Facebook to integrate the infrastructure for WhatsApp, Instagram and Messenger
nytimes.com
nytimes.com
I don't blame NYT for getting this wrong wrt WhatsApp but it bears repeating: if you let someone else broker the key exchange, you trust them implicitly. That is to say that IMO this is not truly trustworthy "end to end encryption". To add insult to injury, WhatsApp permits rekeying to take place without any indication to the conversation's participants [in the default settings].
Sort of.
Yes, they could serve you a MITM key, but it would be easily discoverable when you compare security codes in the client. And since the client is widely distributed on major app stores, it would be very risky to ship a compromised client.
Ultimately key exchange is a hard problem to solve. Notice that Signal doesn't do anything that much different; Signal does the key exchange and unless you verify each user's key offline, you have to trust it. Both WhatsApp and Signal have an option to display a notice when keys change, but Signal's is on by default.
Overall it's still pretty damn good. WhatsApp is perhaps the only major form of consumer communication where, by default and with no opt-out, every single chat really is fully encrypted using a widely respected protocol (libsignal). That's not nothing.
Let's not forget Signal is FOSS and has reproducible builds (https://signal.org/blog/reproducible-android/). This makes it far easier to trust its verification code.
Another interesting extension of reproducible builds: https://wiki.mozilla.org/Security/Binary_Transparency
I'm no Android or iOs dev, so I might be wrong, but to my knowledge there is no feature to push an app update specifically to a narrow set of devices?
So at the very least, third parties (Apple/Google) would have to be involved in such an attack. This removes some entities from the list that could create an attack.
Also, Apple/Google have a big reason not to play such games. Their app stores are partially so popular because they, as companies, are trusted. Apple/Google would only do this if they'd be legally required to. IF they were involved, even against their will, this would mean tremendous risk to trust in these companies, meaning risk to the stock. And for a publicly traded company, there is no bigger motivator. Apple/Google would get out all the lobbying power they have, trying to fight off whatever coercion tool the US government uses against them to make them comply.
Even if there'd be no opposition from Apple or Google, people outside would notice sooner or later that they've got malicious updates. If they use it once or twice, they might go undetected, but if governments or other entities start using this as a vector repeatedly, it will get to the public.
This doesn't mean that I think that these issues aren't important. Reproducible builds, binary transparency, gossip protocols, all these things are very important areas to invest research in, but right now they aren't a vector that is being abused on observable scales.
Yes, it's possible to target "narrow set of devices" by using Device Catalog. An excerpt from the ToS:
> Google Play Console Device Catalog Terms of Service
> By using the device catalog and device exclusion tools in the Play Console (“Device Catalog”), You consent to be bound by these terms, in addition to the Google Play Developer Distribution Agreement (“DDA”). If there is a conflict between these terms and the DDA, these terms govern Your use of the Device Catalog. Capitalized terms used below, but not defined below, have the meaning ascribed to them under the DDA.
> 1. The Device Catalog allows You to review a catalog of the Devices supported by Your app and search the Devices by their hardware attributes. It also allows You to exclude specific Devices that are technically incompatible with Your app.
I wasn't aware of Binary Transparency, thanks! A cool idea, akin to Certificate Transparency.
So Signal can learn who talks with whom via requests going through their LDAP-like server. They can get an idea how long calls are, and if it was a vid or audio call. They know the times of communication.
You know, they can see the metadata. When's the last time we had problems with metadata? The POTS network? Yep.
And you're indeed right the client has reproducible builds. But the server side certainly doesn't. And we have no way to ascertain that.
Yes, metadata is a problem, particularly with calls. However, Signal recently added the sealed sender (https://signal.org/blog/sealed-sender/) feature which makes the server blind to who the sender of a message is.
> And you're indeed right the client has reproducible builds. But the server side certainly doesn't.
That's true, but the server side is much less important when it comes to cryptographic assurances.
Signal is definitely not a panacea, but by many counts it's better than anything else that currently exists and has any semblance to something a typical user can use.
Like a lot of things it boils down to your threat model. If the broker or a state are your adversary, it wouldn't need to be a general design feature to behave this way but it could instead target you at the time of key exchange. Not an implausible scenario for reporters and their sources, e.g.
Those folks are especially vulnerable because they might be led to believe claims of "end to end encryption". Put that together with those default settings and interception and impersonation can happen right under your nose.
Maybe the client itself is generating the keypair. In this case, the only issue I can see is the following: when the user wants to communicate with a friend, how can they be sure that the profile they are sending messages to (as displayed by their user interface and communicated by Facebook or Whatsapp or the friend's server) actually do belong to their friend?
I'm confused what you were talkimg about, with the client build possibly being a trojan
That's exactly the point though, how can they be sure in the event that their client (on the author's side) is a trojan? If the "author" client is deliberately compromised, there is no longer any reasonable means of ensuring that the public key the author uses to encrypt the messages is actually equal to the public key the recipient published.
Of course, this point is very much riddled with paranoia: it is exceedingly unlikely that the WhatsApp client deliberately contains such a trojan, especially since there are much easier ways of gaining access to user's messages (such as compromising their firmware with some form of rootkit, possibly installed via the baseband, and then simply sending copies of the local message cache to the NSA).
If your looking to build software that integrates with Signal, then libsignal is great (having built a few things with it).
There have been some concerns with their security:
https://www.schneier.com/blog/archives/2016/03/imessage_encr...
https://www.pandasecurity.com/mediacenter/technology/need-kn...
https://www.tomshardware.com/news/imessage-weak-encryption-m...
Additionally, iMessage doesn't have any means of out-of-band key verification, so you actually have to trust Apple to faithfully exchange keys and there's no way to verify that it's done so.
iMessage also tells you after a message is sent (via the color of a bubble) whether the recipient received it using iMessage. That's not very good assurance if, say, you're messaging a journalist in an authoritarian country. Will it go out over SMS or iMessage? You can find out, but even a little bit of doubt about that can have significant consequences.
I'm glad iMessage does do encryption like it does, but it's no replacement for Signal and WhatsApp uses libsignal for its encryption.
Do you mean "you have to trust Apple"? I don't see what Facebook has to do with iMessage.
[EDIT: Now corrected above. Thanks!]
Who does that for every conversation? Or even once per week/contact?
And I don't really see how they could get rid of the web features, it represents a massive number of FB Messenger users. This ties nicely with the older pressures from Zuckerberg to monetize WhatsApp and the resistance of the founders for security reasons, this most likely means access to the conversation plaintext.
isnt that how things like dashlane work? it sends the encrypted historical blob to your device, your device decodes it.
Beyond the technical considerations, different demographics have various expectations about what end-to-end encryption means. Sometimes their position is that end-to-end encryption does not exist without decentralization. Some want to have a fully federated protocol. Others believe that allowing an intermediary to broker key exchange invalidates the end-to-end confidentiality and authenticity assurances.
This often leads to nitpicking about what defines end-to-end encryption which, while a useful exercise in its own right, doesn't capture the heart of the grievances at play. In many cases it would be more productive to talk more directly about expectations regarding the security and privacy of a service or protocol rather than whether or not it fulfills an underspecified set of criteria.
This is to say that you can make a compelling argument that allowing a third party to broker your key exchange is insufficiently secure for you. But if you anchor that critique to whether or not the protocol satisfies end-to-end encryption, you're inviting rebuttals that don't substantially respond to what your critique is. Whether or not something satisfies end-to-end encryption is somewhat less important than whether or not you think it holistically satisfies what you consider to be strong confidentiality and authenticity assurances. If your problem is that you don't want a company like Facebook bootstrapping the key exchange for you, then you should defend that (valid) opinion by choosing a different set of criteria to work with.
a. a cryptographically secure protocol
b. an UI that is strict about checking that the keys and signatures match and is loud about notifying the user when they don't
c. an open source clientDo you see what I'm getting at? We're quibbling about a technically precise definition instead of what you'd like to see in a secure messaging application.
Application companies will always be able to backdoor their apps.
What e2e encryption does do is make messages nearly impossible to be intercepted in transit or on a massive scale by anyone without the cooperation of the company.
No, this is a non-standard definition of "e2e encryption" that I've never heard of. In fact, it's exactly counter to the whole point of e2e encryption. The reason "end" and "end" are specified is because it precludes anyone in the middle from getting the plain text of the message. End to end encryption is supposed to assume "cooperation of the company" as a threat model!
I don't understand why you and others in this thread describe it this way. "end to end" in this description sounds a lot like "transport security" -- like what you get from TLS (https, e.g.). How is this version of "end to end" (where are the ends?) any better than TLS?
TLS is client-server oriented. When a messaging system uses "transport security", like Facebook Messenger, that normally means that your client's connection to Facebook's server is encrypted, but Facebook's server still has access to your message plaintext. Whereas an "end to end" encrypted system would encrypt messages on your client that are only encrypted by the person you're talking to's client.
(I'm similarly skeptical about how much difference this makes in practice - I don't know what the threat model is where you trust a closed-source app and closed source google play services but don't trust the same company's servers. But it is a real distinction in behaviour)
In fact I don't understand the difference between TLS and -- let's call it E2E' (that which might be "end to end encryption"). If E2E' permits the message broker to intercept messages, does it satisfy the conventional definition of "end to end encryption"? No, certainly not. Is it any better than TLS? No, not in my opinion.
Here's what I quoted, which I believe to be E2E':
> What e2e encryption does do is make messages nearly impossible to be intercepted in transit or on a massive scale by anyone without the cooperation of the company.
By "broker" do you mean the server or are you including e.g. the company's code running on your device? "End to end" conventionally means "device to device" since few if any strong cryptosystems can be implemented by humans without mechanical assistance.
Key exchange is traditionally assumed away as outside the scope of analysis; we assume as a starting point that the users have a preshared secret key. So in theory E2E is very different from TLS. But in practice key exchange is very relevant.
There is still a very real practical distinction though: WhatsApp/Signal/... do not allow the server to passively intercept messages. There are active attacks that the server can perform against they key exchange process, but these would be very likely to be detected if performed on a large scale (even by insiders at the company).
It's also worth noting that a TLS approach leaves a much bigger attack surface for bulk attacks from outside the company: any security hole in the company's servers gives a single point at which an attacker can capture plaintext messages on a large scale (as the NSA is known to have done to GMail).
E2EE establishes a secure channel between two clients who each have access to the plaintext, via an intermediating server which has no access to the plaintext.
The two clients are the "ends" in E2EE. E2EE does not mandate that the server is uninvolved in the key exchange.
You know what's bizarre to me? Most US states are either one party consent or 2 party consent states. Meaning to record a conversation, at least one party must consent to the conversation being recorded.
So how does this not apply at all to private conversations online?
Facebook controls the clients and as such can do whatever it likes with your chats (or whatever you agreed to)
This is what I was getting at in my other comment. If you’re going to reject end-to-end encryption because you can’t verify the client, you’re looking at a very different set of criteria to establish the confidentiality and authenticity assurances you want. In particular, you are at a point where it’s difficult to establish a secure channel unless you’re using a fully decentralized, federated protocol with a server you stood up yourself.
The parent poster is not rejecting end-to-end crypto itself, but how it's typically done. (on a locked phone you don't really control in an autoupdating app you don't control at all) Web based end to end encryption is even more ridiculous (say mega.nz for example), because then it's even more trivial to distribute different code to differnet users.
And what happens if you have no social networks / websites like me? HN is probably the closest I got to a social network online.
I don't agree. This is the antithesis of the intent of the term "end to end encryption." Otherwise you could just use TLS to secure each of the {client->broker} connections and then you could call it "end to end".
I assume they think that the network effect is going to lock users into WhatsApp but the moment it becomes too painful to run on a 100$ Android phone with 1GB of RAM, it will inevitably die. Sure it's not going to be instantaneous but I'm a 100% sure that all the PMs that run Facebook Messenger are itching to get their hands on WhatsApp.
I understand these changes are only on the server side, but I imagine the client side is not too far away. Some client changes are inevitable because I'm pretty sure they'll build a "unified" API for all these apps and it's is going to contain a whole bunch of messenger service code (because look at all those messenger features that noone cares about, surely we can't just drop what a whole org has been working on for two years)
Well, let it just die quickly! There's not much to love in products from a company that's repeatedly so hostile to its users. I'm all for anything from Facebook dying sooner, and will be cheering when that happens.
No thanks. Delete Messenger/WhatsApp and move everything onto other services.
But let's keep this serious: Instagram isn't a tool for secure messaging. It is a tool to publish images, mostly public images.
A person might very well decide to move sensitive communication off Instagram and continue to post their cat videos on Instagram.
A valid reason for not using Instagram however is to lead by example and weaken the network effect of Facebook.
Facebook is already in panic because users are leaving the platform so IMO now is a good time to test out alternative solutions :-)
I'll be out of there as soon as a federated alternative pops up and gets the least bit of traction.
Was this ever a question? Seriously.
The web has evolved with messaging APIs and server side push notification things, how easy is it to put together a group chat for just your family these days? The wider friend-verse can stay on these common platforms but the inner circle can be kept off servers and so long as someone in the group has the messages then a complete transcript can be had?
I don't believe it can be that hard. Facebook has become a behemoth and you don't need all that to just share messages within a small family sized group. Whilst Facebook merge their triplet of behemoth apps I am sure it can be possible to put something together that just works for the inner friend/family group everyone has, a little advert free zone that just does text and phone recorded media. Can it be done utterly serverless or is this something the blockchain crowd have solved already for me to have dismissed as snakeoil?
I've been researching this lately and I'm about to test out private (but possibly federated) instances of hubzilla and nextcloud as soon as I can get some time.
Both looks extremely promising although I know there are issues.
Do you think lawmakers care? There is a fair bit of public goodwill for acting against big evil intl tax evading tech companies...so I think they actually could force this.
Not necessarily. My understanding is WhatsApp basically uses the Signal protocol right now, Signal itself is open source, so I assume an acquirer could just stand up some new Signal infrastructure and get 80%+ of WhatsApp functionality without much redevelopment.
All the other protocol bits are very much WhatsApp-specific.
This is easy to fix by increasing the punishment, right?
http://europa.eu/rapid/press-release_IP-14-1088_en.htm
That release sums it up indirectly -- they had no issue with it because they were all distinct platforms with different features, but if Facebook consolidates them, I think that somewhat implies they are competitors and there is clear duplication of offerings.
So now I'd like to point out that the article has a couple mistakes. You don't actually need to provide anything but a phone number to use Facebook Messenger, but not many people know this, it seems. Related to this is a lot of hand-wringing about "oh no this will mean Facebook is watching us in all these apps now". Well, I'll address this in a second. I want to talk about this quote in the article:
"Matching Facebook and Instagram users to their WhatsApp handles could give pause to those who prefer keeping their use of each app compartmentalized."
This is already impossible. WhatsApp and Instagram collect information on you whether you have a Facebook account and whether or not you are logged in if you do have one. They know who are you are (this is the reason why I don't really care how encrypted WhatsApp is, I'm not going to use it). So if this really bothers people, well, I've got some bad news.
This freaks me out, as i have deliberately chosen to stay away from facebook since the early days! I somehow felt repelled by the idea of facebook back then, now its trying to hunt me down! Oops!
I have been thinking of quitting Whatsapp since facebook acquired it, but continued using it since almost everyone i frequently communicate with does so on Whatsapp.
Maybe it's time to quit whatsapp before this integration happens! Or am i just freaking out ? :D
Been trying to get friends and family to switch to Signal since early 2017 with no luck.
https://www.cnbc.com/2018/03/26/how-to-stop-your-phone-from-...
^Site to do so. I figured that I'd share my lesson[s] from my own idiocy: Note that you need to put in your full international number (even though they make you select a country?) for it to work.
So, for Sweden, 075555555 becomes +4675555555 (which most people don't store their contacts' numbers with country code but what do I know, yeah?).
Very true and it has been bugging me since I have gotten familiar with internet since a long time ago. This was the reason I used to create accounts online without my real data back then. Up until recently that is. Once there were tools in place to get rid of ur discovery online, unless deliberately shared I stayed away. But everything comes under question once more. This is hostile takeover of data.
And yeah, I used to be as meticulous about data as you had been while storing phone contacts etc., But more and more it is becoming evident that what's given away online can never come back to you at least until there is effective regulation in place.
I appreciate the EU for their foresight and strict data policies!
Also, I have been trying to request people to move on to other platforms with no luck for the past many years.
But it's not too late to wean yourself off of it and get rid of your account (though you have given more information to Facebook through WhatsApp all this while).
YMMV, but here are some suggestions. Turn off notifications and the message count badge completely. Then avoid opening the app. Do these for a few days until you realize that you're not missing much and are probably less stressed and happier than before. Get others to use Wire (I won't recommend Signal because it sucks and has a bad user experience even in 2019, and has only its protocol's fame going for it).
There's no such thing though.
WhatsApp calls every number as an “account”. I deleted my account when WhatsApp was bought by Facebook. Here are the links to WhatsApp’s own FAQ to delete one’s account on iOS [1] and Android. [2]
[1] https://faq.whatsapp.com/en/iphone/21325453/?category=524524...
Clearly FB wanted to not just have access to those users, but also integrate them into the wider FB ecosystem.
>"a Facebook user could send an encrypted message to someone who has only a WhatsApp account, for example. Currently, that isn’t possible because the apps are separate."
Nothing stops you from encrypting with your own scheme before sending the message to the other service, it’s just added inconvenience. More importantly it implies that you depend on the medium owner for the key management which (as others here are pointing out) defeats the point of encryption (in part) by allowing said medium to read the plaintexts.
Edit: Am I wrong?
Essentially, one could share a single table of "users" between Facebook, Instagram, and WhatsApp.
Because the accounts can be easily identified and connected by email addresses and phone numbers, which don't change that often.
This way, a "Facebook Account" could become like a "Google Account", but for social media.
This is exactly how Google integrated YouTube.
It's bad for privacy, but good for everything else.
Also, because of E2E encryption, the server infrastructure really cannot do the sort of content translation necessary to make things seamless.
For instance: facebook.users, facebook.ads, facebook.feed, facebook.messenger, facebook.instagram, facebook.whatsapp.
This way, users and ads would be shared across all Facebook's platforms, which is, I believe, the main reason for the entire integration.
I'd argue that then, as we are talking of platforms on which you share most of your personal and private digital life, it is nothing but bad.
It would also help to increase the protection of the single "Facebook Account" to those, who will decide that they still want to have it.
There were many questions such as "Did you quit Facebook in 2018?" in the media. Yet, the question should have really been "Did you quit Facebook, Instagram, and WhatsApp in 2018?".
This update would make it much easier to do.
What's more, Facebook can, and will, paint this as something it's doing in order to monitor content and handle fake news, earning brownie points from various governments who'd be eager to tap into this new source for surveillance.
It's rather betting the value lies in the social graph, not in being able to tell that this user is a democrat voter with a disabled child and that is a republican who is black. [#]
If facebook already holds that data on users and does not "give it up" then yes totally - they raise the bar so that absolutely no competitor can garner that data - a perfect moat.
If somehow a regulator forces them to anonymise the data - they are at the same stage as any competitor.
I guess that's the regulator challenge?
[#] ie arbitrary meta data about users but that is extremely valuable to advertisers and political campaigns. do not take the examples as meaning anything :-)
While (anecdotally) Facebook doesn't appear to be very hype with the youth today, Instagram and WhatsApp still appear to be quite popular. In a weird way Facebook is both the mainstream choice and the underdog, that's a good position to be in IMO.
Beyond that what does it mean for people like me who use WhatsApp but do not have a Facebook account? Is the plan to force people like me to create a Facebook profile?
While it would be great if they moved to a pure Jabber federation model or similar, I very much doubt they will do that, however, unless someone like the EU can get their act together and force them to do it.
Most likely though in the background they will use these links as ways to package your identity up when selling to advertisers. Thats what I'm guessing is the end goal , enrich their stagnant platform (FB) with their growth platforms (WhatsApp and Instagram)
At least I now have an incentive to move to Signal and convince my friends to do so, hopefully, or otherwise I’ll be alone. Well, I can always be reached by SMS or email.
I really hope it stays out of Zuck's "vision" but it likely won't, considering the amount of money he paid for it
as someone who has no FB apps on phone other than whatsapp, I hope/wish this move means someone from messenger/insta can send message to Whatsapp account and vice versa. Nothing more than that.
FB has done a good job in keeping Whatsapp true to it's core features (except the status/stories debacle). Once it's whatsapp payments / business messaging picks up, there's no looking back for FB even if it's core FB web platform goes to zero, Whatsapp + Messenger + Instagram will be a force to reckon with.
ios it's irrelevant niche platform outside US, whole world use Android
ninja edit I was already debating going back to iPhone to begin with. I feel like this just cements it as my friends and I will give up Whatsapp for group iMessage
If anyone has any idea, please share.
Edit -> I don’t understand why the heck are honest technical questions downvoted!! It’s not like I would have found a ready answer for my question with a simple Google search. If a question does not interest you, at least please don’t downvote it! Some dumb people are courageous enough to ask questions.
http://highscalability.com/blog/2014/2/26/the-whatsapp-archi...
the article (and others) have crazy stories about scale in WhatsApp (70 million messages a second (from a few years ago)).
Erlang (and Elixir) are perfect for this scale and high reliability challenge. But, its corporate decision, so it might wind up being rewritten in some idiotic language. Or, more likely, it will be a hodgepodge of micro services written in different languages and glued together with HAProxie (or whatever).
Thank god. If they collapsed WhatsApp into Facebook Messenger, I would quit WhatsApp.
They would have to instead tie Facebook messenger to a phone like Whatsapp does and use a web app to send messages directly from the device instead. I don't see how else it could be done and still be called end-to-end encryption.
And according to the article, this radical change is coming. Why is that so hard to believe?
Yeah, WhatsApp is e2e encrypted by default, but it also automatically backs up all your chat history encrypted using a WhatsApp-owned private key. Sure, you can opt-out of backups, but will your peers do as well? Without a clear spec, I think it's perfectly reasonable to be very skeptical of what will be the final product of this operation.
AFAIK, end to end encryption can't really support having multiple clients all using the same account. For example, WhatsApp's web interface is sort of wonky and goes via the phone, to get around the limitations, and I can't really see that being a solution here.
Of course, "end to end" encryption from a Messenger on the website is sort of meaningless anyway.
Improving your AFAIK here. Signal Desktop works independently without proxying communications through the phone (which is what WhatsApp does). Wire supports multiple platforms (Windows, Mac, mobile) and syncs chats across all of them with end to end encryption. There are different ways to do this. It's just that WhatsApp didn't implement it.
Agreed.
A nice Twitter thread [0] by Mustafa Al-Bassam back at the end of November on how that might be exploited by GCHQ:
>Ian Levy of GCHQ has released an essay on how law enforcement should get access to end-to-end encrypted communications. Here is the critical bit to pay attention to. They're proposing to exploit the fact that users don't verify each other's public keys, and inject bad keys.
Then this [1] later in the same thread by Twitter @inag_fc:
>This is a coordinated attack by 5 eyes. They slipped it through AU parliament in the week, presumably as some horse trading because there was practically no debate nor warning, beyond the normal straw man proposals.
My family is all on WhatsApp, but my friends and colleagues are on Messenger and SMS.
Previously, I would only ever use Messenger, checking SMS and WhatsApp once a month at best.
A while ago, SMS got integrated to Messenger, I started staying in touch with people who only use SMS.
Now that they're adding WhatsApp, I literally don't know a single person I can't reach from Messenger/Gmail.
I love it, and I hope things go smoothly.
I wonder how you will feel the day FB decided to ban you for whatever rule their algorithm would decide you violated.
But I'm okay with ignoring people, asking people to stop, and mercilessly blocking people when they don't. Some are unwilling to take such deliberate action to reduce unwanted communications. Some perhaps have good reasons: it'll be socially costly.
> Mr. Zuckerberg has also ordered all of the apps to incorporate end-to-end encryption, the people said, a significant step that protects messages from being viewed by anyone except the participants in the conversation.
Also an option to enable web E2E with a password-protected key stored on FB's servers is still pretty darn good.
People are using both Messenger & Facebook web to send messages, they will have to break that somewhere for end-to-end.
If Facebook is storing your encrypted message database on their servers then the problem gets significantly easier.
You can start at, for example:
- https://account.conversations.im/ (8€/year)
- https://quicksy.im/ (free account)
I want to like Signal but it's kind of the worst of both worlds for me. Since they absolutely refuse to allow for easy modification of the client it means that I'm stuck with their crappy Electron app on the desktop that lacks some basic features (like being able to select the spellchecking language for instance). I can't script anything, migrating conversation histories between devices is messy and complicated etc... And of course on top of that it easily swallows half a GB of RAM to do all that.
On the other hand if I put myself into a random user's shoes it doesn't "just work" like WhatsApp does. I don't have a web browser client that I can use from anywhere. It doesn't have stickers and stuff like that that seems to be popular on WhatsApp.
It's basically a good crypto library with a terrible UI around it.
In my experience (after trying it a few times every year for the last few years), even its backend platform is unreliable and slow. So I'd call it as "It's basically a good crypto library with a terrible UI and a flakey backend behind it."
Use Signal if you absolutely need end to end encryption, extremely secure chat, and no way to use it outside of your phone being on and connected to the Internet.
Use Telegram if you want chat. Don't except high levels of security and for the average user who already uses Facebook Messenger and Instagram, it's good enough.
The number one feature I wish WhatsApp (and Signal) would adopt. I don't care for either service, but that would at least allow me or my partner to occasionally participate in group chats without resorting to buying an Android or IOS smartphone.
People just assume everyone under 60 has WhatsApp in some countries (the Netherlands being one of them), and it borders on being a requirement to function socially.
My partner went to a course for pregnant women, and during the first meeting it was agreed that all communication outside of the meetings would go via WhatsApp, but the course leader would send emails to my partner for changes in scheduling. (My partner has no smartphone, and doesn't want one either, but she owns a modern laptop and works in IT.) So basically any knowledge and questions shared in the group are invisible to her.
This situation is likely to come up again and again as we start raising a child, and all we can do to remedy it is buy a smartphone with one of the pre-approved operating systems, and join the social graph of Facebook…
You can use Signal on Desktop without your phone being online. (This does not work with WhatsApp.)
Signal on the other hand has a quite poor desktop app and I find their mobile app a little slow. It usually takes more time for me to open a conversation than with Telegram.
Telegrams UX is leagues beyond Signal and good enough that I've gotten my entire social circle to switch.
This is in contrast to e.g. Wire, [a near-future release of] Riot.im / Matrix.org, and (AFAICT) Viber, which do end-to-end encryption by default and cross-device without compromises. The messaging providers don't know anything about your chats there. This is the way it should be.
There are also complaints about Telegram's "weird" cryptography, although nobody's ever shown anything close to a practical attack yet, and definitely not for the current version of their custom MTProto protocol. The core problem is really in their insecure-by-default service offering.
https://security.stackexchange.com/questions/18197/why-shoul...
It is impossible, because the don't want an open API, which other clients can use too.
I guess everything old is new again.
It's nice that they advertise end-to-end encrypting the messages in transit, but then just dump everything to the world's biggest data mining machine.
Oh wait. We do. That's what the IETF is for. We just let pricks like Zuckerberg run closed gardens because we suck at using choice to walk to things like signal.
Go signal!
They're writing standards and deploying closed ecologies.
Your comments in https://news.ycombinator.com/item?id=16325803 seem relevant.
Before anyone gets pissy, think about it, it's true.
FTR: I would love!!! an open source / open protocol messaging platform that wasn't owned by anyone. But, that doesn't seem to be in the cards for us all.
This is the case for business accounts but not quite for normal users just yet. You can create an Instagram account with a username and password and it will repeatedly nag you to connect to Facebook for a while but eventually give up.
And if course they have my WhatsApp number from 2FA on the other sites.
The headline is missing a key word: infrastructure
For the end-user, the most "seamless" way to integrate is to adopt Messenger's approach, which will be a security loss for WhatsApp unfortunately. As other users mentioned, there is also the possibility that the end-to-end encryption will lose its default status.
The article says otherwise.
- mark a title as clickbait
- either suggest an alternate title, or accept one from a list of previously submitted alternate titles
When enough karma has gathered behind a title the system can automatically replace it.
I'm not sure if it is done my moderators or it just depends on the original poster to change it.
On the other hand, it is the exact title of the article being linked....
I feel a lot of the comments decrying "clickbait" actually disagree with the opinion or the underlying assumptions the title conveys.
(Such as in this case the question whether or not this is a simple decision over technical details or a broader shift in strategy with consequences for the users)
I fear this feature could be easily abused by people removing the connotation of the title in the name of making it more "objective" - but by doing this, actually throwing out the reason why the article was posted.
If the headline had been "combine," then I agree it would've been clickbait.
That smells like a little more than just infrastructure. More like product integration, with their UIs retaining the old.
Edit:
Also note that the article describes a lot of changes that go far beyond infrastructure - notably, that users can communicate across services and that user profiles from different services might be matched. If done, they would have a lot more far-reaching relevance than technical details.