WhatsApp end-to-end encrypted backups security assessment
research.nccgroup.com
research.nccgroup.com
I quote the author:
This is really weird. In #WhatsApp, I started to see messages that I know 100% that I deleted 2 days ago?! WTF is happening there? I think this is a really big violation of privacy! I see the messages from a month ago, with my disappearing messages setting turned on?! Gosh
https://twitter.com/pytlicek/status/1445072626729242637?s=21
This is not surprising - when you ask someone else to route messages for you, even encrypted messages, you are giving them the (encrpyted) payload and asking them to route it for you.
If you have a large network with billions of users, it's reasonable that some of the users' phones may be offline some of the time.
Should the service just drop messages on the floor when that happens, or buffer them in some queue (recall, they're E2EE) that gets emptied every so often?
Now assume all your infra has a hiccup (outage) and goes offline, and then comes online again.
Probably the retry logic didn't synch correctly and attempted to retransmit encrypted messages that had already been delivered.
In the second tweet the user says "3 chats before the outage and now 15+ or more chats which I deleted before the week or two."
Two weeks (and in screenshots, only 8 days shown) does not seem surprising. Especially given the increasing rate of internet shutdowns across the globe [1].
E2EE is too important to play fast and loose with.
[1] "In 2020, Access Now and the #KeepItOn coalition documented at least 155 internet shutdowns in 29 countries." (https://www.accessnow.org/keepiton/)
Any other features are dependent on the protocol that uses the secret key. You will generally see an encryption method that is protected against cipher-text manipulation, but e2e does not guarantee that. Similarly, a protocol that uses e2e encryption can add replay protections, but it is not at all a feature inherent in e2e.
I could well imagine that whatsapp has some replay protection build in. I could similarly imagine they have a way to override that in case they need to. Heck, perhaps the replay protection is implemented with WhatsApp as the ultimate arbiter of what counts as a replay. As long as WhatsApp does not know the key used to encrypt my messages, the encryption is e2e in my book.
I mentioned this on Reddit and someone replied that they saw it too with hundreds of deleted messages going back to 2015 returning.
[0] https://en.wikipedia.org/wiki/Hash_table#Open_addressing
The option should be labelled as 'Hide Message*' together with a link to an explanation of the feature & its limitations.
This is not a trivial problem and I don't want to downplay their effort and transparency. Seeing their struggle and audits is a good sign - they are doing the right things.
In the cited documentation below ([0]), it claims that media will not be saved for either method 1 or 2 ("To stop media from all your individual chats and groups from being saved" and "To stop media from a particular individual chat or group from being saved").
I found out that the media is in fact written to storage, straight to the "Private" directory ("Internal Storage/WhatsApp/Media/WhatsApp Images/Private"). Said directory includes a ".nomedia" file which inhibits the Gallery app from your phone to see such media. So if you were to copy the "Media" directory into your PC, such "unsaved media" would come with it.
Also, when sending View Once media ([1]), it can be easily screenshot on your smartphone, or if you're using WhatsApp Web, use the DevTools while image is open, so you can grab it in their transmitted resolution.
Want to grab a status from a contact? Go to "Internal Storage/WhatsApp/Media/.Statuses" (enable view hidden directories in your Files Explorer application) and copy/move the file elsewhere, so it goes out of reach when WhatsApp tries to delete it.
Not to spill poisonous words around here, but I highly doubt they take security seriously.
[0]: https://faq.whatsapp.com/android/how-to-stop-saving-whatsapp... [1]: https://faq.whatsapp.com/general/chats/about-view-once/?lang...
Likewise touching file storage makes sense, the media files have to sit somewhere. Any vaguely modern android phone has full disk encryption, so it's only apps with global filesystem access that present a threat.
I'm not an expert in Java Android, but I'm pretty certain there must be something like that.
You can't check chapter markers or frame counts because they are encrypted.You can't usually partially decrypt a file either.
Every time you want to read some data off flash, you read it then immediately decrypt it. Any time you want to write data to flash, you decrypt it first. Checking chapter markers or frame counts will be the same as before as long as you decrypt those bytes immediately after reading them from flash.
For the non-private media, just write it to storage straight away.
Nope, look up HDCP. They could enforce that on desktop if they wanted to.
> or just take a picture using a second device.
Yes, but you will lose quality.
If you have your phone rooted, go to the "/data/data/com.whatsapp" using a terminal, and copy the messages database to the Internal Storage (wherever that is, I don't have any rooted device right now with me).
Then extract that file to your computer and use any SQLite3 viewer. It's not encrypted.
You'll find messages since the very first install of WhatsApp, even if you deleted these.
Last tested: about the year 2017.
"My Files" ("com.sec.android.app.myfiles" on Samsung Android) is an app and certainly has access to those files.
If that app has access to that directory, certainly many other apps do have access, such as Samsung Gallery ("com.sec.android.gallery3d" on Samsung Android). Of course, in the case of the Gallery app it's just used as an image viewer, but that is not an inhibition for another app to exfiltrate these directories into a server.
What if some malicious app synced WhatsApp directories into a 3rd party server? I don't see it too hard.
Note, I hate Facebook, but there’s nothing worse than when someone/something tries to get better in good faith, and we shit on their efforts simply because their starting position is weak (aka fat shaming the new person at the gym).
Signal and Matrix are open source and full-featured.
I said same things to most of my closer people and in the end they tell me “well they have all our data anyway”.
And all they have to do is just download an application.
I understand these aren't huge obstacles, but I am generally reluctant to add additional communication channels for these reasons - they aren't trivialities to everyone.
Messengers usually don’t have forwarding or a sensible polling interface. It would be nice to have all-in-one app even with limited functionality, since I’m mostly using text and images. Or use one of real full-featured messengers with gateways to others.
The people who can judge if Facebook are to be trusted should be in the millions by now though...
Actually, no that's not sufficient evidence. That's only sufficient evidence for those interactions between the auditors and whatsapp's servers, it doesn't say anything about your interaction with whatsapp's servers. And that's the heart of the problem: using code shipped to a browser for e2e encryption is a flawed model, it would be trivial to target you with a version that has broken e2e encryption but subtle enough that you would never notice.
Signal may be open source at times, but that alone is not a reliable factor for the platform/company to be considered as trustworthy.
Agreed - I've moved ~80 of my friends from Messenger to the free Matrix server, and I host my own server. It's a wonderful experience.
This absolutely untrue. Signals source has NEVER been closed source. The Signal server source code(which isn't special and doesn't change that often) just had no public commits. The Signal client source code(what matters and makes Signal secure) was frequently updated.
> Signal may be open source at times,
Again, Signal has always been open source.
So it was opensource... you just couldn't see the source running on the servers? Yeah, makes sense. Right.
The client source code is the only thing that's really relevant in an e2e encryption model, anyway. Regardless, 100% of the production versions of the Signal server software have been published under free software licenses, so I'm not sure what you're arguing.
But I think what they're trying to say is because signal prevents any user from being able to use the signal app with servers they the user control. You're stuck with trusting the people running the servers because they say they won't do anything wrong. The whole reason you say the client is what matters is because it's something the user doesn't need to trust somebody else won't do something wrong. if I can build my own client and validate myself The security doesn't depend on blindly trusting somebody else because they say it's safe to do so.
A well designed encrypted protocol doesn't depend on blind trust in some service. The main signal app requires blind trust in the servers they control.
Now with signal and other E2EE messengers, you can just get the metadata graph, maybe. Not using the standard set of servers makes you stand out in a different way metadata wise, and more vulnerable, because you don't have as much labor available to secure your personal network, which is what your hinting at. It's partly why tor is a public network, because they want more noise in metadata analysis, and why you want to use VPN providers, so it's not just "you" that is aggregating your traffic.
The 3rd era will do both in a usable way, but usable ones don't really exist yet. All you have is research messengers.
One step at a time. Perfect is the enemy of good, or something better.
Phrased differently; Other messengers don't protect privacy so it's acceptable for this one claiming security to break privacy too.
> Now with signal and other E2EE messengers, you can just get the metadata graph, maybe. Not using the standard set of servers makes you stand out in a different way metadata wise, and more vulnerable, because you don't have as much labor available to secure your personal network, which is what your hinting at.
No, that's not what I'm hinting at. I'm complaining signal pretends it's primary focus is privacy any security, but fails at some of the most basic designs! If someone is targeting me specifically they can own my server, and I'm screwed. But using my server; if they own Signal, they don't get me for free. The inverse is correct as well, if they're targeting me, and they own me. They might not put forth the effort to own Signal. And if your opposition includes people who can server a sealed warrant, hacking into signal might not even be needed.
> It's partly why tor is a public network, because they want more noise in metadata analysis, and why you want to use VPN providers, so it's not just "you" that is aggregating your traffic.
What?
> The 3rd era will do both in a usable way, but usable ones don't really exist yet. All you have is research messengers.
> One step at a time. Perfect is the enemy of good, or something better.
No, that's not true about security. No security is better than half-assed security. Especially if you don't know it's half-assed.
Those are some of the few companies that are large enough to oppose governments.
> Signal and Matrix are open source
The main advantage of which is to enable audits like this, which WhatsApp is doing.
Of course you can't actually build WhatsApp from the audited source or pin it to the audited version... but you can't do that with Signal either. Not to mention that you're stuck with closed-source Google Play Services (or closed-source iOS) anyway.
They're more likely to cooperate with governments because they have so much to lose. All the big guys are caving in to China for example because they don't want to lose that sweet 1+ billion consumer market. Yes even Google. Check maps.google.cn and see the border around the South China Sea.
And also their interests are much more aligned with the governments, being entities similar in size and controlled by huge shareholder interest groups.
Oh and finally most of them don't even pretend to oppose government interests. Even Apple.
The best thing about Matrix is that both the software and the network is open and decentralised. This is why I prefer it over Signal (which even frowns on third party clients)
However I also think more people are on WhatsApp than those two (and possibly more) combined and people want to just use it probably for that reason.
I saw some of my contacts sign up to Signal firstly after the privacy fiasco then again in smaller quantity after the major outage. I deleted WhatsApp a while ago but I decided to re-install it again recently or basically risk losing contact with some old friends. In fairness I did try and convert people to Signal; I managed to convince a couple - so not all was lost.
Can you highlight your collective pet peeves ?
It should also be noted that we are not privacy-critical, just like these “numb people” I believe, who choose over little details rather than a big picture. Our background at the time was whatsapp, telegram and viber.
Another very small thing, but it irks me slightly - the chat bubbles are rounded too much.
And that's before we get to Whatsapp == Facebook.
> Weak 512 bits RSA key signing key
That's unprofessional at best, negligent at worse. I understand that it's quite a bit more calculations at more key lengths, but still, 512 is simply looking for trouble.
> It enforces a maximum number of user login attempts, in order to prevent brute-force of a user PIN/passphrase; after ten unsuccessful attempts to log into an account, the account is locked and the backup data is irremediably lost.
That's essentially a denial of service waiting to happen. So if another actor can access my account (e.g. has access to the telephone operator), they can destroy my backup. I would understand a delay between retries (maybe a week ?), but just throwing out the backup is just bad.
This is why I don't have an fb, wa, or ig account. If you want to talk to me, you can't do it on there.
This is first-hand as well. But I'm not the one making a universal claim.
We value our independence highly. It is what ultimately brings in business. It would be very bad business if one our customers gets hacked, when it was an easy vulnerability for us to find.
This is the same for the NCC group here. If in a few weeks the WhatsApp e2e encryption on backups was cracked, they would look like fools. And that is not good for business.
This doesn’t tally with my own experience and I’ve worked with many including NCC Group.
There are firms that do what you say--they write a report that says how totally wonderful it was to work with you and how wonderful it is that you quickly fixed all the informationals they found, and what a genius you were to work with them. And they happily make these reports public.
Reputable firms will write savagely brutal reports when warranted.
It now has backups which rely on 'trusted' hardware security modules in Facebook's data centers.
That seems like a serious downgrade to me.
1. Backups are opt-in - just as they have always been.
2. The E2EE backups do not rely on HSM's - they rely on a client-side only key derived by the WhatsApp client, on the user's phone.
3. The client-side key backup does not rely solely on HSM's - naturally, the client-side key must be backed up in case the user loses their phone. This key is itself encrypted and stored remotely (whether this is on third-party cloud or on WA servers is unclear from the report). However, decrypting it requires a user passphrase, known only to the user.
4. The design uses HSM's additively, not as the only support - via an OPAQUE exchange the user can combine their passphrase with a per-user secret stored in the HSM to derive, client-side, the key that unwraps the backup key. OPAQUE ensures WA cannot learn the user key material required to derive the key that unwraps the backup key.
This is all on page 6 of the published NCC report.
This for local backups, but I assume that the encryption schema is the same for a backup on Google Drive (just the file that would be stored locally is uploaded into Google Drive in a non user accessible location).
By the way I don't care that much of backup secrecy, in fact I use mainly Telegram even if everything is on the server clear text. WhatsApp tries to give users a false sense of security in my opinion.
i don't mean to be ironic, i genuinely couldn't understand after reading the paper.
I have only used key derivation in symmetric protocols, so tbh I don't know how you do deterministic asymmetric key generation, or even which primitive uses it.
Of course we still have to take their word from it that the app doesn't secretly store this key somewhere. But I suppose this audit will validate that. I have to do a deep dive into it. The problem remains of course that this app can be modified at any time through the update mechanism.