9 ms·
WhatsApp – Security of End-to-End Encrypted Backups [pdf]
- pgalvin 5y agoHelpfully given in the introduction, here is some useful context for this change in case some people miss this part: > Since 2016, all personal messages, calls, video chats and media sent on WhatsApp have been end-to-end encrypted. […] > WhatsApp’s backup management relies on mobile device cloud partners, such as Apple and Google, to store backups of the WhatsApp data (chat messages, photos, etc ) in Apple iCloud or Google Drive. Prior to the introduction of end-to-end encrypted backups, backups stored on Apple iCloud and Google Drive were not protected by WhatsApp’s end-to-end encryption. Now we are offering the ability to secure your backups with end-to-end encryption before they are uploaded to these cloud services.
- beagle3 5y agoIt used to be encrypted before upload to google, and then … one day it just wasn’t (but came with the “candy” that it no longer counts against your account quota). I could never found any explanation for this, best hypothesis I found is that it’s a backdoor for law enforcement without admitting it. I would be surprised, given everything happening in the world today, if the new system does not somehow allow law enforcement to get access (possibly indirectly, through the app giving the key in some weird back channel)
- pgalvin 5y agoFwiw, that “encryption” never used your own key or password. Facebook held the key, Google held the encrypted blob, and I doubt the extra warrant to get data from both companies was a huge hurdle. Definitely was not E2EE before.
- baby 5y agoAh so that's how it worked? I heard that concept once and thought it was a really interesting way to ensure a user wouldn't lose their backup while preventing the company from accessing it.
- beagle3 5y agoThat's correct. And yet ... back then, Google couldn't read your messages; Facebook couldn't read your backup; And hackers or law enforcement would need to both get a copy of the blob from Google and the key from Facebook - not insurmountable, but requiring a lot more work and more likely to raise suspicion. Whereas ... after that change, Google can read your messages, hackers/law-enforcement only need to talk to Google, and yet -- you yourself can't get that backup without impersonating the WhatsApp app to Google Drive; The local backup is still encrypted with a key that only Facebook knows (and would give you, but only if you impersonate the WhatsApp app when talking to Facebook). I've looked for the logic and failed. Only reasons I can find is that FB wants to let Google index your messages behind your back (unlikely) or some plausibly deniable legal backdoor.
- dannyw 5y agoIf you read Texas's antitrust lawsuit against Google, you will see that FB and Google signed an exclusive agreement, where Google gets access to WhatsApp messages stored on Drive in exchange for [redacted]. https://www.theverge.com/2020/12/17/22180258/google-whatsapp-facebook-data-deal-antitrust-case-debunk https://www.theverge.com/2020/12/17/22180258/google-whatsapp...
- jbverschoor 5y agoDeduplication could be a thing
- beagle3 5y agoIncredibly unlikely. The backup is AFAIK an SQLite file that contains the text messages (and indexes, etc). The bigger files - images, videos and voice messages - are not included in that backup, and are backed up independently to Google Photos (and always have been).
- dannyw 5y agoIt's not solely law enforcement. It's a commercial deal. https://www.theverge.com/2020/12/17/22180258/google-whatsapp-facebook-data-deal-antitrust-case-debunk https://www.theverge.com/2020/12/17/22180258/google-whatsapp...
- baby 5y agoAnd that's why I kept saying "no" to the backup requests in WhatsApp.
- sneak 5y agoDoesn't matter; everyone else you talk to on WhatsApp is uploading those same conversations to Apple and Google effectively unencrypted.
- baby 5y agoI mean that's the problem of any protocol in general. Your opsec can be great, but if it relies on someone else's opsec...
- quaintdev 5y agoAnd that is why I dont use WhatsApp. Self hosted matrix is super awesome.
- reginold 5y agoWhat do you do instead? Replies like this I may mistakenly interpret as "doesn't matter, so I'll do nothing about it" which is just an excuse.
- sneak 5y agoI deleted my Facebook, WhatsApp, and Instagram accounts, as well as iMessage/iCloud (same issue, unencrypted backups). I am only reachable via email and Signal. I got my contacts to switch to Signal.
- blackoil 5y agoHow does that solve the problem you mentioned? People on other side still may not be careful with mail/signal data privacy.
- approxim8ion 5y ago
- 5faulker 5y agoStill not total encrypted but getting there.
- inasio 5y agoI'm pretty sure both Apple and Google are very happy with the current state of affairs, this system works great to keep people locked into IOS or Android, as exporting your data is super hard (there were a number of expensive sketchy-looking apps that claimed to be able to do this)
- pgalvin 5y agohttps://wabetainfo.com/how-to-migrate-your-chat-history-from-ios-to-android/ https://wabetainfo.com/how-to-migrate-your-chat-history-from... This is possible now (in one direction, so far).
- blue_rog 5y agoSlight Nitpick: This is only available for Apple to Samsung devices. However, > Unfortunately, it’s still not possible to migrate your chat history [from iOS] to a different Android phone, but WhatsApp is planning this in the future. It’s also not possible to migrate your chat history from Android to iOS right now.
- godelski 5y agoWhy is this being called E2EE? If you're uploading them, shouldn't they be encrypted at rest? Why would we want it decrypted on the other end? I just want to upload an encrypted file that can only be decrypted by my app. No other end.
- Thorrez 5y agoIn this case both ends are you. You could back up on one phone and restore on another. You're right that "E2E" is slightly ambiguous. But "encryption at rest" is even worse in my opinion, since it could just mean that Apple/Google's datacenters have disk encryption with a key they can access.
- godelski 5y agoWell if Facebook is encrypting I'm hoping Apple/Google can't decrypt on their datacenters. That would be really weird. Just with the key that I hold (aka my app account). I've always understood E2EE as an in transit thing or public/private key where it is encrypted till the other end. I definitely want my backups sitting at rest on some server where I have no ends and it is just a loop.
- blackoil 5y agoNext step is who owns the key, if it is FB that kills E2E story. If it is user, they'll forget/lose it, so it doesn't scale to 2B users. Currently Apple/Google are set as the custodians of the key.
- Thorrez 5y agoFrom the pdf, it sounds like the HSM owns the key, and will only give it up if the correct password is provided.
- Thorrez 5y ago>Well if Facebook is encrypting I'm hoping Apple/Google can't decrypt on their datacenters. I was referring to the prior backup scheme where Facebook wasn't encrypting. It could accurately be described as encrypted at rest I think, but yet Google and Apple could read the contents I think. >no ends and it is just a loop. The terminology is getting pretty confusing at this point. I usually think of the ends as the intended parties to look at the data. If there are no ends, then no one will look at the data, meaning the data is useless. Actually if there's no beginning end, there's no one to create the data, so thus the data doesn't even exist.
- pharmakom 5y agoThe data could probably be exfiltrated via WhatsApp web?
- huhtenberg 5y agoThey may say all the right words, but given how Facebook has been consistently behaving with respect to people's privacy, all this e2e goodness amounts to nothing less than an extremely disingenuous and misleading charade. So, yeah, good to know. But, no, still have zero trust in FB's implementation of it and won't touch it with a long pole.
- anaganisk 5y agoWe’re sorry that we have accidentally introduced a bug, which allowed us to mine data and peep into everything.
- ziddoap 5y agoI must say, it is unclear to me why this is being downvoted -- it mirrors my exact reaction. The old saying "Actions speak louder than words" has never been more apt. It was just two days ago that Ars & others ran "WhatsApp "end-to-end encrypted" messages aren't that private after all" [1]. Yet, here we are. It's a strong "No thanks" from me. [1] https://arstechnica.com/gadgets/2021/09/whatsapp-end-to-end-encrypted-messages-arent-that-private-after-all/ https://arstechnica.com/gadgets/2021/09/whatsapp-end-to-end-...
- FiloSottile 5y agoI don’t trust Facebook’s intentions, but WhatsApp has demonstrated consistency in bringing encryption to users. The ProPublica article that the ones you saw are based on was flawed, and has been updated. https://twitter.com/propublica/status/1436054877663375372 https://twitter.com/propublica/status/1436054877663375372
- ziddoap 5y agoThanks for linking that, I had not actually seen the update to it. Of course, if one of the parties in E2EE shares the message it doesn't constitute a 'break' in E2EE. However, what I think was important from the Ars article I linked was this statement: >An "end-to-end" encrypted messaging platform could choose to, for example, perform automated AI-based content scanning of all messages on a device, then forward automatically flagged messages to the platform's cloud for further action. Ultimately, privacy-focused users must rely on policies and platform trust as heavily as they do on technological bullet points. Which doesn't break E2EE technically, but it certainly breaks it in spirit. And yes, I understand that really any application could feasibly implement something like this, it's not in many peoples threat models, etc. However, if I had to bet on which company would implement such a feature, it would be FB. It just felt sort of funny, seeing this only a few days after all of those articles were written. Of course there is no way FB weaved the whole system and documentation together in two days, but I can't help but roll my eyes slightly at the timing of their release.
- 2Gkashmiri 5y agoCool. At least now we can pretend the e2e didn't exist till now on WhatsApp. According to them only. https://jknewsline.com/parras-email-whatsapp-data-to-be-accessed-jk-police-approaches-google/ https://jknewsline.com/parras-email-whatsapp-data-to-be-acce... Here is how political vendetta is taken against people. This news is just a few months old. I am not on WhatsApp for a couple of idealogocal reasons, this being one of them
- Andrew_nenakhov 5y agoIt seems that End-to-end (encryption) is now firmly established as a buzzword. I'm not really a cryptographer, but from what I've gathered from a whitepaper, it's just an encrypted backup with a fancy system that allows users to safely store encryption keys on WhatsApp servers. But of course they have to call it end-to-end because users know it is safe
- baby 5y agoI don't agree, if you were to define end-to-end encrypted backup this is what it would be.
- Andrew_nenakhov 5y agoEnd-to-end encryption is when to entities communicate and establish an encrypted connection between them. In this case one device makes a backup while another might not be even made yet. (Edit: Rephrased for better clarity)
- baby 5y agoI'm not sure what you mean by "while another is not yet even made"
- Andrew_nenakhov 5y agoI mean it literally. It might be not yet even assembled at a factory, not delivered to its destination country and not sold to a user.
- baby 5y agoAh, well that doesn't really matter, you can still see them as two separate participants in an asynchronous protocol.
- Andrew_nenakhov 5y ago
- josh_today 5y agoIs this really end to end encryption?
- Andrew_nenakhov 5y agoTo me it is just an encryption, which isn't bad, but still.
- phreack 5y agoThe worst part is even if you disable automatic backups, which you should, the app will nevertheless force the creation of a backup every day at 2am. And keep 7 days worth of backups at a time. Of every single thing it can gets its hands on. The amount of storage and processing that globally occurs daily due to this, that people neither want nor need, is probably jaw dropping. Many non-tech people I know that are not aware of this have just come to terms with the fact that phone storage just runs out quicker than it did before, and old phones just lag at 2am for mysterious reasons.
- krrrh 5y agoNot to mention that the solution to not uploading over cellular (on iOS at least) reads: > To avoid excessive data charges, connect your phone to Wi-Fi or disable cellular data for iCloud. iPhone Settings > Cellular > iCloud Drive > OFF. Like I have to be inconvenienced when I simply want to grab a pdf from iCloud, just to avoid having a few GB of my data cap used if I happen to be out at 2am.
- john2010 5y agoAutomatic backups do not include any images or videos. They remain just unencrypted. > Many non-tech people I know that are not aware of this have just come to terms with the fact that phone storage just runs out quicker than it did before, and old phones just lag at 2am for mysterious reasons. Non-tech people get pissed when one smiley message is lost. So for all non-hn people automatic backups are a boon. I know this as we run a free repair-cafe - and help people migrate data from old phones.
- deleted 5y ago[deleted]
- leonixyz 5y agoThis is ridicolous, they block the account of people for no reason, making them loose years of messages, and now they come up with encrypted backups... they should focus on improving their support. They have only an email address for support. Try to get your account unblocked if their AI decides to block you. Good luck
- sneak 5y agoYour complete chat history with everyone on WhatsApp, to date, has been provided in basically unencrypted form to Apple and Google by your conversation partners, which means that it is available on demand and without a warrant to US federal authorities via FAA Section 702 (commonly known as PRISM, or FISA). This means that even if you stop using it today, there is a huge wealth of information about your habits, travel, personal identifiers, social graph, location history, and personal thoughts and opinions that will be permanently stored associated with your name. Enabling e2e on backups won't purge this information, especially if it has already been downloaded by USG from Apple/Google. If you want to mitigate this, you basically have to move, replace all your friends/contacts, never go back to the same venues/restaurants/cities, et c, because your existing pattern of life is already archived. Too little, too late.
- prawnsalad 5y agoI think the expectations of e2ee have been greatly stretched in this case. e2ee means that the data is encrypted from device to device only and that's it, from one end to another end. If someone backs up their device in an unencrypted way then thats out of scope for WhatsApp - that's not what e2ee is about. People that expected full at rest encryption (which is what a backup system would include) despite the app never being advertised that way would have always needed a large kick to realise that isn't the case. Encryption is complicated and you can't expect everybody to fully understand what e2ee/at rest/etc really means. This whole situation is a learning experience for everyone and I wouldn't blame WhatsApp for it either. They now know that advertising encryption needs a little more explanation.
- JohnJamesRambo 5y agoDoes anyone have an NSA address users can just send their backups to and cut out the middleman?
- vinay427 5y agoWhatsApp currently handles local backups entirely incompetently and infuriatingly despite claiming (IMO dishonestly) that the feature exists, providing inaccurate and incomplete documentation. This is nice to see, but far too little too late for me to trust the app for longevity. I recently had the issue for the second time of losing over a year of messages due to dysfunctional WhatsApp backups, about which I wrote a blog post of complaints/rants [1]. The user, as far as I can tell at least on Android, currently has no viable option besides uploading their messages, unencrypted, to Google. [1] https://vinayh.com/posts/2021-08-28/ https://vinayh.com/posts/2021-08-28/
- annadane 5y agoTaking bets on how much of this is an ego trip from Zuck to stick it to the Apple people about their child protection controversy "See? We're not like them"
- prirun 5y ago> To decrypt the backup, the key K is needed Thus, to safeguard K in the HSM-based Backup Key Vault, the client performs a registration of K with WhatsApp. > The key to encrypt the backup is secured with a user-provided password. The password is unknown to WhatsApp, the user’s mobile device cloud partners, or any third party. The key is stored in the HSM Backup Key Vault to allow the user to recover the key in the event the device is lost or stolen. The HSM Backup Key Vault is responsible for enforcing password verification attempts and rendering the key permanently inaccessible after a certain number of unsuccessful attempts to access it. These security measures provide protection against brute force attempts to retrieve the key. > Additionally, the users have a choice to use a 64-digit encryption key instead of a password, which would require them to remember the encryption key themselves or store it manually as in this case the key is not sent to the HSM Backup Key Vault So they do allow not storing the key on their servers, which is the only way I know to ensure encrypted backups can't be decrypted, but they make it inconvenient by forcing the key to be 64 digits, for a strength of 10^64. They could make "no store" keys much easier by allowing the key to be characters, so that people could use a sentence or other sequence of words as a key and not have to write down or remember 64 digits. Using just letters (ignoring case), you'd need at least 46 to get equivalent (12x actually) strength. With uppercase, lowercase, and digits, you'd only need 36 to get 3x the strength of 64 digits. If users already need to create a password to secure the random key stored on WhatsApp servers, it seems the strength of that password is really the strength of the whole system. In that case, they could just derive a key from the password and use that directly as the encryption key. Assuming they actually want to protect the backup that is. Disclaimer: I have never used WhatsApp, but am author of HashBackup which does not store your key on any servers.
- habibur 5y agoBest comment so far.
- kevincox 5y ago> it seems the strength of that password is really the strength of the whole system Not quite. If you trust the HSM that WhatsApp is using the HSMs provide a defense against brute-force attacks that is infeasible with a mathematical key derivation function. For example even with a weak password you could limit an attacker to 10 attempts after which the key is wiped. This isn't something that you can do if your key is only protected my math. With a random 4 digit pin and 10 attempts you can only guess it 1% of the time. With a password you can brute force it until you get it (of course a password with sufficient entropy is probably still out of reach). Of course trusting their HSMs is a huge if. There are also concerns about refreshing the attempt count (you don't want a brute force attack to wipe your key!) and synchronizing the attempt count across the distributed HSMs. (just enforcing the limit on each is likely to be sufficient though)
- AUSNA-ZI 5y agoEnd-to-end encryption should mean that the cloud provider doesn't have the key to decrypt the data
- whitetrump 5y agoEnd-to-end encryption should mean that the cloud provider doesn't have access to the key to decrypt the data.
- account-5 5y agoGenuine question, context first. I've never backed up any chat, I don't use WhatsApp anymore, I used to keep the photos I liked and deleted the rest. What's the point? I've never felt the need to go back and read any messages I've previously sent. I have no idea why you'd keep them. And also can you imagine if someone got hold of your life's worth of messages?
- Tenoke 5y agoI frequently search old chats to see when something happened or get some other information I know has been talked about.
- TedShiller 5y ago"encrypted"