Privacy critique of WhatsApp
twitter.com
twitter.com
I strongly believe if you asked the majority of users with an engineering background if they thought whatsapp kept a log of "all your contacts and group names, past and present, covering multiple phones you've connected to the account, plus your account info" - they would say yes. These seem like pretty normal things for a messenger app that's focused on UX rather than security to store?
It's honestly the best we can ever hope for in a free but commercial product. Everything with better privacy would either have to run almost server free or cost money. Both of which would probably kill mainstream adoption for different reasons.
Not to mention that even if everyone was willing to pay $1 per month for a messaging service, now people are instantly identified with a bank account. And even if you allowed bitcoin, since 99.9% of people would just use your bank account, not using one would instantly put a spotlight on you. And who sends messages to whom is still going through their servers. To actually get significantly better privacy, you'd have to essentially use the Tor network or something.
You even say this yourself in a post you linked to above:
> “WhatsApp’s main appeal to the masses is not its secure, end-to-end encryption, but its general simplicity. “
> “99% of WhatsApp’s users more than likely have no idea how E2E encryption works and they don’t even particularly care about it.”
https://risky.biz/e2e-not-pointless-but/
(I generally liked that post! Which is why this jumped out at me)
How do you know this to be true?
> I feel like you just read the first tweet in a seven part thread and came to a weird conclusion based on an argument that was never made that way.
Why are you being so snarky to anyone who disagrees with you in this thread?
I'm not being snarky, just direct (kind of typing these fast to talk to as many folks who are interested as possible) , sorry if it came across badly to you, that wasn't the intention
OP is well respected in the infosec community and the fact that he gets attacked and downvoted here tells more about the HN community's ignorance about something that should actually be muscle-memory for anyone who works in Tech. Many commenters here seem to just shovel JSON from A to B in their day jobs, so no surprise that this thread feels more like something you see on Reddit.
the marketing effort by FB to convince users that because of WhatsApp switching to double-ratchet now makes it as secure as Signal suggests otherwise
If you only knew the amount of criminals caught in Europe because of the perceived privacy of WhatsAPP.
Is there a high correlation between criminals and intelligence?
WhatsApp is the only mainstream messaging platform that uses proper end-to-end encryption by default. From what I've understood, it's much safer than other popular alternatives, such as texting, Facebook Messenger, Slack, iMessage, and, yes, Telegram.
Sure, it's still not perfect. But to casual readers, it's totally not obvious that if WhatsApp is a "dumpster fire", all popular alternatives except Signal and Matrix and the likes are a nuclear disaster.
Nobody at WhatsApp claims that it's good for overthrowing your government. But if I want to send a password to my sister without having her install an app, just to satisfy her brother's tin foil hat, I think WhatsApp is a much better choice than every other option I have readily available.
We should stop driving people from somewhat secure tools towards insecure tools.
At least hear out what the Telegram devs have to say about this:
> WhatsApp aggressively pushes users to enable backups to third-party services by Apple and Google. Even if you don't backup your messages, it is extremely likely that your chat partners are doing so. It is likely that they don‘t even remember dismissing an annoying notification with a “yes” a long time ago. The interface provides no way of knowing whether or not your messages are being backed up. Meanwhile, for group chats of five members, there’s a 99% probability that all messages are stored on Apple‘s or Google’s servers in the US.
> As Product Manager Randall Sarafa put it, just one month after Google Drive backups were introduced to Whatsapp:
> “About 75% of Whatsapp users are on Android, and of our Android users, we have about 40% of them opted into Google Drive backups today. That will likely continue to increase over time, as people get prompted.”
https://telegra.ph/whatsapp-backdoor-01-16
So Whatsapp's usage of end to end encryption might not be as helpful as advertised.
I suggest you use Signal or Threema instead of apps like Whatsapp or Telegram. Both lack options to back up to the cloud.
The interface is clear about it on your side: https://postimg.cc/gn3LxBNz
If you mean the other side, then the only valid assumption is: yes, the other side of conversation backs up your messages. This is unavoidable and for the general population having a backup is more important than the edge case where the backup is abused.
WhatsApp has been more successful than any other technology in history in getting people to use end to end encryption by orders of magnitude. Yes, there are limits. Yes, people with strict privacy concerns should consider other options. But altogether WhatsApp has been an outrageous win for privacy advocates.
you forgot WeChat, which is also pretty secure provided that you trust the CCP.
> We should stop driving people from somewhat secure tools towards insecure tools.
you think that Signal is an insecure tool when compared to WhatsApp?
Signal is pretty secure, but Moxie's "The Ecosystem Is Moving" is the wrong mindset. Email is only still alive because anyone* can run their own with their own settings.
* including companies and individuals
——
It sounds like your whole life (social graph and private messages) is one search away by big entities. Who is big enough to intercept your messages but is unable to get the unencrypted data in storage?
Even if Telegram has shoddy crypto, their funding model is "we got a pile of money from a billionaire". WhatsApp's funding model is "senator, we run ads".
Thus, WhatsApp will be incentivized to lie as far as possible about these claims, whereas Telegram could at worst be considered to be mildly incompetent.
Matrix is a relatively new open source message protocol that offers various bridges to connect to other chat/messenger services: https://matrix.org/bridges/
All my contacts are on msn.
On skype.
On myspace.
On facebook.
Now on whatsapp.
It will change.
The only things that haven't up to now are postal addresses, emails and phone numbers.
Are you constantly marked as spam?
I'm still smarting, we still sometimes have problems (from a different host now) but just resend via an outlook.com address and it's fine.
So, no never had our domain marked as spam on any dbl that I've checked (but only done that sporadically).
We also had a blip with Gmail around the same time (but not the exact same time), but I reported it as a false positive and it was fixed in a few days; no problems since.
We were/are sending so few emails (<1 day average) that it's not worth me spending a couple of days trying to see through the murk of MS to fix it. We're probably not losing any revenue, just have to treat MS sent emails differently to everyone else's.
Sounds wrong to me too ;o)
If we choose things mainly because "all my friends are on it", then no.
I don't have a fb account. I don't have whatsapp. Never had.
Yet I have a very rich social life and maintain relationship with people far away.
The tools we use are a choice.
The price we pay is different depending on that choice.
The secret is to focus on quality, not quantity, and realize a lot of FOMO is involved.
For example, if they write - in the group - that the next meeting is 3 PM next Wednesday at so-and-so, unless you happen to run into them at that specific time your chances of knowing this are slim.
There is (was?) plenty of said messengers; Trillian, Miranda, Pidgin, Adium to name a few, plus XMPP transports that could be used from any Jabber client. I've no idea though whether they're still around and play nice with modern walled gardens that require registration by phone no.
Facebook may be evil, but not because of WhatsApp.
The foothold it has over here in Europe (The Netherlands) is enormous. Everybody uses it, there's even neighbourhood watches that use it, see: https://cdn.nieuws.nl/media/sites/305/2015/12/05153708/atten...
Any advice? Just pull the plug and pay the social cost?
Turns out that people don't bother communicating with you if you're on SMS, and can never be bothered to write an email.
This implies that the communication they were going to send is not important. If it were, they'd write an email. And people don't like the cost of MMS and soon stop sending me stupid pictures.
I can archive email + SMS, not any of the other chat systems.
I hardly get bothered by any notifications or interruptions or silly photos unlike my wife's phone that is constantly binging and buzzing and silly comments from "family chats" and work chats eg. "lol rofl haha random internet picture"
It's refreshingly quiet.
If others can't be bothered to find a method to communicate with you, they can't be very sociable? Their friendship and social interaction with you seems to be tied to an app. That's not a social cost - that's a social price.
Some didn't migrate, but they are still able to reach me via email. I'm OK with that outcome of having lost some of those who didn't care.
It has advantages too - I get many of my friends to use Signal and I can avoid participating in many group chats that usually have a poor signal to noise ratio. Instead I just get a filtered report about the conclusion from one of the members.
I really like the ideas behind matrix.org but that is a dumpster fire of epic proportion.
Storing that amount of information for extended period of time, cataloging it under your identifiable information was not done by all messenger apps.
If I leave a WhatsApp group immediately after I don't like what was posted, the data will still reference me.
That's not great. It doesn't need to be permenant. Thats kinda the point.
No, not at all.
Always presumed it was a basic way to collate alt-accounts to real people in the back end.
It is also one of the most responsive messengers out there. It's also one of the rare messengers what are reliable also on 2G and other very slow and spotty networks. It's also one of the rare messengers that includes video calls, voice calls and mutiple other features that make communication easy. It supports groups, invitations via links and multiple other features that make coordination of communities easy and seamless. And it also doesn't lose all your messaging history everytime your phone breaks.
Privacy crowd needs to start understanding this and needs to stop behaving like robots who don't understand WHY people use these apps although they might be "dumpster fire" in that one privacy aspect. And then move to fix Signal and other to make sure they're not "dumpster fire" in aspects the wide users actually care about.
There is no way to transfer Messages between iOS and Android or to backup messages in any way really - except of storing them plaintext at Google/Apple.
I'd be really thankful, if anyone had some solution for this...
As for keeping your messages - that is a trade-off between convenience and privacy. When people are aware of how their emails are being read, processed and used for spying they often (usually?) choose the privacy option.
That would mess with their metadata collection, however.
I mean I guess it kinda sucks that Whatsapp isn't Signal, or E2E Jabber, or E2E Matrix. But man, it could've been so much worse. It was so much worse. A global network accessible to and used by billions of people sending E2E encrypted messages was a privacy activist's wet dream 6 years ago. Whatsapp's move to E2E alone is amongst the most impactful changes in real-world privacy on the entire internet.
Calling that a 'dumpster fire' because they transparently communicate they still know metadata about you really does make you seem like a robot. 'Dumpster fire' is not a synonym for 'has room to improve'. This kind of talk is par for the course on Twitter surely, but not it's not unreasonable to expect some flak for it.
How would you know? Is WhatsApp source code available anywhere?
Not a security dumpster fire. Not a privacy dumpster fire. There's no qualifier in the title or the inital tweet.
And WhatsApp is not a dumpster fire by any standard. I've edited my post to perhaps make this clearer.
See this article from last year if you want a more nuanced take: https://risky.biz/e2e-not-pointless-but/
I find the VOIP calling on it laggy and delayed (listening to my wife's calls with her mum who hasn't realised that the default on her iPhone for calls is now WhatsApp as it has hijacked the default "phone" behaviour...)
I did once use 2G to VNC over SSH to a machine for work and that was painful, but usable. Colour depth had to be pretty low for it to work though.
We just love ever-increasing data usage, with about the same level of actual content (text).