WhatsApp's secure messages aren't so secure after all

Discussion in 'mobile device security' started by ronjor, Jan 13, 2017.

  1. ronjor

    ronjor Global Moderator

  2. Tarnak

    Tarnak Registered Member

    Don't use, and will never use it. So, no problem, for me.
     
  3. kC_

    kC_ Registered Member

    Anyone looking for an alternative I can recommend signal private messanger.
     
  4. Sampei Nihira

    Sampei Nihira Registered Member

  5. ronjor

    ronjor Global Moderator

  6. ronjor

    ronjor Global Moderator

    There is no WhatsApp 'backdoor'
     
  7. lotuseclat79

    lotuseclat79 Registered Member

  8. TheWindBringeth

    TheWindBringeth Registered Member

    Plausible user-convenience trade-off or plausible deniability? Is it even possible to distinguish one from the other?

    If/when there is a legitimate security vs convenience decision to be made, should a developer silently default to "convenience" and require users to locate and opt-in to "security"?
     
  9. Sampei Nihira

    Sampei Nihira Registered Member

    Account/Security - Enable show security notifications.

    This option is disabled by default.
     
  10. lotuseclat79

    lotuseclat79 Registered Member

  11. TheWindBringeth

    TheWindBringeth Registered Member

    Heads up:

    http://arstechnica.com/security/201...e-umbrage-at-report-its-crypto-is-backdoored/ (posted above)
    https://www.theguardian.com/technology/2017/jan/14/whatsapp-vulnerability-secure-messaging-apps (new)
    The HN discussion about WhatsApp contains constructive criticism that might serve as a reference.
     
  12. Minimalist

    Minimalist Registered Member

  13. guest

    guest Guest

  14. 93036

    93036 Registered Member

    Last edited: Jan 24, 2017
  15. TheWindBringeth

    TheWindBringeth Registered Member

    I think you'd need a scoring system in order to rate the safety/security of WhatsApp and similar tools. With bullet points for each of the specific technical requirements that one would want such an application to meet. Which would include whether any messages can be MITM'd, whether users can be alerted to recipient key changes, whether users can be alerted before the new key is used (so they have a chance to verify or abort), whether there is a third-party server in the middle that can collect contact info and/or metadata about messages sent/received, whether the app can be used in a way that protects messages from platform leaks (cloud backups, sync, etc), and so forth.
     
  16. Minimalist

    Minimalist Registered Member

    https://www.forbes.com/sites/thomasbrewster/2017/05/08/whatsapp-enhances-icloud-encryption
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice