About the partnership: https://signal.org/blog/whatsapp-complete/
But of course, in this case the issue seems to be either compromise of the device(s) via zero days, whatsapp usage simply being the target matrix - and/or a leveraging a zero day in whatsapp for full device compromise.
It's unlikely signal would be immune - they didn't Crack the encryption, they cracked the app/os.
In olden times the vector might have been a font, or a gif.
The only advantage signal has is a conservative interface and small userbase. I'm not sure if they do some kind of hard-line whitelisting of attachments though - if you can pack an exploit as a file, I'm pretty sure you could send it via signal.
Signal is open source, WhatsApp is not. So how did you determine Signal has only one advantage over WhatsApp, without access to the WhatsApp source code?
Nothing seems to indicate a back door here.
1. Do you trust Facebook (or open whisper systems) with your metadata/expect them to delete it?
2. How likely are there to be bugs (in the app, not in the protocol itself) which lead to exploits. On the one hand WhatsApp probably have more people working on the app and likely more security people too. On the other hand they may be pushed to add more features and having lots of code churn may introduce security holes.
3. How much work will be put into exploiting each app. On the one hand more people use WhatsApp but on the other, I guess security conscious people may be more likely to use signal.
A known exploit to WhatsApp happened due to 2 with a bug in how audio calls were initiated. I don’t really have a good guess as to how the apps compare on points 2 and 3 but I guess WhatsApp loses on 1. A more practical point is that it’s likely easier to convince someone to use WhatsApp than signal, especially for group chat.
(Widely reported, see Guardian article)
From WhatsApp’s point of view this was a reasonable ux trade off. It is a major pain point of signal when it does this (particularly in group chats where it is more likely to happen).
But I agree that from a strict security focused point of view this is a disadvantage to WhatsApp.
Even moxie, who created this stuff, more or less admitted this[0], by saying the rekeying notification is the only defense, but that one is off by default in whatapp last I checked (which moxie confirmed[1]), which makes whatapp insecure by default at the very least. I wouldn't be surprised if WhatApp servers know if this notification setting is on or off, which would enable them to e.g. target people with insecure default settings only to avoid detection.
I already said this in [0], but let's repeat it: This is essentially the same as if a webbrowser would just accept any TLS certificate without showing a warning no matter if valid or the issuer trust.
Sure, this is hard problem to solve UX-wise and user-education-wise, but that doesn't excuse that you advertise your known-and-deliberately-insecure-by-default default-MITMable product as "secure communication using end-to-end encryption".
Personally I can not imagine Human Rights Activist having the Rekeying Notification set OFF.
>Personally I can not imagine Human Rights Activist having the Rekeying Notification set OFF.
I can. A lot of those people are not tech savvy. And the targets of e.g. the most recent NSO story weren't just activists, but a lot of other people too, politicians, state officials, lawyers, journalists, etc.
And on top of that, this system becomes MITMable as soon as one of the communicating parties has notifications off (or ignores them, which then comes back to the UX and education issue).
From a career in software development, I tend to feel that the more devs, the buggier. Maybe, MAYBE (number of QA)/(number of devs) = reliability coefficient.
Oversimplification: WhatsApp is based on Signal, but repurposed for Facebook.