How to Tell Us a Secret
nytimes.com
nytimes.com
WhatsApp, with more than 1.2 billion active users, is one of the easiest ways to send secure information.
“With WhatsApp, it’s as simple as sending a text message — but it’s encrypted,” Mr. Dance explained.
I'm not a security expert but I think this is not exactly the best practice. This may have been true pre-fb acquisition but there has been changes to how WhatsApp behaves, especially server side storage.Also the departure of WhatsApp founders under uncertain terms, doesn't give me much confidence with usage of that app for clandestine operations.
Perhaps folks here who are well versed with the state of the app can chime in.
https://www.engadget.com/2018/08/29/whatsapp-google-drive-ba...
Personally, I don't trust FB, but for a non-technical person there aren't any clearly superior alternatives.
I have not used Wire beyond a test install but it indeed looked promising. In a sense it's even better than Telegram that allows you to just use usernames but you have to add a phone number anyway (also if the other Telegram user by any chance has your phone number in their contacts then your identity is revealed anyway).
But I'd say that Telegram's apps (mobile and desktop both) are superior too all the major IM apps around. I wish they could be more forthcoming about openness.
This can be done in a number of ways from subpoenas to hacking to threats/blackmail.
In the case of WhatsApp, we do have public confirmation of the Signal team working with WhatsApp to implement end-to-end encryption. [1]
Sigh.
However, the generally accepted quote syntax on HN does not use code blocks in the first place.
> *Quote goes here*Some users don't, there is no one unambiguously correct method, and the 2nd- most common variant I see has several obvious detriments.
The fact that the "show us your code" feature seems to be predominantly used for blockquotes, on a generally technological site, strongly suggests a failure to correctly match user expectations and needs.
Though as metacommentary in infotech, SV, and YC, the message couldn't be clearer.
Seems more likely that it's a lack of instruction on the comment page. Discord manages to fit all of its formatting into the whitespace under the chat input....
I don't think the major problem is that `/^ {4}/` lines don't wrap in a way that's useful for quotes; it's that there's no way to format quotes so people use the only formatting element HN has.
Technically, HN has a couple other formatting elements.
It is a standing convention to use the following syntax for quotes here:
> *Quote text here* pre { whitespace: pre-wrap; }
https://www.w3schools.com/cssref/pr_text_white-space.aspThat's what I've included in my own HN Stylus stylesheet for years. Works on Desktop or Firefox/Android, but other mobile browsers don't support it, for lack of extension support.
Updating the HN markup to offer true blockquote support would be a more complete, though less trivial, solution.
I've suggested the first myself repeatedly.
pg asked how to fix this, and was given the solution, on HN, nine years ago:
https://news.ycombinator.com/item?id=592603
The suggestion's been made numerous times:
https://hn.algolia.com/?query=whitespace%20pre-wrap&sort=byP...
Format your posts appropriately - that's the sole burden of the writer, no one else's.
Don't blame the user.
In researching WhatsApp a while ago, I came across this in a Quora post "But one more point I want to stress here is that, though whatsapp is allowing end to end communication , it does not necessarily mean they can not analyse the encrypted data. in cryptography we call it Searchable Encryption." (https://www.quora.com/Now-that-WhatsApp-can-no-longer-read-y...)
I don't know whether it is accurate to WhatsApp, but it's certainly food for thought and also made me wonder how many other end-end encrypted systems use it.
I personally don't trust FB. WhatsApp is not open source, so I have to trust what FB says. I don't.
There are many important considerations in secure messaging and the EFF has done a reasonable job of trying to cover the subject in their series on messaging (https://www.eff.org/deeplinks/2018/03/secure-messaging-more-...)
It not being open source is a political argument, not a technical one.
EDIT: I ended up doing just that. It took roughly 5 minutes (most of that was making sure I had my PATH for Java set up correctly on this machine) to get decompiled Java code ready to inspect.
If I can compare the open source to the reverse engineered code to see what I'm really using/getting, that seems like a technical advantage. Also, all of the reverse engineered code I've worked with has been difficult and time consuming to digest (missing var names, comments etc); open source gives me a technical advantage in analyzing and understanding the code. Lastly, looking at a companies open source lets me assess their technical sophistication and practices which also seems like a technical advantage.
I haven't spent much time thinking on this subject, but the political aspect seems to be the line of thinking that says: you will engender trust by making a project open source.
Is your reasoning similar?
Also are there good tools for reverse engineering iOS deployments?
I'm not an Apple consumer, I don't know anything about iOS in particular.
There are many; since apps are native on iOS a standard disassembler would work. But there are many more specialized tools, such as class-dump and Hopper.
My point is open sourced code is much more readable and hence more accessible and you can build it yourself and use it most of the times.
Meanwhile, it's not 1994 anymore, and people who know how to look for bugs can (I know this is hard for some people to wrap their heads around) look inside of binaries and draw conclusions about how programs work. There's a name for it; it's a kind of engineering.
Build it yourself and host/use your own app builds and server instances. But then I'll have trust the company I bought my VPS from to host my Matrix instance, isn't it?
WhatsApp messages are encrypted end-to-end between each person using it. The whole point of end-to-end encryption is not having to trust the server-side storage.
Furthermore, WhatsApp uses the Signal Protocol-- the state-of-the-art for secure messaging protocols.
The worst that WhatsApp can see is "who's talking to who?"
Finally, the adoption of the Signal Protocol in WhatsApp came long after the Facebook acquisition.
So, no. It wasn't better off pre-fb.
That can be a problem when you're a whistle blower contacting a journalist.
(Server-side storage is a non-issue, due to the encryption protocols in use. It doesn't matter if you distrust Facebook, they aren't going to be able to read your messages. End of.)
The main problems with WhatsApp are as I can see:
- they scoop up metadata
- they upload the data more or less plaintext to Google for backup. (I personally dislike but trust Google but not everyone trusts them.)
- they paid way to much for it to not try to monetize it in all kinds of crazy ways
How do we know this hasn't happened already?
How do we know it won't happen tomorrow?
As has been pointed out here in the chat already: Scott (and others) have reverse engineered it.
> How do we know it won't happen tomorrow?
Consequences.
Even Facebook seems to realize that is the nuclear option.
That said there is a number of places this can still go wrong, but they are equally true for any mainstream client (edit:) and non mainstream clients have their own issues.
Personally neither like nor trust Facebook at all so I try to minimize contact.
But I could also just dex2jar + JD-GUI the Android app and study the decompiled Java code to see what they're doing.
Edited to add: https://twitter.com/CiPHPerCoder/status/1042870740880637952
I use WhatsApp without doing that (on iOS), but it does require other people to contact you first before you can have a conversation.
Follow-through on WatsApp's initial verification step using some other channel before you assume the communication is secret.
Not really, given keys are centrally managed, it is fairly straightforward for WhatsApp to setup MITM intercept.
In fact they don't even need to push a malicious client etc, they just need to push a different public key than the sender/receiver's actual ones when contacts mutually add each other and this will quite simply allow MITM interception unless the people do key verification in person. If what the whistle blower is trying to do is stay anonymous - would they physically meet the reporter immediately?
They could even push new keys to existing mutual contacts and get away with it since most people don't display or again verify key change messages.
Lastly, most people turn on message backup in Google drive which is not encrypted - so a warrant or an account hack would suffice.
WhatsApp implementation can protect basically from malicious non state actors. That's a great thing in today's world in itself but be aware of the underlying tech.
What we have now is (mostly) talk-shows roughly passed off as genuine journalism, but really it's pretty obvious that it's the lowest common denominator kind of gossip-spreading.
https://medium.com/@Susys/lets-change-this-journalism-motto-...
Instead, the NYT wrote an article about how dangerous Saddam's WMDs were and how he was supporting terrorism, even though it had nothing to do with 9/11. Nowadays they defend themselves by saying "everyone agreed at the time". It's not true.
Mainstream media is a rubber stamp for corporate and state interests, just propaganda. They rubber stamped Bush's war's just like they rubber stamped Obamas, they will probably rubber stamp Trump's too. Yes, they also contain true information, but they are still just corporate/state propaganda.
If they aren't willing to fact-check the govt for an issue as serious as going to war, especially with all the red-flags that were out there, like the fact that Colin Powell, a year prior to holding up anthrax in congress as "proof" that Iraq had WMDs, was giving speeches a year earlier claiming there was no evidence Saddam was making WMDs. Like the fact the Bush admin certainty about WMD was far greater than the actual intel communities claims. No one fact-checked them.
And, by the way, the NYT fired the reporter and an editor over that mistake, wrote numerous articles on how it happened, and instituted new rules to prevent similar things happening in the future.
And the problem is compounded in that the internet, for all of its glories, has also taught folks that their opinions/beliefs/dogma are just as valuable as actual facts.
I don't know what, how, or why. But the only two things different now to, say, the 80's in terms of bullshit journalism is its ability to reach people directly in a 'one-on-one' setting and its ability to be echoed with no challenge in online forums and the like.
You may be thinking of "unnamed sources" or "anonymous sources". Those people may be quoted on a factual basis, but the reporter has an obligation to obtain the same kind of confirmation of their information as any other investigative lead.
Actually, that's not a tip by the NY Times definition:
A strong news tip will have several components. Documentation or evidence is essential. Speculating or having a hunch does not rise to the level of a tip.
Your implication is that because a story contains no named sources, the information is not legitimate, or not reliable. I would submit to you that this is exceedingly rare at a reputable newspaper like the New York Times, and although all newspapers are sometimes mislead by their sources, or otherwise get things wrong, when this happens at a paper like the Times, it is universally followed by a correction.
In other words, the Times is not going to print a story based on anonymous submissions without any further vetting, or investigation. They're going to seek independent corroboration, they're going to involve other experts, and they're going to ask questions of the principals.
There is tons of NYT articles that are factually wrong and have never been updated.
I was just going to add that just based on the articles I read (in the NYT and elsewhere) that are within my field of expertise and how wrong they get basic facts, cause and Effect, etc. I don’t think I can trust them with reporting of other domains either.
News outlets across the board have entertainment value at best, nothing else.
After 9/11, New York Times wrote an article about how dangerous Saddam's weapons of mass destruction were. MSM just takes Bush/Obama admin + intelligence communities claims at face value. It is supposed to be their job to fact-check govt, but instead they are just a rubber stamp for govt propaganda. The only admin they have been capable of properly fact-checking is Trump admin and that's only because their corporate sponsors & donors are anti-Trump.
When the intelligence community makes a claim, media fact-checks that claim by asking the SAME intelligence community to verify.
If they aren't willing to put in the work to be trustworthy, there's no reason to give them any trust.
Libel laws say that if you write something about someone that you believe COULD be true, it's not libel.
So imagine you are a writer who discovers a sensationalized claim you really want to print. But it could be completely false.
If you fact-check it, and it turns out to be false, now you know it's false. You could be liable for libel if you decide to print it.
However, if you don't fact-check it, you get to print the claim because you sincerely believed it could be true. Also, you get the advantage of getting the story out quicker, and you can always change it later if someone complains.
In other words, a policy of publishing without investigation would not limit libel liability. If the information is false, and the publishers did not have a good-faith belief that it is true, then they might still be held liable.
Come on, let's see some examples. Should be easy to find at least a few, since there are "tons" of them.
http://www.foxnews.com/entertainment/2018/05/30/new-york-tim...
https://www.washingtonpost.com/blogs/erik-wemple/wp/2017/08/...
Small print corrections issued days later, are not effective in undoing the damage an erroneous blaring headline did.
Cut through layers of agenda pushers and give me facts.
They can do this by reporting facts, but generally it is easier to do this by reporting stuff people want to read, which includes facts and non-facts and things that may or may not be factual. This also generally involves summaries which aren't factually true as they drop relevant details, but which are close enough that people tend to tolerate them (see any reporting on a scientific paper ever).
Also, an "an anonymous source said X" could be factual, but the implication is that X has some level of truth when the only known fact is that in reference to that X was said by an anonymous source.
You've never regularly read UK newspapers I take it?
I wish that was their primary purpose, a few of them never let a story get in the way of their agenda.
This is not useful most of the time. I've never seen a viral correction. Damage is done.
Second, the point is not that reputable newspapers perfectly correct their readership's understanding. The point is that reputable newspapers correct themselves. Newspapers reputations are built on that honesty, and astute readers will have an understanding of a paper's track-record of accuracy and corrections. Less astute readers will rely on those that do track such things.
Citation needed.
Here are some counterpoints to your assertion that they would not print a story not independently corroborated.
https://en.m.wikipedia.org/wiki/Jayson_Blair
http://thefederalist.com/2018/05/28/media-double-down-after-...
https://www.nationalreview.com/corner/columbia-and-new-york-...
http://ajrarchive.org/Article.asp?id=4379 [duke lacrosse reporting]
https://archives.cjr.org/behind_the_news/wrong_wrong_wrong_w...
A great example of the Times and their “anonymous” sources (and lack of corroboration) http://latimesblogs.latimes.com/washington/2008/02/maybe.htm...
Suggesting that the Times “isn’t going to print a story..without further vetting” is based on some idealistic view of the Times, but not necessarily on a reality based on their history. Didn’t they also just print an anonymous op-ed, providing zero opportunity to challenge or verify any of the claims contained therein?
The Times is a reputable as any other news outlet, but Reuter’s they are not. They are laced with a history of subtle bias and outright dishonesty when it suits them.
The first link regarding Jayson Blair is the clearest counterpoint, showing a Times reporter fabricating story. This is absolutely an example of the NYT failing. But the same Wikipedia article says that the NYT, on their own initiative, investigated and fired Jayson Blair in a very public manner.
> After internal investigations, The New York Times reported on Blair's journalistic misdeeds in an "unprecedented"[14] 7,239-word front-page story on May 11, 2003, headlined "Times Reporter Who Resigned Leaves Long Trail of Deception."[2] The story called the affair "a low point in the 152-year history of the newspaper."
To me, publishing Jayson Blair's articles is a huge mistake by the Times. But the way they handle it proves that they do hold their journalistic values in high regard.
The 2nd article itself admits that what the Times published is supported by many others in the media. (Their point is that the entire media is lying.) The audio proof that the 2nd article mentions is also not included, so I don't know if I should trust it more than I trust the Times.
The 3rd link is not easy to understand for me since there isn't a lot of context.
Better fact-checking tools in the hands of the publisher is critical here. It's ultimately on the them to decide if it passes the smell test.
I'll give publishers the benefit of the doubt that they at least attempt to corroborate anonymous tips with other sources. Perhaps some more accessible forms of anonymous expert networks with a trust/reputation system built-in can help, though the cynic in me sees how easily platforms like that can be manipulated.
Harsher consequences for publishing false news is a slippery slope. It's necessary at a certain level, but quickly runs up a slippery slope that can end up with tightly state-controlled media like in other countries.
Those sources aren't "anonymous sources," they're more accurately called confidential sources.
You may see an story backed by no public sources. You then have to make a decision about whether you trust the publisher to have adequately checked the story using private sources.
If the newspaper gets information from a truly anonymous source (say a classified military memo), they need to verify that it's authentic before they publish. They may do that by checking as much of the memo's content as they can and calling up people in the Pentagon and asking if they've seen that particular memo. Those people may not be willing to confirm the memo publicly (because that may open them up to legal problems), but if if their identity is kept private it's less risk to them so they may be willing to confirm it.
What Makes a Good Tip?
A strong news tip will have several components. Documentation or evidence is essential. Speculating or having a hunch does not rise to the level of a tip.
https://www.thewrap.com/media-enablers-harvey-weinstein-new-...
The NYTimes should be the last company anyone should be telling secrets to. We have social media. People should post it anonymously to social media than an establishment organization like the NYTimes.
Hell post it on HN. I trust HN and the mods here more than I trust the editors at the NYTimes.
Also, news companies aren't immune to "fake news". The news industry have spread their fair share of "fake news". And their fake news causes wars and the suffering of millions of innocent people.
If you really cared about fake news, then you should be more worried about the news companies than social media. It's odd you are not. But I guess you trust a couple of highly biased editors tied to the establishment more than an open platform like HN. I frankly trust HN far more than the nytimes. HN isn't perfect, but you are far more likely to get the truth here than in the nytimes. Certainly the mods here do a better job of keeping things even-keeled and less biased.
The Weinstein story was researched heavily by reporters for (years?) and published by the New Yorker and the New York Times, for which they jointly won the Pulitzer Prize.
News outlets never had the ability to silence truth, just limit how easily it could spread. You could still self publish your truth or tell everyone you know, the same thing social media allows.
>If you really cared about fake news, then you should be more worried about the news companies than social media. It's odd you are not
Media companies are perfectly capable of using social media to spread their propaganda. It's likely easier, as it allows them to craft separate versions that appeal to different people.
grep "gpg" - no results
grep "pgp" - no results
What in the what. Oh come on, how can you go through all this effort writing how share secrets with them, and there's zero mention of an actual public key?It's not there.
Edit: I do see the sub-linked page now, easily missed with it just being a hyper link on the phrase "tips page". But as my original comment mentioned, it's not on the article page (directly) at all.
To the user downvoting me: yeah sorry the original comment still stands and is 100% accurate. If you have something meaningful to add to the conversation actually add it.
Yeah, your original comment is 100% accurate. But is it so hard to click another link? You are technically correct but you are just doubling down to preserve your "correctness" instead of admitting you didn't look hard enough.
To the user downvoting me: yeah sorry the original comment still stands and is 100% accurate. If you have something meaningful to add to the conversation actually add it.