WhatsApp whitepaper removed sentence about never having access to private keys
twitter.com
twitter.com
The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions:
"At no time does the WhatsApp server have access to any of the client's private keys."
[1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...
https://www.academia.edu/36044237/WhatsApp_Encryption_Overvi...
A copy I had downloaded on 29 July 2020
> The WhatsApp server has no access to the client’s private keys, (...)
>All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook.
Not sure if the facebook exception was there in the previous version.
This is craftily ambiguous.
All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook.
(https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857..., p. 13)
> However, these private keys will still not be stored on the WhatsApp chat server.
I guess it wasn't clear, but I was trying to refute the claim implied by the Twitter post (by showing that the document still claims that WhatsApp servers don't have access to the private keys).
> The move, the spokeswoman said, is part of a previously disclosed move to allow businesses to store and manage WhatsApp chats using Facebook's infrastructure. Users won't have to use WhatsApp to interact with the businesses and have the option of blocking the businesses. She said there will be no change in how WhatsApp shares provides data with Facebook for non-business chats and account data.
And yet, somehow, everyone is just in complete hysterics over all of this, claiming Facebook is evil and undermining the feeling of security people have in WhatsApp, with lots of talk of switching not only to reasonable alternatives like Signal, but also to less secure messaging protocols like Telegram (or, frankly, Matrix). People at my supposedly-smart privacy company--Orchid, building something akin to "incentivized Tor for general VPN use"--are even panicking about this news, and it is really frustrating how no one even seems to want to analyze this carefully... "bUt FaCeBoOk Is EvIl!!" :/.
For many of us, facebook's past actions are more than enough to prove that they do not deserve the benefit of the doubt in this case.
> but also to less secure messaging protocols like Telegram (or, frankly, Matrix)
Appreciate that Telegram doesn't have a good rep in the security community, but whats wrong with Matrix?
Also, this is off-topic, but I just wanted to say thank you for all the work you've done in the past with Cydia. I was a 1st gen iPhone user, and got a lot of use from services such as Cydia (in fact i'm convinced the App Store was inspired by services like Cydia).
https://matrix.org/blog/wp-content/uploads/2017/02/2017-02-0...
> Matrix does not protect metadata currently; server admins can see who you talk to & when (but not what). If you need this today, look at Ricochet or Vuvuzela etc.
> Protecting metadata is incompatible with bridging.
> However, in future peer-to-peer home servers could run clientside, tunnelling traffic over Tor and using anonymous store-and-forward servers (a la Pond).
> But for now this is sci-fi.
https://github.com/matrix-org/synapse/issues/2188
https://github.com/matrix-org/synapse/issues/4565
Signal, in contrast, put a lot of effort into metadata reduction--critical as they are a single giant hosted relay service--and in the process (I am very sure) even fixed the issue I used to complain about wherein their server was technically keeping around a temporary-ish in-memory metadata log for rate limiting.
https://signal.org/blog/sealed-sender/
If you are going to switch to something, switch to Signal (...though I sadly can't in good faith ever really recommend anyone do that, due to how Signal has crippled the ability to do chat backups; more info on this in the other thread going on today re Signal/WhatsApp).
So, yes, for now the metadata leakage is a real issue. However this is likely to change in the near future.
Not trying to push Matrix or anything, i've been using Signal for some time already anyway, but thought i'd see what alternatives there are. The lack of chat backups is a real drawback, though since the Android version has a backup option, i'm hoping it's something they'll eventually implement?
I personally am scared because the language being used here is not at all specific to the scenario mentioned here ("hosted clients"). I understand that anything more specific would probably be rejected by their legal team. I am afraid that some 5 years down the line they'll be able to do something worse without notifying users because the TOCs and privacy policies are written in this ambiguous language.
Regarding alternatives, I can't really speak on the security/privacy of any of them but from what I can gather, Matrix does have E2E-encryption functionality [2] so I'm not quite sure how it is less secure than Signal (provided you host your own server and/or have a reasonable degree of trust in the server-operator of your conversation-partner).
[0] https://www.cgmagonline.com/2020/08/19/oculus-founder-facebo...
[1] https://www.eurogamer.net/articles/2020-10-15-oculus-quest-2...
[2] https://matrix.org/blog/2020/05/06/cross-signing-and-end-to-...
Obviously, though, (but maybe not to you?!?) this is a completely unrelated issue to the WhatsApp "changes" this week: trying to use "Facebook is evil, so everything they do is evil" is not only ridiculously disingenuous--to the point of undermining the ability to make these kinds of arguments at all and still be taken seriously :(--but doesn't even satisfy basic questions like "ok, and do you also consistently use this frame with Apple and Google?" (both of whom are also evil to the point of being morally reprehensible).
As for Matrix: they do not have a solution for metadata yet, and even have gone so far as to claim that maybe they will never figure it out (due to being a federated system). Your metadata just ends up getting semi-permanently logged on various machines, and there is nothing you can do about it at this time. AFAIK, Signal has implemented solutions to this (even, I believe, fixing the subtle thing I used to complain about where their server technically had a temporary in-memory metadata log for rate limiting).
https://github.com/matrix-org/synapse/issues/2188
https://github.com/matrix-org/synapse/issues/4565
(I have now provided a bit more quoted detail in this other comment, which i will link to rather than cause a lot of replication spam.)
Sealed sender means that an eavesdropper who can introspect into RAM inside Signal's AWS infrastructure is no better off than a network eavesdropper who passively sniffs ingress/egress.
That doesn't mean they can't build a reasonably accurate metadata database covering most people--people who communicate from a limited number of mobile ips to a limited number of mobile ips.
Signal is way better than matrix, but let's not pretend it has totally solved the metadata problem.
(I use "evil" in the technical sense: not necessarily intending to exterminate humanity, but wanting to be able to -- or anything short of that -- if they did.)
обманывать
Don't get me wrong, the Telegram crypto can (and should) definitely be criticized. But please criticize that they use "bad crypto" or "strange crypto" or "unreviewed crypto", not that it's their own. (And of course, substantiate such claims with references that can be discussed.)
(the criticisms are well enough known that people either aren't going to listen or can just go read them)
It’s almost as if your cognitive time series is not the same as everyone’s.
(why the parens)?
1. Folks spear-heading the Noise Protocol Framework (upon which Signal's protocol is based) are cryptographers [0].
2. They built upon existing standards for one specific purpose: Creating two-way secure channels [1].
At some point in time, all now well-established cryptographers will have developed their first own cryptosystem, without already having established a good reputation. Whether or not someone develops a cryptosystem without being famous for cryptography work is simply not a good argument for discussing a cryptosystem. The properties of a cryptosystem are a good argument for discussing it.
All protocols are invented at some point. Telegram did a terrible job marketing this one but it has been a long time now and the only issue I ever heard of was fixed some years ago. It's still not exactly pretty, but then look at TLS and I'm actually quite okay with mtproto.
The real issue is that mtproto is never used. It isn't implemented in most clients for no apparent reason ("can't keep state for encryption keys!" is the usual excuse - dude you keep my login token what's the big deal here) and if you try to use it, it doesn't sync between devices. One of the core selling points is a solid desktop experience.
And I can't tell if Moxie really means to improve the status quo or works for some three letter agency and builds just enough metadata opportunities into popular messengers and opportunistic encryption into WhatsApp to be helpful without being suspicious. To avoid redundancy, I posted these only yesterday and it includes some of the reasons: https://news.ycombinator.com/item?id=25669531 https://news.ycombinator.com/item?id=25669267
They don't cover everything unfortunately but I'm also getting annoyed with the ephemerality of HN. What's posted last week is forgotten and never looked at again. I can try to find old posts that cover it or type it all out again (and it's a big claim so very few people will even take the time to read a big comment with reasons in the middle of another thread). I'm also not denying he does good stuff, just that there are enough weird opinions (decentralization = evil, anybody but us = evil, bug bounties = evil...) that I carefully look at what he makes and would rather there were better alternatives than their central servers.
Signal is still the only realistic messenger to use for good security and usability, unfortunately. Wire is a good second but Signal is definitely more smooth and I'd still recommend that to the general public, with the asterisk that it's an American company and that they should try Matrix if they're feeling adventurous (Wire falling somewhere in the middle, at that point you might as well try Matrix).
Not a fan of Moxie either but you got a source for that?
As if Moxie having opinions that you don’t agree with is evidence for some covert NSA operation or some such. What nonesense.
Moxie is an anarchist (or near to it) and has been so for a long time. Secretly working for the NSA would be a stupendously long con.
> it's more of a hyperbole than something I truly suspect. It's just that their opinions are in line with the hacker community 50% of the time, and in line with surveillance organisations the other 50% of the time. Of course, he always has some reason for having the opinion, it's all covered up just fine, so it could also be perfectly legit. It's just weird to argue both sides at the same time.
His being an alleged anarchist, how does that hold with the prohibition for forks to use Signal's servers? Or the insistence that Google is the only place you should get the apk from? Shouldn't we all build from source, not trust a central distribution point? They argue both sides and I find it hard to tell what they really believe in.
That said, I definitely see your point and, as said, he does plenty things to improve the status quo. It's just his rejection of other things that would be even better.
No, you can but are not forced to. There is compiled apk (that autoupdates) which you can get directly from their website.
The moment a product is "secure by exception" rather than "secure by default," a huge benefit of E2E encryption is immediately thrown out the window. Sometimes the simple knowledge of which conversations are secure, and which aren't, is more valuable than the content of those conversations.
Furthermore, when everything is E2E encrypted, mass surveillance of message content is essentially quashed.
At this point, Matrix, Threema, and Signal are some of the more popular cross-platform solutions left to ponder about. Telegram nor WhatsApp are answers to any privacy question anyone may have.
But that situation is still that WhatsApp profits, and is produced and maintained by, one of the most morally bankrupt companies on earth.
So to ditch it is still a good thing.
What might need a warning is that the server can push new keys to your phone at any time and, unless you go into your security settings, you will never notice. Being warned of key changes is opt-in. That's why WhatsApp does, by default, opportunistic encryption.
But Moxie was involved in the implementation and got only a few million for publishing that claim so no worries y'all.
I've felt very uncomfortable about the way Valley firms jumped on board the end-to-end bandwagon. The intentions are good and ones I wholeheartedly support, but the claims made for it are just not true. The WhatsApp paper is at least slightly less deceptive than it once was, and I guess that's progress of sorts, but the damage is done already. One day Facebook will discover some sort of burning reason why a WhatsApp user has to be decrypted, it will come out that this has been done, and trust will be irrevocably burned.
They just removed the part about not having access to private keys.
Omission of the line doesn't actually mean that they now have access to private keys as well.
But honestly, it doesn't matter anyway since Whatsapp is somehow able to backup all your data on Google Drive and restore it on separate phones. How are they able to do that without backing up the private key?
https://faq.whatsapp.com/android/chats/how-to-restore-your-c...
> For example, if you use a data backup service integrated with our Services (like iCloud or Google Drive), they will receive information you share with them, such as your WhatsApp messages.
https://www.whatsapp.com/legal/updates/privacy-policy/?lang=...
Looks like you're right, it must be unencrypted.
I'm not sure they deserve the benefit of the doubt. Facebook has shown themselves to be dodgy as hell when it comes to our privacy.
I would prefer them to explicitly state that they don't have access to the private keys.
sudo apt-get install diffpdf
https://www.linuxlinks.com/diffpdf-compare-two-pdf-files/This change was introduced in October 2020
Of course the implication by the tweet is that they removed this claim because they added some mechanism for the client to turn over the keys.
The US usage patterns seem different, but where I am everyone has whatsapp and it's basically used as a sms system that actually works. If you compare whatsapp's security and features to sms security and features, you stop caring.
If you really want trustable end to end encryption, there are other apps for that :)
I just tried out version 1.4.4 for desktop, and device linking is nowhere to be found anymore.
⌘ https://github.com/loki-project/session-desktop/issues/1104
I independently implemented similar ideas over the holidays and then discovered that there were people with similar ideas.
Code:
https://github.com/adsharma/zre_raft/blob/main/zre_raft/zre_...
Usage:
https://github.com/adsharma/zre_raft/commit/b6f897539d1bef10...
This momentum is a good opportunity to ask friends and family to install Signal. Go for it!
For me personally I only ever used WhatsApp very lightly with a few work friends. After all of the recent news surrounding the app I sent a message saying I plan on leaving the app soon.
I wish it were easier to switch apps like this but it makes sense that they wouldn't want that to be the case.
I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.
They have a social graph that indicates who your probable friends are, regardless of actual Facebook/Instagram/Whatsapp friend status; using Bluetooth & Wifi identifiers based on physical closeness.
I have heard something similar to this but just assumed it was a coincidence. Has this every been proven with verified results ?
On Android, I can spoof the microphone access permission so that Whatsapp thinks it has access. I can then log whenever this permission is being used while giving it spoofed data. I have it done this for many apps and unsurprisingly, most try to access the microphone in the background over and over again. I have not done this experiment with Whatsapp yet, though.
What I use for this is XPrivacyLua by M66B, which also has suppory for scriptable hooks in Lua.
My story is: 2 years ago I was looking for an apartment. My friend who is an agent took me to an apartment. After viewing I messaged him on what’s app saying I liked the place but I want the landlord to put latches on the windows so it’s child safe.
After messaging him I went to Facebook. Scrolling the timeline. A minute later I have adverts for window latches and window grills for child safety.
I didn’t search Google or anything. I was shocked.
Chances are that you're either more predictable than you expected, or it's just random chance and correlation bias. Billions of people use these services, there have to be some freaky coincidences happening all the time. We need something a lot more solid than "I've heard people" to make any conclusion.
But the general point still holds, it's a closed source app made by a company that thrives on data mining, of course it should be considered insecure by default.
https://news.ycombinator.com/item?id=25686128
If it’s a coincidence it’s scary cos I have no idea how I posted something in chat to getting an advert for that within a minute.
This tweet doesn't establish otherwise.
It would also completely invalidate their "we don't have the keys" defence to law enforcement requests.