There's a lot of people here saying this should have happened faster, they're likely right, but also, given how extensive and thorough this is, it is more likely an example of how old-school editorial rigour just takes a lot of time.
There's a lot of people here saying this should have happened faster, they're likely right, but also, given how extensive and thorough this is, it is more likely an example of how old-school editorial rigour just takes a lot of time.
The technical side of the study is very well understood by practically anyone. People have different type of opinions on the matter not because they misinterpret the technical details but because they have different expectations on how the privacy situation will end up being for different groups in the light of this knowledge.
So all of this makes it way harder to define if the story was overblown or not. Apparently Guardian editors ended up thinking that it was indeed, after giving it a long consideration. This is not a technical fact (and it cannot be), it is just their interpretation of it (and also the interpretation of many security experts but that's not the point).
It could be that I am the one who is missing something. That's why we are discussing here, right? :)
You are correct that it is impractical to "exploit" the chosen design, I think the bigger issue their portrayal of this as a vulnerability rather than a security suggestion.
My general point is, even if they made some technical errors as well, their consideration, I believe, was more about the consequences of their interpretation.
I didn't remember that and it seems to have been removed from the article (with a note on the end which I have missed). Well, that's just sensationalism and must have been picked up way earlier in a sane review process. I stand corrected.
From this linked article.
Those who value maximizing security at all costs, even to UX, disliked this default.
WhatsApp was trying to switch end-to-end encryption to on-by-default for its over a billion users. An understandable requirement of doing so was to ship E2E encryption in such a way that did not involve changes to the UX.
Whether or not this tradeoff is the best compromise is certainly debatable, but it is just that: a tradeoff, not a "backdoor", not a "vulnerability", and not a "flaw". It's a deliberate design decision.
Why is it not a "backdoor", not a "vulnerability", or "flaw"? Well, let's examine what would happen if the default were reversed: let's say users were notified by default. Would this keep them more secure?
I have doubts. These notifications are not high signal or immediately actionable. They do not indicate an attack. They indicate "a key changed" and whether or not that's abnormal is up to users to determine. The overwhelming majority of these events will be innocuous, leading to alert fatigue. It's also unclear how well an average end user would even understand or be able to react to these alerts.
I am certainly willing to give WhatsApp's UX designers the benefit of the doubt here. UX design is hard and the tinfoil hat crowd saying things to the contrary have a history of producing unusable software by demanding security misfeatures which tick off a box on a threat model without actually improving user outcomes.
While some people in the tinfoil hat crowd seem to think bombarding users with a bunch of low-signal security alerts is a good idea, practitioners working with IDS/SIEM systems probably have a different opinion: that low quality / low signal alerts are worthless.
There are solutions to providing high-quality signals about key change events to users without asking them to manually confirm key fingerprints in person, but they are complicated, haven't been largely deployed, and it's still unclear how they'll work...
I'm talking about CONIKS and Google Key Transparency, which implement logs which users' own devices can monitor to discover changes to their keys as advertised through a key server. These systems can ask a very simple question to users when this happened: "Did you just log in on another device?" If they didn't, the user can select no and publish an alert indicating they were compromised.
Apparently if you're so wrong that an entire field disagrees with you, you can get anything printed in the Guardian.
I suspect this might be the side effect of excessive CYA. I'm not happy with it, but there have been so, so many articles that get the basic premises of tech completely wrong that I think I'd still rather them take an excessive amount of time checking than publish another ill-informed piece.
But it takes a while to verify this if you're not already familiar with it (I'd argue that's a reason why they shouldn't have published the article to begin with, but w/e)
More importantly: your comment leaves the impression that there were notable people in the field who had a problem with the letter. If an expert working in messaging security didn't sign it, you and I both know that's probably just because they weren't aware of it (or, at the time, The Guardian's story).
They emailed me asking why I hadn't signed and if it meant that I didn't agree with the petition.
Funny thing, two reasons why I hadn't signed. First, it was because I only caught the petition when it was already deep with many people I respect a lot and I felt I added nothing
And second, I was conflicted because i'd previously had a disagreement with The Guardian on another story that got kicked up all the way to editorial and I felt was never adequately resolved and was largely swept under the rug.
After that experience I didn't feel that The Guardian were genuinely going to make a best effort to resolve what was their own mess, again.
edit: to add, it drives me fucking nuts every time I hear someone repeat "I heard WhatsApp is insecure". Thanks again, Gruardian.
Here's their apology: https://www.google.co.uk/amp/s/amp.theguardian.com/media/201...
Although, what Sulzberger actually said was:
“Our followers on social media and our readers across the internet have come together to collectively serve as a modern watchdog, more vigilant and forceful than one person could ever be,” he wrote. “Our responsibility is to empower all of those watchdogs, and to listen to them, rather than to channel their voice through a single office.”
https://www.nytimes.com/2017/05/31/business/media/new-york-t...
"Our followers on social media and readers can be ignored a lot easier than a guy in our office, so when complaints come in, we can simply sweep them under the rug"
These days people get so worked up on social media anytime a brand does anything (i.e. people getting mad a cinnabon for their carrie fisher bun pic - http://cbsnews3.cbsistatic.com/hub/i/r/2016/12/27/a9c2ac0c-3...). I think social media can serve as a watchdog for more important issues, too.