How WhatsApp enables multi-device capability
engineering.fb.com
engineering.fb.com
1. It's impossible to export your chat history, except for one conversation at a time. The only exception to this is if you root an android phone which gives you access to the raw database.
2. It's impossible to move chat history from an android device to an iOS device. And moving from ios to android is only possible with certain samsung phones.
3. It's impossible to access WhatsApp from more than one phone at once. This is mostly still true with this update. You cannot use the mobile app as a "companion device".
Do people not consider their chat histories valuable? I have my SMS history going back to 2011 (when I first got an android phone). Email can be archived. Facebook messenger keeps messages in perpetuity. WhatsApp is a frustrating outlier here.
Personally, no. I treat it like a real life conversation, if it's something I need to note later on, then I'll make a note of it outside of the chat app
No, I consider them a positive liability and delete messages/conversations as soon as they're done/actioned.
When the Brown Shirts come to get you, it'll be your own message history they hang you with. (Only slightly :))
Question: You have your SMS history going back a decade. How many times has that proven useful?
I, too, used to keep messages & emails "forever" until I realised that it was doing nothing for me but becoming a maintenance burden. Now I have "max 24 months" retention policy and have never once needed to retrieve an email older than that.
There are certainly some countries where this isn't a hyperbole. But in all others, suggesting that Nazis might come take you away because of messages you've written in the past is in pretty bad taste, IMO.
> suggesting that Nazis might come take you away because of messages you've written in the past is in pretty bad taste
These two statements seem conflicting. If we're already seeing it in places why should we not be concerned? It may be unlikely to happen here and to us, but why take the chance? The risk-reward tradeoff is extremely unbalanced. Like the above commenter said, how often do you go back in your history?
As a more real west experience we do see morals changing and we have been going through cultural changes. There are plenty of people who have had tweets uncovered with positions they themselves no longer agree with. That's a question people are trying to address right now but it is a difficult one to have because it is so heated. But it does boil down to "do people change opinions?" Personally I think the answer is obvious. But it is undeniable that history gets people in trouble, even if those histories were popular opinions at the time. (I wouldn't draw parallels to Brown Shirts with these instances as there's a big difference in scale and power, but I would draw parallels to Brown Shirts for countries with authoritarian rules where text histories are large liabilities and can get you killed or jailed).
Does other side delete it too? Otherwise if you delete you create a bigger liability in case the other side start claiming things that have not happened. For that reason it's vital to keep an audit trail and of course you need to have good op sec with that.
This is especially true if we're talking about targeted attacks it is a lot harder to find all your previous contacts and then search through those to find something to hang you on. Your side is consolidated and easily searchable. The other side is distributed.
Though I kinda miss old text messaging where you only had 250 texts max.
if your actions (or messages) are a liability, then why make them in the first place?
If you deleted your messages, it doesn't delete the record (from someone else's phone, for example, like a screenshot).
If the adversary is powerful enough (like a state actor), it matters not what your phone history is, because they can pin something on you anyway.
They may not be to begin with. Think changing morals or changing governments. Also I really hate this sentiment in general. Your solution is to just censor yourself. We're talking about about the abstract here.
> If you deleted your messages, it doesn't delete the record (from someone else's phone, for example, like a screenshot).
I feel like I literally addressed this above in my second paragraph. It's much harder to search multiple phones than a single phone that has all the information consolidated. Security is not about being bulletproof but that your are sufficiently difficult to attack. This distributed version of your data is harder to attack. That's the advantage.
> If the adversary is powerful enough (like a state actor), it matters not what your phone history is, because they can pin something on you anyway.
1) better something made up than something real. One is harder to fight and requires more resources for them.
2) what's the point of this comment? Are we just supposed to give up? No fighting back? This statement is always going to be true but isn't a meaningful trump card.
All else, purge every year
I suppose you don't want to do that, maybe because it gives a third party access to your history (although it should be E2EE), but I am writing this for readers who may stumble upon this
Android only let you use google drive. There's no way to transfer between the two
Where chat histories are valuable and where you see a "store and index it all" approach is enterprise chat. Slack, Google Hangouts Chat, etc, store and archive all the data because that is the collective wisdom of past and present employees and it is valuable to search through. Depending on the industry (i.e. Finance requires this via FINRA) it may even be mandatory to record all communications.
* unless you are moving to a new device, but even then it is rare to search that far back in history.
It is possible to do this with third party apps. Incredibly sketchy looking apps I should add, but they do work. I've done it several times both ways.
I used that effectively to keep long term archives of all my Facebook conversations. Critical for remembering what happened when and cat photos.
Transferring history between iOS and Android is a work in progress, it works now from iPhone to Samsung devices (for reasons I don’t really understand), general support is supposed to be rolled out the coming months.
If anyone is interested, I can dig up and share the software/company I purchased from.
If this new feature proves to work as advertised, I might as well sell my soul to the Facebook devil and go back to WhatsApp full time due to how frictionless the experience is (and everyone in the EU already being on it), and leave Signal only for private info sharing, as I grew tired of convincing people in my circles to move to Signal for privacy only to receive complaints that X,Y, Z features from WhatsApp are either missing, buggy or super frustrating to use on Signal. Oh, and receiving calls on Signal for Android is a mess (known bugs for years) where some calls just won't come through to my phone even if the desktop client is ringing, only to have it show up as a missed call notification on my phone a few minutes later. Unacceptable.
I do support the Signal team for their work and what they stand for, but my patience (and that of those around me I convinced to switch from WhatsApp) is wearing thin.
The traditional "WhatsApp Web" and "Signal desktop" are completely different experiences though.
Though the details differ, WhatsApp's new approach, outlined in this article, is much closer to what Signal has always been doing since it introduced Signal Desktop - which, once linked, functions independently of your phone.
I also selfhost a Matrix homeserver and bridge all-the-things to it, possibly its finest feature but there's no way any of its client implementations is going to spark joy in the hearts of the mainstream.
It's important, much like in our politics, to find the fine line between the extremes so that we can leverage and exploit good-enough choices for more freedom for everyone. I use Linux but for most people it's enough to at least get them to consider some FOSS alternatives in their Windows or macOS environments. We can use these small victories to chip away at the mortar of surveillance.
I will never, ever, return to Facebook products. The global damage wrought by that company will go down in the history books, I'm sure. So let's pick those things that are "good enough" as our chisels for a better future for all.
EDIT: Telegram has a chat export feature if you're a WhatsApp user considering the switch [1].
Oh yeah, especially the recent Smart Voting fiasco. A true hero.
[1] https://telegra.ph/Why-Telegram-had-to-follow-Apple-and-Goog...
(Personally, I'm also bitter that Signal Android supports backup while Signal iOS doesn't...and transferring from one iOS device to another isn't considered backup).
I also want to note that you can use them in parallel, no need to switch or convince other people to do so.
Your comment implies that security is being traded off in favour of convenience. Could you explain how?
WhatsApp "harvests “data linked to you,” including your device ID, for “developer’s advertising and marketing.” It also collects your contact info, user ID and device ID for ominously vague “other purposes.” (https://www.forbes.com/sites/zakdoffman/2021/03/06/stop-usin...)
It's true Facebook only collect metadata and can't read your actual messages normally, but that's still important. (https://www.eff.org/deeplinks/2013/06/why-metadata-matters)
As an individual, no, there's no need, you can use your phone number as a user ID (although this comes up as a concern whenever Signal is mentioned as an alternative). There's also a practical factor - using device IDs allows end-to-end encryption to multiple devices without the user needing to manage keys themselves. (ie: WhatsApp can just create a new key pair for each device).
As Facebook however, there is a business need to be able to identify a single user across multiple devices in order to properly track them for marketing reasons.
If Facebook are unable to do this, then the business case for operating a free messaging service falls apart. Each individual needs to make their own decision as to whether they are prepared to pay the price of sharing the data that Facebook collects in exchange for simple, free-of-cost, international messaging. It's not an easy decision.
Is your problem that a phone is required to be the primary device when doing this?
Basically people have been using their favourite messaging apps for years now and if they're satisfied they aren't going to switch.
The way e2e works is by exchanging public keys (kinda like a cryptographic username), imagine having multiple devices and verifying + keeping track of the keys from each device.
This is why im not surprised fb was the first to come out with this feature, you need fb level resources to get this out first and from a quick look at the article it seems like they're not using centralization to solve the problem.
"WhatsApp multi-device uses a client-fanout approach, where the WhatsApp client sending the message encrypts and transmits it N number of times to N number of different devices — those in the sender and receiver’s device lists."
Facebook takes part in the US government's mass surveillance operations, granting wide, possibly complete, access to users' communications. This was revealed by whistle-blower Edward Snowden and the documents he had released. Facebook's interaction with the NSA or other government agencies is kept secret, and will not be admitted, so when Facebook tells you your communications via its applications and services are secure, that is certainly not wholly the case, and quite possibly not at all the case.
Additionally, Facebook uses your communications for its own business interests, e.g. to manipulate you into paying for services or products whose providers pay Facebook, or for other kinds of social engineering. It stands to reason that this includes the information Facebook gathers about you from your WhatsApp conversations.
There are other messaging applications with multi-device capabilities - better or worse - and we should strive to use those with open source code, well-established algorithms, and transparent, robust and trustworthy governance as projects.
----
So - please do not use WhatsApp and try to get your friends and family to switch to alternative applications. Signal and Telegram seem to be the popular alternatives, even if they each have their own shortcomings and flaws.
As for commenting, I can’t speak for other Facebook employees but I made it a point to never comment on Facebook related discussions while I was still employed there. Frankly I didn’t see the point. Most threads would get so vitriolic and emotional that there wasn’t any space to have a discussion. There would be people spouting conspiracy theories like “Facebook controls discussions on HN”. No real point in engaging in such discussions, I figured.
"Please don't post insinuations about astroturfing, shilling, brigading, foreign agents and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data."
taking your own argument into account, using "popular alternatives" is probably not the right criteria here.
Telegram is not E2E by default, so the name shouldn't even appear in any list of recommendations.
It stands to reason that they miraculously break the end to end encryption of Whatsapp?
When onboarding a new device, it needs some amount of state in order for conversations to have a useful context. So the new sender device gets a bundle of recent conversations from who-ever onboarding it. I'm not clear on how you could control the amount of context or add more state, but that is off-topic.
What I'm wondering is: Does this have a race condition? Say that you have:
Sender A knows about receivers {B,C,D} Sender A sends message Foo to {B,C,D} Receiver E is onboarded at the same time Foo is sent. Is there no state where E does not receive the message?
I'm sure that this is accounted for and out of scope in a high level blog post, but I am curious how that part works.
It would be nice if it was the other way around - encrypted by default and unencrypted using settings
Multiple devices, multiple platforms, E2EE, gateways to other networks... my XMPP server handles all of that, and I convinced non-tech users to use it mainly because of the great Android client Conversations.
Yes, there are some rough edges because there isn't a iOS client that matches Conversations in terms of user friendliness. But siskin-im in on its way there.
I also have had complaints from friends but mainly because I am a shitty admin...
Oh, and having your phone number as your username is something that really is important for you? Use Quicksy then.
And that's the only client in existence that supports the XEPs required for XMPP to be a viable alternative in the modern world.
What about iOS? What about desktop?
> I also have had complaints from friends but mainly because I am a shitty admin
What if I don't want to run my own XMPP server? How do I find the one that supports message carbons, file uploads, encryption, push notification, client state indications...
That's not true, but admittedly that information is not trivial to find right now for end users. It's a known problem, and people are working on a nice comparison of XMPP client capabilities so people can make a more informed choice.
> What if I don't want to run my own XMPP server? How do I find the one that supports message carbons, file uploads, encryption, push notification, client state indications...
https://compliance.conversations.im/ or for something less overwhelming, https://joinjabber.org/
So, it's true for end users.
> It's a known problem, and people are working on a nice comparison of XMPP client capabilities so people can make a more informed choice.
There can't be more than a handful of usable XMPP clients in existence. The fact that "people are working" and "information is not trivial to find" speaks volumes about the state of XMPP clients.
> or for something less overwhelming
This is the reason XMPP is more-or-less dead for most users: "information is not trivial to find", "overwhelming" and so on.
Meanwhile already in 2016 Daniel Gultsch wrote what's expected of a mobile client for XMPP, and this can be easily extended to all other clients. [1]
Instead, 5 years later there's Conversations, "information is not trivial to find" and "check your server for compliance".
If you think nothing happened in 5 years then you're very much mistaken. As I said, the information should be more easily discoverable, and I linked you to some of the projects working on that aspect.
You seem to confuse "not easily discoverable" with "doesn't exist", which are different things when it comes to the kind and amount of effort required to fix them.
My own work is on Snikket, which is a project working on XMPP clients for all platforms with a modern feature baseline. My belief is that simply telling people to "use XMPP", and requiring them to find appropriate clients and servers is solving the problem from the wrong end. XMPP-based solutions should be attractive to people in their own right. Whether we like it or not, the average person does not (and will never) choose to use software because it "uses open standards".
From the point of users this: "information is not trivial to find right now for end users" is equal to "doesn't exist".
This is true for both clients and servers. When I asked "what if I don't want to run my own server", the very first link you provided me with was "Check the compliance of your server". Wat? I immediately closed the page, and I will never come back to it.
These things simply do not exist for anyone except hardcore geeks who are willing to figure all this out. 20 years ago when I was young I would do that. Now I will just open Telegram.
> My belief is that simply telling people to "use XMPP", and requiring them to find appropriate clients and servers is solving the problem from the wrong end. XMPP-based solutions should be attractive to people in their own right.
Yes! That's so very true.
Siskin [1] seems to be the best client for iOS right now. It's not as good as Conversations.
>What about desktop?
I am pretty happy with beagle (OSX) [2], Dino (Linux) [3] and Gajim (linux, windows, OSX) [4]. If in-browser is your thing, converse.js [5] or movim [6] come to mind.
>What if I don't want to run my own XMPP server?
Use quicksy.im?
[3] https://dino.im
What are blabber's or monocles' selling points compared to Conversations? I couldn't find with a quick search, but I'm open to suggesting them instead of Conversations if their UI is better.
Overall both are very frontend centric modifications, focusing on user comfort.
Multiple platforms... but iOS a night mare with E2EE
Gateways to other networks... Honestly I couldn't find working ones
Why would you want to make a phone number your user ame - this way you are sharing it with almost everyone...
My message history in sync'ed between Conversations (Android), Dino (Linux), Gajim (also Linux) and beagle-im (Mac OS X). Not sure what you are referring to.
>Gateways to other networks... Honestly I couldn't find working ones
Anything supported by pidgin can be used as a gateway through spectrum2. I use telegram and mattermost this way. I admit that spectrum2 is a bit confusing to set up, but it works!
>Why would you want to make a phone number your user ame - this way you are sharing it with almost everyone...
I am with you on this! But to many non tech user, this seems to be important. Some get the feeling that they don't "create an account" when they use whatsapp or similar.
Upd. See also:
WhatsApp whitepaper removed sentence about never having access to private keys (twitter.com/shiftreduce)
491 points by Aissen 8 months ago | 106 comments
But then again, WhatsApp actively hides the feature away behind menus and pretends it's not really a thing, while Element is a bit more pushy about telling you about it.
Does "non-phone" here at least include "iPad"? The use case of "if your phone battery is dead" is just such a non-issue for me, as I have a million other critical reasons to keep my phone charged and online... but having the WhatsApp external client--the one you install on laptops--available for iPads and even other phones would actually open up new use cases for me.
I'd therefore like to see future chat services like this to just have one big S3 backend (or similar).
Also now, when a conversation is archived it remains archived even if someone in that group posts something. Before when someone in an archived conversation posted something the conversation would be unarchived.
This would be much easier for an application where all state is stored in clear-text on servers.
And even harder for services which are trying to avoid storing metadata on servers as much as possible, such as Signal.
What is FB doing that allows this on Whatsapp but not Signal.
What a WhatsApp users opening themselves up for here?
> Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that."
Ever since Signal introduced the desktop client, its multidevice functionality has involved fully fledged signal-protocol sessions between each device.
It sounds like WhatsApp is now adding something like this to their client, though it sounds like some of the details of the scheme differ.
In principal the signal protocol works fine for a multidevice scenario.
Oh, no...
Which means the server can just substitute keys in.
Users can catch a malicious server injecting incorrect keys by looking at security notifications and comparing security codes. This is part of the Signal protocol.
This may be tedious but only needs to be done in the event of phone keys getting reset (a once in a year event?), as all companion device keys are automatically verified with signatures provided from an account owner's primary (phone) device
Source: https://www.whatsapp.com/security/WhatsApp_Security_Whitepap...