see through their walls. IANAL so I'm not sure whether expectations of privacy for letters are legally as strong as they are your own home, but it certainly seems possible...
- yawaworht1978 5y agoIndeed, if you have something to hide, do not use a mobile phone. E2E chat will only help to keep the messaging hidden. If you have a keylogger on the device, you have lost. In other words, whether or not WhatsApp opposes traceability or not does not matter an iota.
- variable11 5y agoWhatsapp managers and engineers belong in prison for multiple violations of privacy laws and data theft across the globe. You are criminals.
- anti-nazi 5y agothey definitely don't oppose traceability, this is just a marketing scheme
- Havoc 5y agoWTF is going on with their cookie dialog? Surely that's not even remotely legal? There is just agree and a second dialog with guidance on how to clear cookies per browser (???) and a second agree button. That's not even an attempt at a dark pattern nudging you towards one option...it's just do you agree or do you agree. Hard to trust companies that think that's how consent works... https://imgur.com/a/Ya1XBvG https://imgur.com/a/Ya1XBvG
- Y-bar 5y agoI can’t see how that is acceptable in EU. For example Max Schrems has this to say about these dark pattens: https://noyb.eu/en/noyb-aims-end-cookie-banner-terror-and-issues-more-500-gdpr-complaints https://noyb.eu/en/noyb-aims-end-cookie-banner-terror-and-is...
- GekkePrutser 5y agoHe's doing great work for sure!
- iggldiggl 5y agoFacebook's own dialogue is relatively similar – you do get one option for Facebook's own advertising tracking and another for every third-party function mushed together (no differentiation between functional, analytical, advertising, etc.), but in the end no matter what you choose there's still only one 'Accept cookies' button.
- eli 5y agoI mean, it needs at least a session cookie to keep track of your login, right?
- steelbrain 5y ago"Essential Cookies" in EU don't need a prompt. How Github got rid of the cookie banner: https://github.blog/2020-12-17-no-cookie-for-you/ https://github.blog/2020-12-17-no-cookie-for-you/
- yig 5y agoCan't traceability be implemented with digital signatures? WhatsApp could sign my messages with my encryption key and always forward messages with their original signatures as metadata. Wouldn't that implement traceability? I guess that's the "fingerprint" this article alludes to. I don't see the technical limitation, just a policy one. WhatsApp wouldn't need a centralized store of all messages.
- jangid 5y agoWhatsApp should give an option to upload my public-key. I want to generate public key on my computer using some other free software. For non-tech users, they may keep generating keys however they want. But there should be an option. That is the only way to guarantee that it really supports privacy.