End-to-end encryption does not prevent Facebook from accessing WhatsApp chats
medium.com
medium.com
All of this makes Zuckerberg's claims that law enforcement can't read the messages because Facebook can't pretty misleading. Law enforcement could get the backup from Apple/Google and the key from WhatsApp and have access to the whole chat history. There are apps already available to help you through this process. [3]
--
[1] Media and messages you back up aren't protected by WhatsApp end-to-end encryption while in iCloud. https://faq.whatsapp.com/en/iphone/20888066/
[2] Media and messages you back up aren't protected by WhatsApp end-to-end encryption while in Google Drive. https://faq.whatsapp.com/en/android/20887921/
[3] Elcomsoft Explorer for WhatsApp 2.30 can now download and decrypt Android user’s encrypted WhatsApp communication histories https://blog.elcomsoft.com/2018/01/extract-and-decrypt-whats...
Once the terminal is authorized, the backdoor channel is opened in perpetuity and there is no more interaction with the user, it could happen at any time on your phone and you have no way of knowing short of complex reverse engineering of the app or network stream.
And there is absolutely nothing stopping Facebook from inserting code into WhatsApp to skip the UI prompt when initially setting up the back channel, it would be a few lines of code. With Google or Apple's collaboration, a suspect's terminal could be surreptitiously updated to a vulnerable version that could open the channel, then updated again to the stock version, all in a matter of minutes, allowing law enforcement perpetual access to the stream of decrypted data. It's likely NSA has sufficient private key material to orchestrate something like this without any collaboration.
The (not) news here is that any end-to-end encryption scheme is just a way to thwart packet sniffing hackers and telcos, and it has no effects on the providers themselves, you still need to trust their binaries. Open source and audited open repositories were never more relevant.
I don't even know why it goes into backup folder details and things, as if they matter. If Facebook wanted to change the code to read your chats, they wouldn't have to count on the existence of a specially named folder, they could just change the code to send the chats to them directly.
It is written for the people that don't know better and believe end-to-end encryption will always be safe, even though Facebook controls the source code and therefore can do whatever they want.
Open source ones would be a lot less likely to get away with it.
"(We collect) hardware model, operating system information, battery level, signal strength, app version, browser information, and mobile network, connection information including phone number, mobile operator or ISP, language and time zone, and IP, device operations information, and identifiers like device identifiers (including identifiers unique to Facebook Company Products associated with the same device or account)
"...how you interact with others using our Services, and the time, frequency, and duration of your activities and interactions), log files, and diagnostic, crash, website, and performance logs and reports. This also includes information about when you registered to use our Services, the features you use like our messaging, calling, Status, or groups features, profile photo, about information, whether you are online, when you last used our Services (your "last seen"), and when you last updated your about information.
"We collect device location information if you use our location features, like when you choose to share your location with your contacts, view locations nearby or those others have shared with you, and the like, and for diagnostics and troubleshooting purposes such as if you are having trouble with our app's location features. We use various technologies to determine location, including IP, GPS, Bluetooth signals, and information about nearby Wi-Fi access points, beacons, and cell towers.
"We receive information about you from other users and businesses. For example, when other users or businesses you know use our Services, they may provide your phone number, name, and other information
"Businesses you interact with using WhatsApp provide us information about their interactions with you.
This reminds me Windows 10 collecting color of the device, in that it is unnecessary for operation but enough to pinpoint a person in combination.
These applications are super complex and you can't count on all eyeballs detecting a potential backdoor. And, you don't know if the code in the repo matches what you download from the App Store.
As for not knowing what has been downloading (if someone tempered with), the best approach is compiling it on your own.
Eventually, maybe. How many eyeballs and how long to find Heartbleed?
Bringing this up as an argument is a sensible as claiming that transparency and democracy isn't any better than a dictatorship because there is still corruption.
The reason I ask is that this is an oft repeated claim about open source by developers yet when I talk to security people they don’t seem to care about open source nearly as much. To them inspecting binaries is table stakes anyway.
Meanwhile people write backdoors that aren’t obvious for fun. http://underhanded-c.org/
You are also right that appstores are a problem. However, one of the nice things they do is using signatures to prevent tampering with the builds. So having a build system that produces reproducible builds and signatures means users can check whether things line up.
A bigger problem is the reliance on the phone network for identity. A lot of these chat clients insist on using telephone numbers for identifying users. This has been used to shut down chat networks in countries with telecom operators that are collaborating with governments.
If you want to stay secure, most of the chat apps out there are problematic at some level. Signal is one of the very few decent options out there. It is one of the few solutions that has both open source clients and servers and a wide community of people using it and scrutinizing it. With e.g. whatsapp, you are at the mercy of a multinational with a track record of indifference and negligence towards the goal of preserving their user's privacy and, worse, a strong incentive towards doing the exact opposite.
Unless the open source app is transparently built and app store deployed from a public build server, it's very easy for the owner to inject a back-door into it.
There's no mechanism built into the app stores to validate an app against its source code.
So the owner could checkout master, add a back-door, build and publish to the app stores, and you'd update, never knowing you're exposed.
Nothing is 100% safe. It's just dependent on how much trust you assign.
Commoners have no transparency if Facebook is data mining who they talk to, how often, what type of content and for how long. From the anecdata we have, we know some of this metadata is being mined (contacts at this point).
1) Claim that no data is harvested, only unimportant metadata that you shouldn't be concerned about, so there is no need to worry!
2) Gradually expand the definition of "metadata" to include all desired data.
Of course, metadata sometimes contains even more information than the data itself, so framing it as "unimportant" is already incredibly dishonest.
That doesn't really help Joe User, but it's possible to do it.
But yes it is an overly complicated mechanism for what would be a simple change by Facebook and one that people have raised here since the original announcement.
So if you haven't already switched to Signal (or better), there's no point in waiting around. WhatsApp's loss of default end-to-end encryption is inevitable and it will come soon.
I expect it's frequently the same people.
Weird article. If modifying the WhatsApp app is on the table, there are trivial ways to send decrypted messages elsewhere.
I guess that if the app starts looking for the chats within the devices, it would be much easier to spot than it would if the messages were just analyzed as they went through WhatsApp's servers (so that's what the encryption is for).
I’m not sure whether or not a publisher could opt into providing such assurances, either. You could imagine that with a deterministic build regime, something might be possible, at least if you had rooted your phone so you could directly inspect the install footprint.
Here is what happened few weeks ago : I exchanged whatsapp messages with a well known founder. Lo and behold - news about him and his startup are all over my facebook feed. Some which was published years ago.
We live in echo chambers.
It's not as convenient, but misplacing trust into corporation that has no interest in your privacy is dangerous.
no piece of hardware or software is safe from evil deeds of people building them.