Making Signal show white-on-white text would make it more secure against attackers reading over your shoulder. So why doesn't Signal do that?
These are legitimate trade-offs that the Guardian is portraying as vulnerabilities.
Making Signal show white-on-white text would make it more secure against attackers reading over your shoulder. So why doesn't Signal do that?
These are legitimate trade-offs that the Guardian is portraying as vulnerabilities.
Anyway, I don't think it's a reasonable choice. How any times do people change phones?!? Even if you're rich you don't do that more than once a year. It doesn't happen often enough for the user to become "accustomed" to warnings and simply click through them.
But you don't, because shoulder surfing is not the threat model for Signal. And individually targeted MITM attacks by governments that can take over a server are not the threat model for WhatsApp.
If it even works to enhance the privacy of 0.1% of users, it's helped a million people in ways that SMS has not.
I see all these people come in defense of WhatsApp using bizarre statistics about domestic violence (big correlation with hacking?). Then someone (tptacek?) was going around saying not a single crypto expert disagrees with their consensus (trucking all over the original source, Tobias Boelter). Then there are all these jokey "Is WhatsApp Backdoored Yet?" expressions. It's a frenzy.
There seem to be a whole bunch of people who take The Guardian article as "omg, after this article, people will drop WhatsApp and use something like Messenger instead!". Which, sure enough, maybe a common scenario, and worse. However, the article was obviously meant to push people outside of Facebook gardens, and into a more secure alternative. It's supposed to make you go "WhatsApp is unsafe, I will use Signal instead". One of those "trade-offs" you're talking about in the first place, just like the security vs. purity one. In this case, erring on the side of activism.
As a sideline observer with very little crypto knowledge, I think Boelter presented an interesting case, while the anti-Guardian crowd reacted like crazy people, pulling fire alarms, hurling insults, and Streisand-effect-ing the story into a huge controversy.
I mean, the EFF article itself, in defense of WhatsApp and against The Guardian, says:
https://www.eff.org/deeplinks/2017/01/google-launches-key-tr...
> If you are a high-risk user whose safety might be compromised by a single revealed message, you may want to consider alternative applications. As we mention in our Surveillance Self-Defense guides for Android and iOS, we don't currently recommend WhatsApp for secure communications.
It goes on to qualify this statement by saying that's a rare threat model. However, that right there, is enough to justify the original piece. The idea, I think, is that everyone should be on something like Signal, so that merely using Signal wouldn't be taken as a reason for suspicion. If you disagree, your argument could surely be better than jokes about white text.
Just my two cents as a nobody.
Honestly, would a 'recipient key changed; resend message?' be the worst prompt in the world?