7 ms·
Should We Chat, Too? Security Analysis of WeChat's Mmtls Encryption Protocol
- kccqzy 2y agoI personally am not very interested in this research. WeChat is well known not to use end-to-end encryption. Considering that the app is unlikely to adopt end-to-end encryption (likely due to censorship being a business requirement, which was mentioned in the article and previously uncovered by this lab), I don't really feel like I care a whole lot between good non-end-to-end encryption and bad non-end-to-end encryption. Parties that are interested in subverting this kind of encryption, such as governments, likely already collaborate Tencent to get decrypted messages from the source.
- deleted 2y ago[deleted]
- palata 2y ago> I don't really feel like I care a whole lot between good non-end-to-end encryption and bad non-end-to-end encryption. That's the difference between "you have to trust WeChat" and "anyone can read your chats". Of course you may not personally be interested because you don't personally use WeChat, but for the billion active users who do, I think it should matter.
- kccqzy 2y agoWhere did you see that "anyone can read your chats" in this article? Indeed near the beginning of the article in the fourth bullet point the author states "we were unable to develop an attack to completely defeat WeChat’s encryption" right there. The only parties who are interested in expending more effort to break this kind of encryption are just governments, who can simply force Tencent to give up plaintext records.
- kadoban 2y ago> I don't really feel like I care a whole lot between good non-end-to-end encryption and bad non-end-to-end encryption Bad non-end-to-end encryption is exactly that: "anyone can read your chats". That's not what the research found, it's just the implication of your original statement.
- est 2y agoPlease realize, in China, you can't trust your "end" either. It's always infested with spyware with local root access.
- deleted 2y ago[deleted]
- kccqzy 2y agoOkay I shouldn't have used the word "bad" here. I should have used "flawed but not detrimental" just like what's described in the article.
- datadeft 2y agoYep. Btw the threat model for me is this: - against random 3rd party, even WeChat is ok - against random black hats, most of chat software is ok, maybe even WeChat - against gov agencies, nothing is going to protect you When I am in China, i happily use WeChat including the gazillion of services available through it. Buying metro pass, ordering food, getting a battery pack and so on. Btw no country could replicate this outside of China, which is an interesting phenomenon. We have endless ads including actual scams and malware distributed by Google Ads yet I cannot buy train tickets in the EU through a single app and order food as well, let alone getting a cab. It would be great though.
- xvilka 2y agoGrab in SEA region could be said as one more example of such a "super app" too.
- palata 2y ago
- mouse_ 2y agoShow me the outcome and I'll show you the incentive. Hint: backdoors I wouldn't trust any federally approved encryption. From any country. I wouldn't trust them, but I WOULD use them, given no other choice to reach the users I'm after. But always assume zero trust. With any computer thing, zero trust. Computer systems and those who orchestrate them are sneaky little devils.
- deleted 2y ago[deleted]
- creatonez 2y agoAnd even if it isn't screwed up by active malice... don't be surprised if it's screwed up by pure incompetence. South Korea's internet is still plagued by government-approved encryption standards, which, due to the deprecation of ActiveX, sometimes require installing institution-specific cryptography software to tunnel connections through a local HTTP server so it can be encrypted outside of the web browser - https://palant.info/2023/01/02/south-koreas-online-security-dead-end/ https://palant.info/2023/01/02/south-koreas-online-security-...
- palata 2y ago> I wouldn't trust them, but I WOULD use them, given no other choice to reach the users I'm after. Which is no different from trusting them. The reality is that you have to trust something at some point.
- sodality2 2y agoNot true, you can use something in an untrusting manner. Like assuming everything you send on the platform to be known to the government. Anyone in the USA who uses SMS should be operating like that, for example.
- palata 2y agoHmm... if you assume that your government can read your messages but still use the service, then you trust your government to not hurt you based on that. So there is trust. If, however, you don't send messages you would like to send because you don't trust the service, then it is true that you are not trusting the service, but you are not using it (for those sensitive messages) either. As soon as you actually use something that matters, you have to trust it. Sending sensitive messages over a system that you don't trust while admitting you don't trust it is... weird.
- dtquad 2y agoThe Chinese government has direct access to the WeChat backend so it's unlikely that these weaknesses were government mandated. Probably just the result of overworked 996 developers: >The name 996.ICU refers to "Work by '996', sick in ICU", an ironic saying among Chinese developers, which means that by following the "996" work schedule, you are risking yourself getting into the ICU (Intensive Care Unit) https://github.com/996icu/996.ICU https://github.com/996icu/996.ICU
- deleted 2y ago[deleted]
- daghamm 2y agoWeChat is basically one of the tools the communist party uses to control the population. If something is on there it is most likely by design. Off topic (or is it?): While back a western journalist in China reported that her wechat account was banned 10 minutes after changing her password to "fuckCCP"...
- tptacek 2y agoThe point being made in the preceding comment is that the threat model for WeChat already overtly includes its operators being able to puncture its confidentiality. It doesn't make a lot of operational sense to introduce complicated cryptographic backdoors (such as the IV construction, which the authors say could potentially introduce an AES-GCM key/IV brute forcing attack) when you control the keys for all the connections in the first place.
- throwaway48476 2y agoNot only control keys, but control the software update mechanism (backdoor a la xz).
- randomNumber7 2y agoAnd the argument is pretty weak. It doesnt cost them much to introduce cryptographic backdoors. Once they have done this they have even more control. It is then also less effort, because you don't have to deal with a company (like WeChat) directly to spy on their customers.
- bzmrgonz 2y agoWhat do you say to observers who would see this analysis as a parallel to the huawei or Tiktok western argument, meaning, "don't let them spy on you, let us spy on you instead!!!"
- two-sandwich 2y agoIs there something you'd like those observers to hear?
- jeltz 2y agoIsn't this the opposite? It is warning that WeChat's security might be weak since it is using weird non-standard stuff which means everyone might be able to spy on WeChat users, not just China. If WeChat fixed this then only China would be able to spy on the users.
- thimabi 2y agoWeChat using a custom protocol like MMTLS instead of sticking with something solid like TLS 1.3 is a risky move. Rolling your own crypto almost always leads to trouble. Of course, there may be ulterior motives behind Tencent’s decision, and users have little power to change it. For an app with over a billion users, that’s pretty concerning.
- tptacek 2y agoIs it concerning? It's not end-to-end secure to begin with.
- thimabi 2y agoIt is insecure depending on one’s threat model. Though I agree end-to-end encryption would be the best practice.
- tptacek 2y agoCan you articulate what that threat model would be?
- xvector 2y agoYou are only okay with the CCP and your recipient knowing your conversation.
- tptacek 2y agoThat's kind of how I read it too, which makes some of the suppositions here (about the CCP inducing bad protocol design) odd.
- im3w1l 2y agoI agree it's probably a mistake but I can also see another possibility: But first, consider the CCP. The CCP has nearly 100 million members. That's a lot of people. More than many countries. It's not a very exclusive club. Clearly such a large organization cannot be considered as a united whole. It's not just whether "the CCP can read it" it's about which part of the CCP can read it. Can the low ranking CCP member read the wechat message of the high ranking member fucking his wife? Maybe not? But maybe he would like to? Maybe he knows a mathematician that can help him for a reasonable sum of money? Or maybe someone wants to do a bit of corporate espionage? In other words the inner core of the party wants nobus, whereas the periphery has incentives to undermine it.
- spacebanana7 2y agoI wonder whether WeChat is one of the safest messaging apps because it has the strength to say no to western agencies. Signal and Matrix can be pressured with a rubber hose if there’s enough desire. And I imagine bureaucratic equivalents exits for iMessage and WhatsApp. But the CCP can offer genuine protection to WeChat executives.
- osamagirl69 2y agoI have not been following the end-to-end encryption discussion in a while so please excuse my ignorance in asking... How does the 'rubber hose' threat apply to Matrix? So long as you are in control of your home server (or at least use a home server you trust) I am not sure who your advisary would pressure.
- jeltz 2y agoThey could force them to add a backdoor in the Element build uploaded to the app store so they can use that backdoor to attack specific users. This is why we need reproducible builds and code which automatically check for discrepancies.
- osamagirl69 2y agoFWIW, the current version of element (X) is published as a reproducible build on f-droid. https://f-droid.org/en/packages/io.element.android.x/ https://f-droid.org/en/packages/io.element.android.x/
- zxilly 2y agoThe attack on xz illustrates that even if the code is open source and the build is reproducible, well-designed attacks can still be executed.
- palata 2y ago> I wonder whether WeChat is one of the safest messaging apps because it has the strength to say no to western agencies. That is not how cryptography works. If you use proper end-to-end encryption (e.g. the Signal protocol), and assuming that you use it properly, then the server does not have access to the content of the encrypted messages. So the server cannot be pressured, period. So the Signal protocol is strictly better than a protocol that is audited and found wanting (TFA talking about the WeChat protocol here).
- upofadown 2y ago>Generally, NIST recommends[1] not using a wholly deterministic derivation for IVs in AES-GCM since it is easy to accidentally re-use IVs. A quick skim of the referenced document did not show where NIST recommended against the use of deterministic IVs. The document actually spends a significant amount of text in discussing how one would do such a thing. Did I miss something? >Lack of forward secrecy The article mentions that the key is forgotten when you close the app. Probably enough forward secrecy for most people. >Since AES-CBC is used alongside PKCS7 padding, it is possible that the use of this encryption on its own would be susceptible to an AES-CBC padding oracle, which can lead to recovery of the encrypted plaintext. This is a messaging app. Is there actually an available oracle? Does the implementation even generate a padding error? [1] https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpubli...
- tptacek 2y agoThe GCM IV thing didn't ring true to me either; in fact, the whole reason we have XAES-type constructions is to enable fully nondeterministic IVs, which don't fit comfortably in the GCM IV space. Regarding padding oracles: it is most definitely not necessary for a target to generate a "padding error", or even an explicit error of any sort, to enable the attack.
- upofadown 2y agoThere has to be some reverse channel to do an oracle. Timing? That might not be a thing for messaging. Signal apparently also uses CBC with the same type of padding. So the same shade could be thrown in that direction if someone really wanted to do so. I would be happier if there were fewer vague assertions in these sorts of writeups...
- tptacek 2y agoI'm not sure what part of Signal you're referring to, but the Signal Protocol generally uses AEAD constructions. That aside: the kind of padding is not the issue; every serious system that uses CBC uses PKCS7 padding. The issue is the lack of authenticated ciphertext, which is what enables the attack. The authenticated scheme composing CBC and HMAC in an EtM arrangement is not susceptible to padding oracle attacks. There are other error and behavior oracles for other padding schemes, and for different block cipher modes.
- maxglute 2y ago[flagged]
- throwaway48476 2y agoBy "western encryption" do you mean crypto systems that have been subjected to public scrutiny?
- maxglute 2y agoSystems whose scrutiny/reputation is more subject to western "trust me bro". Authors had courtesy to recognize TLS drama in 2010s, and assumes it's... better/sufficient now because why, a bunch of US companies, many with teams of ex US intelligence on internal security teams is doing bulk of the scrutinizing. PRC seems to like their home-grown cryptography gated behind language barrier. Maybe they're hedging on bet that enough diverse implementations better than eggs in single basket. Or the amount of Chinese fluency decreasing in west going to add another layer of security/obscurity. Ultimately who knows, other than PRC would be idiotic to listen to OTF-ICFP funded recommendations, a program that avoids "focus" on countries with minimal information controls, i.e. if there's a reason not to trust western scrutinized crypto systems, you likely won't find it from OTF and citizenlab.
- throwaway48476 2y agoI don't see how the language barrier provides any security. If your threat model is foreign governments and you're rolling your own crypto you have to assume they have plenty of budget for translation. Technology is one of the main collection activities of any spy agency. Trust in a crypto system is established by having multiple adversarial parties use it and the system being open to attack for many years without success.
- maxglute 2y agoWestern spy agencies already overwhelmed by volume of PRC cyber activity per recent headlines, meanwhile FVEY also short of Chinese specialists, and institutions not generating enough language talent. It's less budget issue as bodies issue. Multiple adversarial parties who are still likely cooperating with intelligence - MSS isn't going to get a seat at the table/behind the scenes for western crypto standards. Do we really know system hasn't been attacked without success when there's frequent PRC penetration in the news. What we do know is west/US has advtanges along the hardware/software stack, so smart for PRC to obfusgate and add complexity at points they can control. And that one of OTF's explicit mission, especially ICFP funded fellows is to undermine PRC controlled web - it would be incredibly dumb for PRC to take their advice seriously.
- imiric 2y agoThese findings are so unsurprising that the research is borderline boring. What I would like to see are similar efforts directed at the tower of complexity that is the modern TLS stack. From the Snowden leaks we know that the NSA has tried to break cryptographic algorithms for decades via their project Bullrun, and that they bribed the RSA to default to their compromised algorithm. From the recent XZ incident we also know that supply chain attacks can be very sophisticated and difficult to detect. How likely is it that the protocols we consider secure today are silently compromised by an undetected agent? Should we just assume that they are, like a sibling comment suggested? I'm frankly more interested in knowing if there is oversight of these complex technologies that could possibly alert us of any anomalies of this type, so that we don't have to rely on whistleblowers or people who happen to notice strange behavior and decide to look into it out of curiosity. Too much is at stake for this to be left up to chance.
- lazide 2y agoOversight, yes mostly. The issue is that the stack is very complex, and who watches/pays the watchers?
- toast0 2y agoMost of the things people get dinged for in this kind of report are things that were already fixed in modern TLS. If you set your clients and servers to TLS 1.3 only (which I consider the modern TLS stack), you only have a handful of ciphers to choose from (AES128-GCM, AES256-GCM, and ChaCha20-Poly1305), which avoids any issues with CBC constructions. Most of your issues are going to be around x.509 certificate processing, because TLS protocol and ciphers are easier to use correctly than in the past, but x.509 hasn't changed significantly.
- est 2y agoChinese apps don't need encryption but pretends to, the government had direct access to all clear-text data. If you can't comply your business would be fucked one way or another. Security researchers need to stop beating the dead horse. The encryption mechanism is mostly used for compliance or certification. In fact many corp-intranet middleboxes can decrypt wechat communications, it's not a bug, it's a feature. IRL people just treat wechat as somekind of Discord with payment options. If you say something slightly wrong your account would instantly get into trouble. Just assume your wechat chat records are public one way or another.
- CGamesPlay 2y agoJust to be clear, encryption to hide from broad government surveillance is one valid use for encryption (which WeChat doesn't have), but it is far from the only reason for encrypted communications. Common theives, abusive exes, or overbearing employers are a few others that immediately come to mind.
- est 2y ago> Common theives, abusive exes, or overbearing employers as I commented on other thread, they don't even bother with network protocols. They just mandate install spyware on your end devices. So E2EE won't help here. Chinese Android ROMs are notorious for this. Even the phone manufacturers are collecting data
- novolunt 2y ago[dead]
- crazylogger 2y agoFor one thing, Chinese government does have an incentive to enforce good encryption so that foreign adversaries cannot snoop in on important Chinese communications. Only the Chinese government has access via Tencent’s backend.
- 2y ago
- ELPROFESOR 2y agoHello
- fdb345 2y agoThese papers really make me laugh. Similar to all the Telegram ones. They can't break shit. Noone has 'cracked' anything. They 'theorise' that they maybe can 'crack something' if they had 10,000 computers daisy chained together and a million dollars.