https://www.forbes.com/sites/kalevleetaru/2019/05/05/faceboo...
It's running in your device, you don't have to trust them if you have technical skill.
They might convince me if they open their client and server code, but even then they're yet another walled garden only interested in keeping their monopoly by building inferior products and using regularly capture to prevent any competition from doing the same thing they did to MySpace.
Not quite. Facebook still controls the endpoints, so when you see the message so can they. This is obvious: you use their app to view the encrypted message, hence the app has access to the cleartext.
If the app is not phoning home with the cleartext, this seems okay. You need some software to retrieve/read text anyway, so this becomes an exercise about trusting trust, etc.
Not at all. Good security often involves some black-and-white thinking, which not everyone is accustomed to.
If Facebook controls the endpoint, then they have the power to access the plaintext, full stop. Using their product (hopefully) implies a choice to trust them not to abuse such access.
Which is what...they said?
Would you argue against all encryption because clearly the CPU maker has a similar access to all decrypted content?
It's still better than nothing, although in the hands of Facebook it might actually be worse than nothing.
I'm sure realistically the US gov could creatively accomplish what they want.
In order to actually provide your messages to Facebook, the app needs to either call home when you view the message or write the cleartext somewhere on-device to send home later. If you view the message and then the app calls out with data we can't inspect, or writes something locally that we can't inspect, it could potentially be exfiltrating the message you viewed. If not... am I missing an attack vector, or is that message safe?
(To be precise: this would only prove forward secrecy, meaning safety for that viewing of that message. If we can't see the app's code, it could have testbench cutouts like Volkswagen or WannaCry, or more likely could only trigger for certain users or in certain cases à la Greyball.)
On WhatsApp there seems to be E2EE enabled but I have no idea what the keys are. A layperson definitely has no idea what the keys are.
Could Facebook build an "NSA mode" where the old keys (K1) are quietly replaced with some known keys (K2) for a particular user at a particular timestamp T?
This means that all messages before T are to be parsed by using K1 and all messages after T are to be parsed by using K2.
As a WhatsApp user, would I even know if "NSA mode" has been enabled for my account? This would enable courts to allow surveillance for all future messages, but the old messages would still be E2EE.
What if you involve Apple+Google into the mix and have them silently deploy a rogue update to a particular user's WhatsApp program - couldn't you just ask a court to write some kind of surveillance warrant which orders the 3 companies to work together to give the alphabet agency a way to remotely take the keys?
https://www.homeaffairs.gov.au/about-us/our-portfolios/natio...
Simply saying "We have E2EE so you can trust us now" and not actually clarifying where E2EE is applicable in your apps is some very typical PR talk.
The keys are shown right in the contact's profile under "Encryption", same as Signal. It even has a feature to validate their key by taking a picture of their screen. How could it be any easier for laypeople than that?
> This code can be found in the contact info screen, both as a QR code and a 60-digit number. These codes are unique to each chat and can be compared between people in each chat to verify that the messages you send to the chat are end-to-end encrypted. Security codes are just visible versions of the special key shared between you - and don't worry, it's not the actual key itself, that's always kept secret
So basically it's just a random unique number and could have no relationship to the key whatsoever. We'll never know.
What would it prove if they showed the private key in plain text?
"Won't" implies they select who they want to give the data to, which mean they probably give that data to other actors, without users even knowing about it.
These people aren't stupid, and their legal and PR teams understand the fine details of the English language.
It says what they mean to say, not what we wish it would say.
They "Won't". Not that they "Can't".
And the alternative is an organization which has an absolutely stellar track record at not doing evil (obvious sarcasm should hopefully be obvious).
Neither party is can be taken at at face value here.