5 ms·
> WhatsApp more secure than Telegram Why is that? With WhatsApp client being closed source, we simply don't know if it really is doing E2EE at all.
by alaricus 4y ago
> WhatsApp more secure than Telegram
Why is that? With WhatsApp client being closed source, we simply don't know if it really is doing E2EE at all.
- ChuckNorris89 4y ago>we simply don't know if it really is doing E2EE at all Why don't we know? Isn't it trivial to set up a MITM test setup and snuff the traffic and analize it?
- alaricus 4y agoIt's trivially easy to encrypt the traffic and then send a copy of the private key to Facebook's servers. You would not be able to decrypt it, but they would.
- hiq 4y agoThat's not how it works: https://news.ycombinator.com/item?id=11432661 https://news.ycombinator.com/item?id=11432661
- alaricus 4y agoThis makes no sense. There is nothing to prove that that WhatsApp is really using the aformentioned Signal code. It's closed source, so it could be anything inside.
- hiq 4y agoThe answer to your objections is literally in the comment I linked, did you read it? One keyword is RE.
- alaricus 4y ago
- pvg 4y agoYour objection to a perfectly cromulent answer is just namecalling. People take apart and find vulnerabilities, including cryptographic ones in closed source software all the time.
- alaricus 4y agoIt's a closed source app. Translation: you and I don't know what it does. Take it apart all you want, but you're not going to find any backdoors or learn about how good the E2EE implementation is. Claiming otherwise is ridiculous.
- pvg 4y agoIt's a closed source app. Translation: you and I don't know what it does. This just isn't true. It's a claim trivially disproved in public by, say, gazillions of detailed P0 posts. Again, all you have is namecalling and confidently stated things with obvious counter-examples. Claiming otherwise is ridiculous. Yours is an extraordinary claim that requires, never mind extraordinary, any evidence.
- gsich 4y agoYes we do as there are 3rd party clients (eg yowsup) that also need to implement it. Problem is that you don't know of the app is leaking your keys somewhere else.
- alaricus 4y agoThis is my point exactly. It doesn't matter as long as the app is closed source. You could do the worlds most secure E2EE implementation, but then send a copy of all keys to Facebook servers.