13 ms·
How WhatsApp enables multi-device capability
- senectus1 5y agoWhatsApp uses the Signal encryption subsystem and they only allow one other machine. What is FB doing that allows this on Whatsapp but not Signal. What a WhatsApp users opening themselves up for here?
- bool3max 5y agoMaybe read the article?
- blowski 5y agoHN Guidelines: > Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that."
- ikawe 5y agoThe Signal app never did the "primary device serves message contents to companion devices" like WhatsApp did. Ever since Signal introduced the desktop client, its multidevice functionality has involved fully fledged signal-protocol sessions between each device. It sounds like WhatsApp is now adding something like this to their client, though it sounds like some of the details of the scheme differ. In principal the signal protocol works fine for a multidevice scenario.
- david_arcos 5y ago> The WhatsApp server maintains a mapping between each person’s account and all their device identities. When someone wants to send a message, they get their device list keys from the server. Oh, no...
- alfongj 5y agoWhat's your concern?
- ev1 5y ago> they get their device list keys from the server Which means the server can just substitute keys in.
- alfongj 5y agoRight, but that doesn't compromise the security of the service necessarily. Users can catch a malicious server injecting incorrect keys by looking at security notifications and comparing security codes. This is part of the Signal protocol. This may be tedious but only needs to be done in the event of phone keys getting reset (a once in a year event?), as all companion device keys are automatically verified with signatures provided from an account owner's primary (phone) device Source: https://www.whatsapp.com/security/WhatsApp_Security_Whitepaper_v4_Preview.pdf https://www.whatsapp.com/security/WhatsApp_Security_Whitepap...
- Malakun 5y agoBut only one phone, yeah...
- p4bl0 5y agoCan anyone with good knowledge of the protocol explain the differences between what WhatsApp is rolling out now and what Signal has been doing for a long time now?
- fsflover 5y agoWhy does it matter if WhatsApp is closed and non-auditable? Upd. See also: WhatsApp whitepaper removed sentence about never having access to private keys (twitter.com/shiftreduce) 491 points by Aissen 8 months ago | 106 comments https://news.ycombinator.com/item?id=25685446 https://news.ycombinator.com/item?id=25685446
- nicce 5y agoIndeed. Signal client at least on Android uses reproducible builds.
- ChuckNorris89 5y agoThis feature (or lack thereof) is pretty much my biggest gripe against Signal. I still don't understand why they won't let you use the same account in paralel on an Android tablet. And the weird part is they provide no explanation for this limitation while this limitation does not exist for iPad users. If this new feature proves to work as advertised, I might as well sell my soul to the Facebook devil and go back to WhatsApp full time due to how frictionless the experience is (and everyone in the EU already being on it), and leave Signal only for private info sharing, as I grew tired of convincing people in my circles to move to Signal for privacy only to receive complaints that X,Y, Z features from WhatsApp are either missing, buggy or super frustrating to use on Signal. Oh, and receiving calls on Signal for Android is a mess (known bugs for years) where some calls just won't come through to my phone even if the desktop client is ringing, only to have it show up as a missed call notification on my phone a few minutes later. Unacceptable. I do support the Signal team for their work and what they stand for, but my patience (and that of those around me I convinced to switch from WhatsApp) is wearing thin.
- dannyw 5y agoSignal's refusal to allow me to export message backups is also unbelievably frustrating.
- NilsIRL 5y agoSignal does have this feature. It's just that their mobile clients do not support it (as a "slave" device), from what I understand this is no different than WhatsApp multi device feature
- ignoramous 5y agoWhitepaper: https://web.archive.org/web/20210922105222/https://www.whatsapp.com/security/WhatsApp_Security_Whitepaper_v4_Preview.pdf https://web.archive.org/web/20210922105222/https://www.whats...
- tasogare 5y agoCrazy that an application is proud, in 2021, to be usable on multiple devices.
- hnick 5y agoAll that and we still can't use it on 2 phones, or even migrate history between Android/iOS when you change phones.
- artiszt 5y agofor your security, ofc, only for the sake of your security [irony-off]
- phaer 5y agoA feature like that tends to become quite a bit more complicated with e2e encryption and and the kind of (potential) adversaries WhatsApp attracts due to its size. This would be much easier for an application where all state is stored in clear-text on servers. And even harder for services which are trying to avoid storing metadata on servers as much as possible, such as Signal.
- nicoburns 5y agoIf they're requiring a QR code scan to add new devices (reasonable IMO), couldn't they just use that to sync the encryption keys?
- ikawe 5y agoThere's so much more state than just the encryption keys - e.g. Without a central source of state, you need to sync mutations to the state - actions like sends and deletes need to be communicated across devices. Suddenly you're in the field of distributed systems, which is a complex field.
- einpoklum 5y agoLet's remind ourselves of a few facts: Facebook takes part in the US government's mass surveillance operations, granting wide, possibly complete, access to users' communications. This was revealed by whistle-blower Edward Snowden and the documents he had released. Facebook's interaction with the NSA or other government agencies is kept secret, and will not be admitted, so when Facebook tells you your communications via its applications and services are secure, that is certainly not wholly the case, and quite possibly not at all the case. Additionally, Facebook uses your communications for its own business interests, e.g. to manipulate you into paying for services or products whose providers pay Facebook, or for other kinds of social engineering. It stands to reason that this includes the information Facebook gathers about you from your WhatsApp conversations. There are other messaging applications with multi-device capabilities - better or worse - and we should strive to use those with open source code, well-established algorithms, and transparent, robust and trustworthy governance as projects. ---- So - please do not use WhatsApp and try to get your friends and family to switch to alternative applications. Signal and Telegram seem to be the popular alternatives, even if they each have their own shortcomings and flaws.
- artiszt 5y agoquite right and this is HN. and one may well wonder in how far FB does NOT seriously interfer with discussions here [and elsewhere, ofc too, for that matter]
- nindalf 5y agoAre you implying that Facebook moderates discussions here? I believe @dang is employed directly by YCombinator and is independent of any other tech company. As for commenting, I can’t speak for other Facebook employees but I made it a point to never comment on Facebook related discussions while I was still employed there. Frankly I didn’t see the point. Most threads would get so vitriolic and emotional that there wasn’t any space to have a discussion. There would be people spouting conspiracy theories like “Facebook controls discussions on HN”. No real point in engaging in such discussions, I figured.
- 5y ago
- nicoburns 5y agoMy phone having recently died, I've recently discovered a number of very annoying limitation to WhatsApp that are making me question my use of it: 1. It's impossible to export your chat history, except for one conversation at a time. The only exception to this is if you root an android phone which gives you access to the raw database. 2. It's impossible to move chat history from an android device to an iOS device. And moving from ios to android is only possible with certain samsung phones. 3. It's impossible to access WhatsApp from more than one phone at once. This is mostly still true with this update. You cannot use the mobile app as a "companion device". Do people not consider their chat histories valuable? I have my SMS history going back to 2011 (when I first got an android phone). Email can be archived. Facebook messenger keeps messages in perpetuity. WhatsApp is a frustrating outlier here.
- illyism 5y agoNo, I clear my history from time to time manually. It is very useful at times (to search through) but also not something I want to stick around.
- bennyp101 5y ago"Do people not consider their chat histories valuable?" Personally, no. I treat it like a real life conversation, if it's something I need to note later on, then I'll make a note of it outside of the chat app
- stavros 5y agoI go one step farther and have conversations auto-expire after a certain amount of time (e.g. a week) for both parties. Scripta volent.
- mikro2nd 5y ago"Do people not consider their chat histories valuable?" No, I consider them a positive liability and delete messages/conversations as soon as they're done/actioned. When the Brown Shirts come to get you, it'll be your own message history they hang you with. (Only slightly :)) Question: You have your SMS history going back a decade. How many times has that proven useful? I, too, used to keep messages & emails "forever" until I realised that it was doing nothing for me but becoming a maintenance burden. Now I have "max 24 months" retention policy and have never once needed to retrieve an email older than that.
- rd07 5y agoEnd-to-end encryption on multi-device? I think Matrix and Element solved this before.
- heeen2 5y agoverifying between all parties involved is incredibly clunky though
- vurpo 5y agoGetting the full benefits of E2EE (that is, protection against active attacks and not only passive eavesdropping) requires verification out-of-band in any case. Verifying is entirely optional on both Matrix and WhatsApp (not verifying doesn't affect the functionality of the chat), but gives you the same benefit on both platforms. But then again, WhatsApp actively hides the feature away behind menus and pretends it's not really a thing, while Element is a bit more pushy about telling you about it.
- bennyp101 5y agoHopefully this will make using the WhatsApp bridge on Matrix much easier - one of the reasons I haven't gone all in on Matrix. If I can have a device setup that is linked, then I don't have to run a VM or (hopefully) have it even installed on my phone.
- 2T1Qka0rEiPr 5y agoPerhaps this is an odd question - but can someone comment on why this was posted today? The blog post is from July, so I'm wondering whether it's past the initial experimentation phase or something?
- rPlayer6554 5y agoWhatsApp only just recently told me this was a feature. So yea I assume it was only fully rolled out around now.
- vdfs 5y agoStill in Beta, I've been using it for ~3 weeks
- londons_explore 5y agoWith more and more services going e2e encrypted, the application servers no longer have any special role or logic. All data they store is no longer privacy or security critical, and they no longer need ACL's. I'd therefore like to see future chat services like this to just have one big S3 backend (or similar).
- SMAAART 5y agoIt has been a while. Also now, when a conversation is archived it remains archived even if someone in that group posts something. Before when someone in an archived conversation posted something the conversation would be unarchived.
- gregoriol 5y agoDoes anyone with knowledge on the subject know how different it is from what Matrix/Element does? or any other implementation?
- nicoco 5y agoctrl+F "XMPP"… No? OKay, I'll be that guy. Multiple devices, multiple platforms, E2EE, gateways to other networks... my XMPP server handles all of that, and I convinced non-tech users to use it mainly because of the great Android client Conversations. Yes, there are some rough edges because there isn't a iOS client that matches Conversations in terms of user friendliness. But siskin-im in on its way there. I also have had complaints from friends but mainly because I am a shitty admin... Oh, and having your phone number as your username is something that really is important for you? Use Quicksy then.
- dmitriid 5y ago> and I convinced non-tech users to use it mainly because of the great Android client Conversations. And that's the only client in existence that supports the XEPs required for XMPP to be a viable alternative in the modern world. What about iOS? What about desktop? > I also have had complaints from friends but mainly because I am a shitty admin What if I don't want to run my own XMPP server? How do I find the one that supports message carbons, file uploads, encryption, push notification, client state indications...
- MattJ100 5y ago> And that's the only client in existence that supports the XEPs required for XMPP to be a viable alternative in the modern world. That's not true, but admittedly that information is not trivial to find right now for end users. It's a known problem, and people are working on a nice comparison of XMPP client capabilities so people can make a more informed choice. > What if I don't want to run my own XMPP server? How do I find the one that supports message carbons, file uploads, encryption, push notification, client state indications... https://compliance.conversations.im/ https://compliance.conversations.im/ or for something less overwhelming, https://joinjabber.org/ https://joinjabber.org/
- dmitriid 5y ago> That's not true, but admittedly that information is not trivial to find right now for end users. So, it's true for end users. > It's a known problem, and people are working on a nice comparison of XMPP client capabilities so people can make a more informed choice. There can't be more than a handful of usable XMPP clients in existence. The fact that "people are working" and "information is not trivial to find" speaks volumes about the state of XMPP clients. > or for something less overwhelming This is the reason XMPP is more-or-less dead for most users: "information is not trivial to find", "overwhelming" and so on. Meanwhile already in 2016 Daniel Gultsch wrote what's expected of a mobile client for XMPP, and this can be easily extended to all other clients. [1] Instead, 5 years later there's Conversations, "information is not trivial to find" and "check your server for compliance". [1] https://gultsch.de/xmpp_2016.html https://gultsch.de/xmpp_2016.html
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- saurik 5y ago> With this new capability, you can now use WhatsApp on your phone and up to four other nonphone devices simultaneously — even if your phone battery is dead. Does "non-phone" here at least include "iPad"? The use case of "if your phone battery is dead" is just such a non-issue for me, as I have a million other critical reasons to keep my phone charged and online... but having the WhatsApp external client--the one you install on laptops--available for iPads and even other phones would actually open up new use cases for me.
- RMPR 5y agoThat's an interesting and long awaited update. But there's no mention of a new desktop app, or new web app. I wonder how users in the beta will be able to test this.
- Aardwolf 5y agoI could run chat programs on multiple computers in the 90s, so today we're in a worse state than then. What gives?
- skymt 5y agoDid those chat programs encrypt messages end-to-end while syncing message history across devices?
- deleted 5y ago[deleted]
- tinus_hn 5y agoWith no encryption so the network, the servers and basically anyone who cares to look can see your private messages. If you don’t care about that, indeed it’s easy to implement things.
- er4hn 5y agoSomething that is interesting here is on-boarding new devices. Since all the encryption is done by each message being sent to the {all sender devices (M), all receiver devices (N)} you end up with M+N encryptions. When onboarding a new device, it needs some amount of state in order for conversations to have a useful context. So the new sender device gets a bundle of recent conversations from who-ever onboarding it. I'm not clear on how you could control the amount of context or add more state, but that is off-topic. What I'm wondering is: Does this have a race condition? Say that you have: Sender A knows about receivers {B,C,D} Sender A sends message Foo to {B,C,D} Receiver E is onboarded at the same time Foo is sent. Is there no state where E does not receive the message? I'm sure that this is accounted for and out of scope in a high level blog post, but I am curious how that part works.
- greggman3 5y agoNow if they'd just stop the spam and get rid of the phone numbers! There is ZERO good reason to require a phone number in 2021 nor to access my contact list of which the majority fo the people I talk do I don't have their number.
- throwawaybutwhy 5y agoThe ship has sailed. While we endure incessant 'we want you to bend backwards and agree to our new TOS' in WhatsApp, Telegram keeps being friggin' awesome and getting better every fortnight or so.
- baby 5y agoisn't Telegram unencrypted?
- AlexanderTheGr8 5y agoby default. But you can change it to encrypted in settings. It would be nice if it was the other way around - encrypted by default and unencrypted using settings
- baby 5y agoMy top 4 messaging apps are encrypted by default (whatsapp, signal, wire, matrix). Why would I use telegram?
- f1refly 5y agoGroup messages cannot be encrypted though which males the whole thing much less exciting
- gaius_baltar 5y agoAlso, encrypted chats don't synchronize among devices. Also, they can't be backup-up or exported for a manual migration.
- Apofis 5y agoSmells of NSA.
- jwogrady 5y agoDon't worry, we will store those keys nice and safe.... In case we get subpoenaed. Just scan you retina.