WhatsApp Just Switched on Encryption for a Billion People
wired.com
wired.com
> There was a middle period where the government had a broad ability to surveil, but if you look at human history in total, people evolved and civilizations evolved with private conversations and private speech. If anything, we’re bringing that back to individuals.
I think on the contrary, the surveillance demon is out of the bottle. It's too hard to hide metadata such as ip addresses in communications; in many places Tor is blocked, browsers can be fingerprinted, typing style and writing style can be identified by statistical methods; we depend on auto-updated operating systems that might be backdoored in the future or are already backdoored and even if we have an "untraceable" system, we can't possibly use our old accounts were we logged in with our real name, or using our real IP address in the past. So, anonymous web use is not as social as plain web use. Besides, we already leak too much data through our GSM phones, at least to the carrier and the state agencies that log the user data.
I gave a talk about such conversational languages [1] at ClojureD last month if you're interested...
This is tragic, since the most interesting and private uses of the internet are in interacting with friends, family, and loved ones.
http://blog.cryptographyengineering.com/2015/09/lets-talk-ab...
At least with Signal you can compile your own client (though that doesn't help if the server is going to send you fake public keys!).
You do have to trust the client and opt in, but the feature exists.
Wow. I'm genuinely impressed. The Nokia app store closed over two years ago, and they still implemented this for those old, trusty devices. That's some dedication for serving the users!
Woo! Props to the WhatsApp team for supporting these features for dumbphone users like me.
Does anyone know if/how/where you can verify a users fingerprint?
Unless the NSA/FBI/CIA secretly orders WhatApp to release compromised app update with a backdoor.
But according to the diagram: http://www.wired.com/wp-content/uploads/2016/04/Whatsapp_Enc...
... A's message is encrypted with Whatsapp's public key, which means that Whatsapp's private key can (and has to) decrypt it on the server side to encrypt it in turn with B's public key.
If the diagram is truthful, the claims the article makes are incorrect.
With PKI the ability of the user to verify that they received and used the correct public key is critical and while I have to admit that I haven't read that much about WhatsApp's E2EE setup I haven't seen anything that shows how this issue can be mitigated in a way that would be useful for most users.
If WhatsApp decides to act malicious, yes, this method would make it very easy for them.
How foolproof is the verification system, how susceptible is it to downgrade attacks (while E2EE isn't not universally deployed) is there are 3d party verification of signatures, is there a community trust signing, can whats app disable E2EE in it's application without a noticeable UX change to either party, how does this work with multi user messages, how does this work with multiple devices, how does this work with historic messages that were encrypted using different keys etc.
I would say that there are sufficient "unknowns" at this point to take the security of this entire solution with some skepticism especially if you remotely planning to use this for anything that could put your life at any risk.
The whitepaper (https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...) goes into more detail.
That said, they could push out an update that changes the UI to disable E2EE without notifying the user, and that would be difficult to notice since the app is closed source. For this reason Signal is more secure, despite using the exact same protocol.
After reading the other sources of information, it's clear it is a secure protocol. More so when designed by the Snowden-approved Open Whisper Systems team.
1. http://www.wired.com/2014/11/whatsapp-encrypted-messaging/
[1] https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...
I think on the contrary, the surveillance demon is out of the bottle. It's impossible to hide metadata (ip addresses) in communications, we depend on auto-updated operating systems that might be backdoored in the future or are already backdoored and even if we have an "untraceable" system, we can't possibly use our old accounts were we logged in with our real name, or which can be traced to our IP address.
Side note, I noticed your account is still green and 13 days old. Are new accounts green only for two weeks?
This OTOH uses peer reviewed, strong, modern crypto that was designed by people who know how to do these things.