Flawed reporting about WhatsApp
theguardian.com
theguardian.com
There's a lot of people here saying this should have happened faster, they're likely right, but also, given how extensive and thorough this is, it is more likely an example of how old-school editorial rigour just takes a lot of time.
The technical side of the study is very well understood by practically anyone. People have different type of opinions on the matter not because they misinterpret the technical details but because they have different expectations on how the privacy situation will end up being for different groups in the light of this knowledge.
So all of this makes it way harder to define if the story was overblown or not. Apparently Guardian editors ended up thinking that it was indeed, after giving it a long consideration. This is not a technical fact (and it cannot be), it is just their interpretation of it (and also the interpretation of many security experts but that's not the point).
It could be that I am the one who is missing something. That's why we are discussing here, right? :)
You are correct that it is impractical to "exploit" the chosen design, I think the bigger issue their portrayal of this as a vulnerability rather than a security suggestion.
My general point is, even if they made some technical errors as well, their consideration, I believe, was more about the consequences of their interpretation.
I didn't remember that and it seems to have been removed from the article (with a note on the end which I have missed). Well, that's just sensationalism and must have been picked up way earlier in a sane review process. I stand corrected.
From this linked article.
Those who value maximizing security at all costs, even to UX, disliked this default.
WhatsApp was trying to switch end-to-end encryption to on-by-default for its over a billion users. An understandable requirement of doing so was to ship E2E encryption in such a way that did not involve changes to the UX.
Whether or not this tradeoff is the best compromise is certainly debatable, but it is just that: a tradeoff, not a "backdoor", not a "vulnerability", and not a "flaw". It's a deliberate design decision.
Why is it not a "backdoor", not a "vulnerability", or "flaw"? Well, let's examine what would happen if the default were reversed: let's say users were notified by default. Would this keep them more secure?
I have doubts. These notifications are not high signal or immediately actionable. They do not indicate an attack. They indicate "a key changed" and whether or not that's abnormal is up to users to determine. The overwhelming majority of these events will be innocuous, leading to alert fatigue. It's also unclear how well an average end user would even understand or be able to react to these alerts.
I am certainly willing to give WhatsApp's UX designers the benefit of the doubt here. UX design is hard and the tinfoil hat crowd saying things to the contrary have a history of producing unusable software by demanding security misfeatures which tick off a box on a threat model without actually improving user outcomes.
While some people in the tinfoil hat crowd seem to think bombarding users with a bunch of low-signal security alerts is a good idea, practitioners working with IDS/SIEM systems probably have a different opinion: that low quality / low signal alerts are worthless.
There are solutions to providing high-quality signals about key change events to users without asking them to manually confirm key fingerprints in person, but they are complicated, haven't been largely deployed, and it's still unclear how they'll work...
I'm talking about CONIKS and Google Key Transparency, which implement logs which users' own devices can monitor to discover changes to their keys as advertised through a key server. These systems can ask a very simple question to users when this happened: "Did you just log in on another device?" If they didn't, the user can select no and publish an alert indicating they were compromised.
Apparently if you're so wrong that an entire field disagrees with you, you can get anything printed in the Guardian.
They emailed me asking why I hadn't signed and if it meant that I didn't agree with the petition.
Funny thing, two reasons why I hadn't signed. First, it was because I only caught the petition when it was already deep with many people I respect a lot and I felt I added nothing
And second, I was conflicted because i'd previously had a disagreement with The Guardian on another story that got kicked up all the way to editorial and I felt was never adequately resolved and was largely swept under the rug.
After that experience I didn't feel that The Guardian were genuinely going to make a best effort to resolve what was their own mess, again.
edit: to add, it drives me fucking nuts every time I hear someone repeat "I heard WhatsApp is insecure". Thanks again, Gruardian.
I suspect this might be the side effect of excessive CYA. I'm not happy with it, but there have been so, so many articles that get the basic premises of tech completely wrong that I think I'd still rather them take an excessive amount of time checking than publish another ill-informed piece.
But it takes a while to verify this if you're not already familiar with it (I'd argue that's a reason why they shouldn't have published the article to begin with, but w/e)
More importantly: your comment leaves the impression that there were notable people in the field who had a problem with the letter. If an expert working in messaging security didn't sign it, you and I both know that's probably just because they weren't aware of it (or, at the time, The Guardian's story).
Here's their apology: https://www.google.co.uk/amp/s/amp.theguardian.com/media/201...
Although, what Sulzberger actually said was:
“Our followers on social media and our readers across the internet have come together to collectively serve as a modern watchdog, more vigilant and forceful than one person could ever be,” he wrote. “Our responsibility is to empower all of those watchdogs, and to listen to them, rather than to channel their voice through a single office.”
https://www.nytimes.com/2017/05/31/business/media/new-york-t...
"Our followers on social media and readers can be ignored a lot easier than a guy in our office, so when complaints come in, we can simply sweep them under the rug"
These days people get so worked up on social media anytime a brand does anything (i.e. people getting mad a cinnabon for their carrie fisher bun pic - http://cbsnews3.cbsistatic.com/hub/i/r/2016/12/27/a9c2ac0c-3...). I think social media can serve as a watchdog for more important issues, too.
It took almost 6 months of badgering for that to finally happen though, despite an extensive and widely signed (by experts) op-ed pointing out how wrong and dangerous it was barely a week after the original article was published, and calls for corrections/retractions started within days if not hours.
> given the frequent failure of other newspapers to publish a prominent apology when they have got things far more wrong than this.
Getting things "far more wrong" matters less when it doesn't put lives at stakes, and you don't need to believe me on that, this correction article makes that point:
> During the review I independently confirmed that a Turkish government official had used the article when, in effect, attempting to deter users from WhatsApp.
Completely agreed, but they do fully concede this in their retraction:
>This made a relatively small, expert, vocal and persistent audience very angry. Guardian editors did not react to an open letter co-signed by 72 experts in a way commensurate with the combined stature of the critics and the huge number of people potentially affected by the story.
It might have taken a while for their internal review to complete but, honestly, what more can we ask for but an honest admission like this? If more media outlets could meet this standard we'd be in a much better place.
Could they have come back to us faster, yes, but an honest, well thought through apology with all these details included is a really strong response and I'm not going to complain.
We can always complain about why not this or that, but it seems we are never satisfied even when we get what we want.
We can ask people to simply not trust traditional newspapers for reporting on stories concerning highly technical and scientific fields.
They all get it wrong sometimes. We should be equally sceptical of all sources of news.
I personally only trust security blogs and Twitters operated by certain security experts when it comes to news about security. I have a list of about 30 or so experts I trust.
I know that's not really practical advice for a typical person, though.
I think the Guardian handled the retraction and apology as best they could, and they deserve props for that, but it seems the hit-miss ratio for infosec stories is very poor for most "mainstream" sources out there (as much as I despise the "MSM" term).
And how do I choose reputable blogs in the first place? Do I trust reputation on HN and Reddit?
In the end, sure some articles will get some things wrong. But I would like to see evidence that they get it wrong more often than any other general source of news.
For crypto, Matt Green: https://twitter.com/matthew_d_green https://blog.cryptographyengineering.com/
For cybercrime, Brian Krebs (though I would call him an investigative journalist rather than an expert): https://krebsonsecurity.com/
For intelligence/counterintelligence/OPSEC, thegrugq: https://twitter.com/thegrugq https://medium.com/@thegrugq
A few of these can occasionally be biased when there's a political edge to something, but some others I trust: Moxie Marlinspike, Daniel Bernstein, Dan Kaminsky, Rob Graham, Thomas Ptacek, Michał Zalewski, @SwiftOnSecurity (semi-parody account, but trustworthy info), Tavis Ormandy
>An investigation by the FBI has concluded that Russian hackers were responsible for sending out fake messages from the Qatari government, sparking the Gulf’s biggest diplomatic crisis in decades.
>It is believed that the Russian government was not involved in the hacks; instead, freelance hackers were paid to undertake the work on behalf of some other state or individual.
They could've easily made the headline "FBI: Qatar hackers of Russian nationality". By making the first 2 words of the headline "Russian hackers", they're obviously trying to take advantage of the recent surge in reports over Russian state-sponsored hacking. Most readers who see that headline are going to assume they meant "Russian state hackers", until they read the second paragraph.
That said, I don't see any factual errors in the article itself.
> "I accept the consensus view of the experts and, in consultation with editors, have arranged for the coverage to be amended and for a note to be added drawing attention to the review and linking to this column.
> I do not agree with critics that the story should be entirely retracted."
Huh? Accepting a consensus view is a really shifty way to avoid acknowledging being blatantly wrong.
I try to avoid making a habit of commenting on things without reading them, and also of over-quickly assuming that others do so.
> This is a lawyers [sic] carefully worded article to avoid being sued [...] Accepting a consensus view is a really shifty way to avoid acknowledging being blatantly wrong.
This leads me to question whether you read the article, or simply picked out snippets to support your preconceptions. Let's take some other quotations:
> In a detailed review I found that misinterpretations, mistakes and misunderstandings happened at several stages of the reporting and editing process. Cumulatively they produced an article that overstated its case.
> The most serious inaccuracy was a claim that WhatsApp had a “backdoor”
^ these look like an acknowledgement to me.
Furthermore, to refute your selectively used quotation above:
> I am not an expert in this field. For the review I consulted suitably experienced experts other than the 72 who had already declared their view. [...] I found a consensus that [...]
The author is accepting the consensus view amongst the experts with whom he spoke, since, as he acknowledges, he is not an expert in the field. This seems to me to be an emminently sensible approach, which most journalists would do well to follow.
Frankly, I think this is a weak response. There is nothing in this investigation they could not have cleared up in January; instead, they dawdled and now they equivocate.
* Whatsapp * FB Messenger * iMessage * Hangouts
They also all believe that the police can look at their Facebook posts because they have special access.
This is precisely why there was minimal reaction to the Snowden revelations - what revelations?
They very likely don't, but that doesn't mean they can't.
Who are those experts?
Further, there is the implication in your comment that Android and iOS are less secure than some other format (assumedly a linux or bsd variant desktop OS) for secure messaging. I'd be shocked if you could find a group of security engineers that even agreed with that. You certainly will find lots of them that disagree, so its in question at least.
I'd go further and suggest that if I made the proposition that from a security perspective you were best served by using e2e encrypted WhatsApp purely from an iOS or Chromebook that I'd gain more agreement from the security community than any other proposition about messaging formats other than "don't use electronic messaging for secret things".
Yes, being able to update their software at will enables them to read messages that have been already sent, even with e2e encryption.
> Further, there is the implication in your comment that Android and iOS are less secure than some other format (assumedly a linux or bsd variant desktop OS) for secure messaging.
Endpoint security is a can of worms. There is no simple conclusion to be taken from my comment, except for the literal meaning.
Or perhaps the 1984 Orwellian explanation - fear of surveillance curtails dissent.
E.g. perhaps there was minimal reaction because while people had always joked about the Govt. reading their messages, when Snowden revealed it was utterly true, and way worse than anyone had supposed, they became afraid to voice dissent about surveillance.
They were right to fear this as Snowden's stated reason for whistleblowing was not the existence of mass surveillance but because the mass surveillance was not for national security but its primary goal was to protect the program of mass surveillance.
Snowden revealed this: that the primary mission of the spying was to keep the spying secret and those who opposed the spying faced the greatest extra-legal retaliatory attacks. [1]
As the recent cataclysmic cyber attacks have shown national defense was not a priority for those 3 letter agencies developing weaponised exploits.
The weaponised exploits they screwed us all over by letting fall into the wrong hands, e.g. Wannacry an American state sponsored cyber-weapon funded by US tax-payer monies that wrecked the UK's National Health Service and now threatens international shipping - oopsie.
[1] Snowden outlines his reasons for turning whistleblower in this conversation with Chomsky & Greenwald https://www.youtube.com/watch?v=IOksJKfapVM
This backup is not e2ee, which means that if the other part is backing up data in Google Drive, then at least part of you WhatsApp history is not e2ee. Yes, it might be encrypted whithin Google Drive by whatever secure methods Google chooses, but not by you.
"People believe that you perform due diligence on matters critical to their lives and safety."
And at the bottom of the open letter many security experts have signed in support. That is, "signed" in the colloquial sense.
Small digression-- let's say a person tasked with reviewing a story in the Guardian is not an expert in security. They would really love some way to start with one or two security experts they know and trust and "fan out" to other experts based on their relationships.
Is there a quick and easy way for the journalist to do that by looking at the names of cryptographers listed at the bottom of a webpage?
Also: can someone explain what "due diligence" means? Is it the expectation here that a journalist not only report what would look reasonable to a non-journalist reader, but also use their considerable skill to ensure that they present their readers with verifiable facts, to the best of their ability? Even if it takes a considerable amount of time and effort on their part? Even if verifying the evidence relies on clunky, cumbersome tools that no one wants to spend time using?
You can get faster results by emailing hn@ycombinator.com. Not to mention more reliable; I only saw this randomly just now.
Mind you, stories load faster via AMP than the app, but still.
Edit: Actually, repeated loads take exactly as long (seven full seconds); but the scrollbar already has the correct page size. Probably some buggy scripting.
I like this title better, and the likelyhood that I'd have clicked on it would have been less with the original.
Just because somebody wrote that rule down doesn't mean you have to follow it, much less enforce it. Do you believe in it yourself, in absolutely every case, or do you follow it just because it is a rule? I'm not trolling, just curious. I find to many people on the net follow rules blindly. Rules are crystallized attitudes of communities. They shape the community, but the community also shapes the rules. If people would never break a rule, not even a little bit, they would either never change, or only change to be more strict over time.
Why am I loosing so many words over this? Why do I say you shouldn't bother that much, but then myself bother so much to write this? Because I don't want the moderation on HN to become like Wikipedia or Stack Overflow.
Personally I couldn't care less about the "Guardian admits…" narrative. The article is a genuinely informative analysis that would be done a disservice to be framed as support for an apology.
I don't think you're trolling. I understand your viewpoint. I'm against selective enforcement. If there's a rule, and it isn't applied evenly to everyone all the time, it is a weapon of oppression. It is like the electronic form of white privilege.
Submitters: please don't rewrite titles unless they are misleading or linkbait: https://news.ycombinator.com/newsguidelines.html.
The idea on HN is to let readers make up their own minds. If you'd like to say what you think is important about a story you submit, that's fine, but please do so in the comment thread. Then your view is on a level playing field with everyone else's.
* If the original title begins with a number or number + gratuitous adjective, we'd appreciate it if you'd crop it. E.g. translate "10 Ways To Do X" to "How To Do X," and "14 Amazing Ys" to "Ys." Exception: when the number is meaningful, e.g. "The 5 Platonic Solids."
* Otherwise please use the original title, unless it is misleading or linkbait.
https://news.ycombinator.com/newsguidelines.html
Use the original title. I've seen many informative titles smacked by this and made less informative. Here, an informative title is made less informative and clickbaity, with no action taken so far.
https://news.ycombinator.com/item?id=13766092
The submitter is editorializing.
"If you flag something, please don't also comment that you did."
I think we all know what is written in HN rules.
So what, I like the title. I don't think anybody should do anything about it. I think we should all take it easy and enjoy an interesting article.
The entire story was based on the question of "what do you do when someone you're communicating with using encryption changes keys?" Whatsapp chose to dynamically use the new key, rather than fail & force the user to verify the new key in some out-of-band way. This was described as a "backdoor" in the guardian story. That was simply false. Even calling it a vulnerability is a mis-understanding of how cryptography works and of the risk involved in that design decision.
That said, the open letter plainly states "WhatsApp effectively protects people against mass surveillance."
How do they know? From this, and the entire tone of the letter, it looks to me like they're still implicitly trusting that WhatsApp does what it claims to do. I see absolutely no reason to do so, and am utterly baffled that top security experts do.
You don't need access to the source code to perform this analysis.
Furthermore, if you can verify that the app does what it advertises, you don't need to trust their infrastructure. E2E takes care of that.
I think it's much easier to conclude that WhatsApp protects peoples messages from leaking or being abused by providers and other "softer" merits.
Yes, it is.
Mass surveillance is, by its very nature, defeated by E2E encryption even without identity verification.
Are you thinking of targeted surveillance?
You can argue that WhatsApp itself de facto doesn't effectively protect (against mass surveillance) because it only works with instant messages and a lot of data isn't instant messages. You can argue that there is still mass surveillance of metadata. And that governments could enact secret laws to force vendors to engage directly in mass surveillance of their customers through the OS (less likely in the US, more so in China, especially as Google isn't present).
Sure, it's a nitpick. It's implied that it's effective because it's a good way to use E2E. But it not necessarily explored in the article whether it effectively protects people. I'm sure someone thinks that PGP was effective against mass surveillance too. So it becomes and issue over what you think is worth protecting.
Did you do that before signing the letter?
> Furthermore, if you can verify that the app does what it advertises...
Without reproducible builds you can only verify the specific version of the app on your device. It's quite a leap from there to say 'Whatsapp is safe for you, too, regardless of your use-case'.