Slashdot Mirror


WhatsApp Enables End-To-End Encryption For All Forms of Communications By Default

Popular instant messaging app WhatsApp, on Tuesday, announced that it is turning on end-to-end encryption for all its users by default. The company says that every call a user makes, every text message they send, all photos and videos they share will now be more secure. Furthermore, the encryption status of any chat is visible under the chat's preferences screen. The announcement comes a little over a year after the Facebook-owned company partnered with Open Whisper Systems, a nonprofit software group that develops collaborative open source projects with a mission to "make private communication simple." The end-to-end encryption feature is available on the latest version of the app. In a blog post, Open Whisper Systems further explains the feature: Once a client recognizes a contact as being fully e2e capable, it will not permit transmitting plaintext to that contact, even if that contact were to downgrade to a version of the software that is not fully e2e capable. This prevents the server or a network attacker from being able to perform a downgrade attack. In a blog post, WhatsApp writes: While WhatsApp is among the few communication platforms to build full end-to-end encryption that is on by default for everything you do, we expect that it will ultimately represent the future of personal communication. WhatsApp has also made available the technical details about how the two companies implemented this feature (PDF). For those of you who haven't heard of WhatsApp, it's an instant messaging and voice calling app. The free service, which is available across all popular platforms, is used by more than a billion people worldwide every month. A report on Wired says that a team of only 15 engineers enabled this security feature for over a billion users. Privacy researcher and activist Christopher Soghoian rightfully adds, "Google has no excuse."

20 of 76 comments (clear)

  1. Nice by Anonymous Coward · · Score: 3, Insightful

    Nice, as it prevents dragnet surveillance. Still I don't want to use what's app just like signal as it doesn't work without GCM, with google/apple knowing my ip address all the time.

    The companies build their encryption so that only the data they are interested in and will monetize reaches them. But they still monetize your data. And for every encrypted messaging app that pops up, the moment you use a whatsapp bot or siri or google maps or whatever, they know your location.

    1. Re:Nice by fph+il+quozientatore · · Score: 2

      Wait, I am confused: I am currently using Whatsapp on a phone that does not have Google Play Services installed. Wouldn't that be a prerequisite to use GCM? (Possibly noob question, sorry, I haven't even written a hello world on Android.)

      --
      My first program:

      Hell Segmentation fault

  2. I bet the stream from the Occulus spying... by Torp · · Score: 2

    ... in your living room will also be encrypted so only Facebook can data mine and sell it.

    --
    I apologize for the lack of a signature.
  3. I don't trust this and simply wonder WHY? by xiando · · Score: 5, Insightful

    Perhaps they really are implementing secure end-to-end but from their previous actions this announcement makes me suspect that something else which is actually secure is becoming so popular that an "approved" "secure" (but not really) needs to be pushed out to the ignorant masses.

    Show me the source code and I will consider trusting that this is secure. I am not going to just take their word for it because they have proved that it means nothing time and time again.

    1. Re:I don't trust this and simply wonder WHY? by rainwalker · · Score: 4, Informative

      As I'm not a cryptographer, I have to trust what experts tell me (source code doesn't really help with this). Given that the people at Open Whisper Systems, who are fanatical privacy and security researchers and advocates, and who built the protocol that's being used and helped WhatsApp implement it, are giving this their stamp of approval, I'm just going to have to trust them. At some point, you have to pick that trust point, and Open Whisper Systems seems like a good point.

    2. Re:I don't trust this and simply wonder WHY? by Pseudonymus+Bosch · · Score: 4, Informative

      In the words of Edward Snowden, "Use programs like Redphone, like Silent Circle â" anything by Moxie Marlinspike and Open Whisper System."

      --
      __
      Men with no respect for life must never be allowed to control the ultimate instruments of death.
      GW Bu
  4. Re:Encrypt all you want by Anonymous Coward · · Score: 3, Funny

    Fuck off for both of your "paragraphs".

  5. Monetization? by ramirodt · · Score: 5, Interesting

    How do they make money if they cannot sift through your data?

  6. Fully encrypted by ThatsNotPudding · · Score: 3, Insightful

    (except for all your data and metadata backdoor copied to the hivemind of Facebook). Why do you think they bought WhatsApp? To ensure they could NOT sell the product (users) to the customers (advertisers and TLAs)? Please. I wouldn't trust Zuckerburg farther than I could throw his precious snowflake (who is doomed to grow up to be an abject nightmare).

  7. Re:Weasel words by rahultyagi · · Score: 3, Informative

    Nope, in this case it really does look like the other "end" is the other party and not WhatsApp's servers. So, unless they are lying about it, it really does seem like user-to-user encryption (and hence, as you point out, no data mining for facebook).

  8. Re:Weasel words by Anonymous Coward · · Score: 4, Informative

    The message content is opaque to them, but the meta-data of who talks to who, when, for how long and how often is not. Last I checked you still need a real phone number to sign up, so they can tie nearly all of their users to their real world identities. Considering that they are owned by facebook, all that meta-data gets fed in to facebook's behemoth databases of personal info.

    So it seems likely that even full-blown e2e is still revenue positive for them.

    That said, going full e2e, even with all the facebookian compromises is still an improvement in the baseline. This is a war of inches, so every inch matters, even when there is still a long road ahead.

  9. WhatsApp is free, buddy by Anonymous Coward · · Score: 2, Informative

    Straight from the horses mouth:

    https://blog.whatsapp.com/615/Making-WhatsApp-free-and-more-useful

    Tell me more about this business model you know so much about.

  10. Meanwhile, in jabber land by grasshoppa · · Score: 4, Insightful

    Meanwhile, in the land of the XMPP protocol, we've been end to end encrypted for over a decade.

    Seriously, why is it 2016 and this is NOT a standard feature of a chat protocol?

    --
    Mod me down with all of your hatred and your journey towards the dark side will be complete!
    1. Re: Meanwhile, in jabber land by Anonymous Coward · · Score: 2, Insightful

      And this is why you don't have e2e encryption -- because you want to shit on the only protocol that has had e2e for over a decade.

      So to keep your snark going, dickhead:

      Meanwhile in the real world nobody really cares about end to end encryption because they could have had it by demanding and using XMPP but instead they decided to whore themselves out to the flashy and shiny Facebook and friends and agree to have their privacy raped and pillaged for no other reason than they needed to know what all of their "friends" were up to every fucking minute of the day.

      "Facebook and friends" are not interested in really giving your e2e on all of your communications because then they couldn't whore you out to the marketers that really pay their bills.

    2. Re: Meanwhile, in jabber land by grasshoppa · · Score: 3, Interesting

      That's more an indictment of the real world than jabber, wouldn't you say?

      That said, I don't know how popular the openfire server is, but that uses the same protocol ( XMPP ) as jabber. I know I use it quite extensively.

      --
      Mod me down with all of your hatred and your journey towards the dark side will be complete!
  11. Re:Does the User Control the Keys? by Meneth · · Score: 4, Informative

    The user's device generates the private key, but only under the control of WhatsApp's closed-source app.

    The key exchange is done through WhatsApp's server, much like message exchange. There is no revokation, though I imagine a user who loses his private key could generate and register a new one. There are no certificates except for the connection to the server.

    An attacker would have to take control of WhatsApp's server, but once that is done, they could run classic MiTM attacks on all WhatsApp users.

  12. intellectually dishonest. by Anonymous Coward · · Score: 4, Informative

    The user's device generates the private key, but only under the control of WhatsApp's closed-source app.

    The key exchange is done through WhatsApp's server, much like message exchange. There is no revokation, though I imagine a user who loses his private key could generate and register a new one. There are no certificates except for the connection to the server.

    An attacker would have to take control of WhatsApp's server, but once that is done, they could run classic MiTM attacks on all WhatsApp users.

    This is intellectually dishonest. Whatsapp allows you to verify the key signature either via barcode or via hash comparison.

  13. Re:Does the User Control the Keys? by nospam007 · · Score: 5, Insightful

    "An attacker would have to take control of WhatsApp's server, but once that is done, they could run classic MiTM attacks on all WhatsApp users."

    But in this case it would be THE MAN in the middle.

  14. EFF Secure Messaging Scorecard by uassholes · · Score: 3, Informative
  15. Re:Does the User Control the Keys? by Agripa · · Score: 2

    I have not used it but apparently the client has facilities to verify the key through an auxiliary communications channel manually (voice, text, whatever) so it would just take getting caught once to show that the WhatsApp server was compromised. I believe PGP phone had the same capability.