Jan Koum: “I couldn't agree more with everything [Apple] said”
facebook.com
facebook.com
https://www.youtube.com/watch?v=SjVxqlncS2I&t=46m15s (also see 49:00+)
[1] http://www2.camara.leg.br/atividade-legislativa/comissoes/co...
However I've seen leaked screenshots that suggest at least the Android client is getting the ability to see what the keys are and pin them. Hence, TOFU encryption. It's about the best you can do in a consumer product.
Neither does Signal/TextSecure. Signal most definitely has E2E encryption.
However, when your primary device is wiped (or changed)[0] your Signal crypto keys are changed and your conversation partners are alerted to this fact.
Do you know what happens when the same thing happens to a WhatsApp user? (I don't. :( )
[0] Or -yanno- one just clears all Signal app data
Every word in your first and third sentences are true. As written, your second sentence is iffy at best. [0][1]
However, the situation that those sentences describes does not apply to end-to-end encryption in Signal. Signal's crypto keys are generated on the end-user's device and never leave that device.
Signal neither requires OOB key exchange, nor does it require that you set a password to encrypt Signal data while on disk.
Because Signal has the same properties that you claim are indicators of a lack of E2E encryption, but actually is E2E encrypted, it's clear that these properties are not proof positive of a lack of E2E encryption.
So, I reword my previous question, which you failed to address:
What happens when a WhatsApp user gets a new phone, wipes his existing phone, or simply clears all locally stored WhatsApp app data? Does he get a new set of crypto keys, and are his conversation partners alerted of this fact as happens in Signal?
I ask because I don't use WhatsApp and don't know the answer to the question.
[0] Consider Diffie-Hellman key exchange. This is a method whereby two parties who wish to communicate securely over a hostile channel can do so without divulging any key material to eavesdroppers listening in on the exchange.
[1] To address the possibility that you're talking about key verification, rather than secure peer-to-peer session creation: if you like, Signal will show you the fingerprint of your encryption key. You can use that fingerprint to perform any OOB key verification that you want.
I do no such thing because I never made such a statement. I addressed your claim about mandatory OOB key exchange, not optional verification. To jog your memory, the two times I brought up OOB exchange were as follows:
>> Last time I checked whats app didn't require any kind of OOB key exchange, or ability to set your own password.
> Neither does Signal/TextSecure. Signal most definitely has E2E encryption. [0]
and
> Signal neither requires OOB key exchange, nor does it require that you set a password to encrypt Signal data while on disk. [1]
Notice that I talk about how Signal doesn't require OOB key exchange, not that Signal doesn't provide OOB key verification.
I don't envy the job of law enforcement. It must feel like at times that everyone is standing in your way. But where does it stop?
If only we could track everyone all the time...
If only we could watch everyone in their homes all the time...
If only we could open everyone's safes whenever we needed to...
Yes, you could solve many mysteries with all of the keys. But it's not your information. You're not owed it. No one is owed the answer to any question.
I hope law enforcement understands someday what a destructive request they've made, but I'm guessing like anything else addictive, that one taste will just lead to more.
It totally disagree but thats how many people see it (I would guess).
It's also important that he's speaking out in opposition to these government tactics. Hopefully Zuckerberg will follow suit but if history tells us anything it's that Facebook is rather compliant and doesn't take security seriously.
Citation needed...
http://m.huffpost.com/us/entry/facebook-security-wall-mark-z...
http://www.forbes.com/sites/thomasbrewster/2015/12/17/facebo...
http://www.businessinsider.com/facebook-security-flaw-leaks-...
http://www.businessinsider.com/well-these-new-zuckerberg-ims...
I'm not aware of that actually existing outside of an extraordinarily tiny enclave. The rest of America does not make such vaporware failures into any kind of role models.
Quite the opposite probably, I see far more mockery than anything. Such failed start-ups are constantly made fun of in the business press. For years now, essentially every major business publication has been waiting with bated breath for the latest bubble crash so they could mock what ultimately became the unicorn bubble.
Zenefits for example has been getting lambasted, and they're not even vaporware, they actually have a real business of some caliber in a serious business category. Color was vaporware, and it was endlessly, and universally mocked. I can't think of good examples of college kids becoming role models for pushing vaporware.
OK, that's mean. WhatsApp and its success is not vaporware. And they DID charge money at the time they were sold to FB, albeit pitiful amounts from virtually nobody. But the asking price was so high and so out of whack with the financial potential of the app, that I hesitate to describe Koum as a traditional businessman. "Sell my app to a company that's terrified of anything that smells social being successful without them" is still not a business model, not even now.
Your comment made me curious about what their actual revenues and costs were leading up to the sale. Putting (massive) stock-based compensation expenses aside it looks like their revenues and operating costs were actually pretty close[1]. That's not delving into potential revenue growth connected to payments and B2C interaction following the path which was already being laid out by wechat[2]-Facebook has decided to attempt this with messenger instead of whatsapp. I'm not saying that they would have quickly found enough revenue to justify a $20B valuation, but that it resembled a traditional business a lot more than many other social startups, and they were kept lean and probably better positioned to capitalize on growth than others.
[1] http://techcrunch.com/2014/10/28/whatsapp-revenue/ "For the year ending December 31, 2013, WhatsApp had $10.2 million in revenue … net cash used in operating during this period was only $9.9 million"
[2] http://dangrover.com/blog/2014/12/01/chinese-mobile-app-ui-t...
As of December 1, 2015, WhatsApp has a score of 2 out of 7 points on the Electronic Frontier Foundation's secure messaging scorecard. It has received points for having communications encrypted in transit and having completed an independent security audit. It is missing points because communications are not encrypted with a key the provider doesn't have access to, users can't verify contacts' identities, past messages are not secure if the encryption keys are stolen, the code is not open to independent review, and the security design is not properly documented
You are probably right that getting a high score on the scorecard doesn't guarantee a secure program. (The standard of the socrecard is not high.)
But can't you still argue that getting a low score on the scorecard would probably mean it's not a secure app?
Having key's held by the creator is a sure way to undermine any security model, having externally auditable code is a measure to ensure people can independently verify if code is secure or not (or if it's taking a carbon copy for it's creators) etc;
Standing with Cook would be a good step for them but I'm not optimistic.
Google 'appeared' to have a negative reaction to the NSA jacking their inter DC lines which at the time were not encryoted.
Google will not make public claims on their infra regardless
Google may stand up to the .gov but it may choose to be more quiet.
Anyone that stands up to the police-state-mentality is honorable. The situation we have now is fucked.
Its not "Armageddon" or anything - but the situation is fucked.
Do you have any idea how many people at places like goog and fb and appl are very progressive - dont give a shit about pot, molly, lsd etc as they have all been partying and have had growth experiences due to this? a fucking ton.
It is disingenuous for these companies and their employees to not have the balls to stand up to the government's over reaching BS. EXCEPT that they all share a tenuous thread of "employment status" with a corporation... thus they dont speak up.
Hey Obama, you smoked pot, (That was the point), so release anyone who has ever gone to jail for pot -- or go to jail yourself?
so tired of this hypocrisy
This situation should have ended 20 years ago with the first round of the crypto wars. /sigh/
> Anyone that stands up to the police-state-mentality is honorable.
Exactly. They aren't alone, either - with Apple taking first-mover risk, it should be easier for others to stand up together.
It's important to realize that there isn't much neutral ground here. Now that the line has been drawn, you're either helping implement backdoors or you are making a stand, potentially at personal risk. Collaborators will not find much cover if they attempt to hide behind a Nuremberg Defense.
I strongly recommend that everybody watch Quinn Norton and Elanor Saitta's amazing talk from 30c3, "No Neutral Ground in a Burning World"[1]. Most people didn't ask for the responsibility, but it's irresponsible to avoid it by pretending that technology is somehow external to politics. Everything we implement has political consequences, and we (the people implementing all of modern technology) need to start thinking about those consequences.
[1] https://media.ccc.de/v/30C3_-_5491_-_en_-_saal_1_-_201312272...
> Anyone that stands up to the police-state-mentality is honorable.
Theres a difference between a police state and a police state mentality. The latter is a subjective and abstract point of view, not so easy to stand up against.
Weak sauce.
https://medium.com/insurge-intelligence/how-the-cia-made-goo...
Also, more surveillance means also more noise
Or ... something "fishy" is going on and this article is just a bait by Apple to let its customers believe they do care about privacy ... while in reality the situation might be entirely different. And the "best" thing is that ordinary people will never know for sure, because with Apple's proprietary software philosophy, there is no way to tell.
[1] https://www.documentcloud.org/documents/2714001-SB-Shooter-O...
Yes, there's a publicly available court order. How would you know there isn't also an NSL?
No, its not.
> I believe this kind of government requests
Its not a request.
> is usually made with a strong non-disclosure agreement
An agreement requires someone to agree. You probably mean a gag order, not a non-disclosure agreement. In any case, whatever you believe is normal is irrelevant: this is a public order, which was widely reported on before Cook's statement.
> So, either the consequences were not that bad or Apple has chosen to ignore them for the good cause.
Its clearly the first: there were no consequences for disclosing the order, since there was no secrecy provision attached to it and, in fact, it had been published and widely reported prior to Cook's response.
The NSA has [most likely] found a way to penetrate Apple/Google/MS/FB for specific targets i.e. they can get the info on any specific person/group covertly. The attack surface is just too large - TAO, Zero-Days, Insider threats, Financial threats, etc. The problem with that is things like needing "Parallel Construction [1]" to legally prosecute.
What the FBI is now doing is using a recent horrible tragedy to force SV companies to establish a precedent. Make no mistake, this has been long time coming. The Feds want to set a precedent both legal and 'cultural'. Ultimately Apple might cave, but the fact that they are raising a stink is very good news. Time for other heavyweights to join the chorus.
[1] http://thefreethoughtproject.com/parallel-construction-law-e...