Slashdot Mirror


Top Security Researchers Ask The Guardian To Retract Its WhatsApp Backdoor Report (technosociology.org)

Earlier this month The Guardian reported what it called a "backdoor" in WhatsApp, a Facebook-owned instant messaging app. Some security researchers were quick to call out The Guardian for what they concluded was irresponsible journalism and misleading story. Now, a group of over three dozen security researchers including Matthew Green and Bruce Schneier (as well as some from companies such as Google, Mozilla, Cloudflare, and EFF) have signed a long editorial post, pointing out where The Guardian's report fell short, and also asking the publication to retract the story. From the story: The WhatsApp behavior described is not a backdoor, but a defensible user-interface trade-off. A debate on this trade-off is fine, but calling this a "loophole" or a "backdoor" is not productive or accurate. The threat is remote, quite limited in scope, applicability (requiring a server or phone number compromise) and stealthiness (users who have the setting enabled still see a warning; "even if after the fact). The fact that warnings exist means that such attacks would almost certainly be quickly detected by security-aware users. This limits this method. Telling people to switch away from WhatsApp is very concretely endangering people. Signal is not an option for many people. These concerns are concrete, and my alarm is from observing what's actually been happening since the publication of this story and years of experience in these areas. You never should have reported on such a crucial issue without interviewing a wide range of experts. The vaccine metaphor is apt: you effectively ran a "vaccines can kill you" story without interviewing doctors, and your defense seems to be, "but vaccines do kill people [through extremely rare side effects]."

70 comments

  1. Take a note of who is doing the requesting by Anonymous Coward · · Score: 0

    These are the sellouts you should ignore in the future. Schneier has no excuse.

    1. Re:Take a note of who is doing the requesting by Anonymous Coward · · Score: 0

      If everyone on that list should be ignored we have a serious problem. The list is a whos-who of the most reliable sources of information on security.

    2. Re:Take a note of who is doing the requesting by arth1 · · Score: 1

      That's the problem with humanity vs security in a nutshell: We're hardwired to put our trust in people, instead of facts.

      In sciences, who says something is not important, what is being said is.
      Any scientist or security expert worth his salt should be the first to admit that they often make mistakes, and that nothing should be taken as gospel, but be verified.

    3. Re:Take a note of who is doing the requesting by fustakrakich · · Score: 2

      The list is a whos-who of the most reliable sources of information on security.

      That's part of the problem. Real security people don't expose themselves to the public, much less talk to the press.

      These people here just serve big business and have every reason to whitewash the report.
      Nice bit of propaganda there:
      *a defensible user-interface trade-off* The threat is remote, quite limited in scope, applicability (requiring a server or phone number compromise) and stealthiness (users who have the setting enabled still see a warning; "even if after the fact). The fact that warnings exist means that such attacks would almost certainly be quickly detected by security-aware users.... Telling people to switch away from WhatsApp is very concretely endangering people... (??!)
      Say whaaa? A little dramatic and self serving, no?

      The problem that it exists.

      --
      “He’s not deformed, he’s just drunk!”
    4. Re:Take a note of who is doing the requesting by cryptizard · · Score: 3, Insightful

      What are you even talking about. A bunch of people that signed the editorial are academic cryptographers who work for universities. What big business are you talking about now? Mozilla is the biggest business represented in the list, do we hate them now too? The EFF? Do we hate them? I can't keep up with things around here.

    5. Re:Take a note of who is doing the requesting by Opportunist · · Score: 4, Interesting

      Dude, take a look at what's happening here.

      The "security hole" in question here is basically the same deal as you have with every other service where you can transfer your service to a new device. You know, you buy a new phone, then want to continue using your IM or whatever on the new phone... but with the new phone you'd also get to negotiate new encryption keys. And that means that all messages still in the queue would be lost, because they have been encrypted with your old key.

      That's the whole "exploit" here.

      There's plenty of reasons to distrust WhatsApp and even more reasons to avoid it like the plague, not the least of which being that it hands all data over to FB despite first claiming and vowing that it would never do that.

      If THIS is your reason to distrust WhatsApp, you have bigger problems.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    6. Re:Take a note of who is doing the requesting by Opportunist · · Score: 3, Insightful

      Yes, but even in the area of science you'll notice that who says something still has some meaning.

      If I say that at the center of every black hole there is a little pink teapot, you'll call me a crackpot and be done with it.
      If Stephen Hawking made this claim, I bet you would want to know his reasoning.

      At the very least this meant for me that I would want to see why Bruce considers it a non-issue.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    7. Re:Take a note of who is doing the requesting by cryptizard · · Score: 1

      There's plenty of reasons to distrust WhatsApp and even more reasons to avoid it like the plague, not the least of which being that it hands all data over to FB [gizmodo.com] despite first claiming and vowing that it would never do that.

      They might do that eventually, but they currently don't and never have, FYI. The plans were scrapped after some legal conflict in the UK.

    8. Re:Take a note of who is doing the requesting by Opportunist · · Score: 1

      Real security people don't expose themselves to the public, much less talk to the press.

      Are you kidding? Nobody listens to you if your name doesn't ring bells. Publish or perish IS pretty much what makes or breaks your career as a security expert these days. You think any of them have a problem getting a speaker slot at any security conference if they so please? Or get any contract they'd want?

      It's sad, but yes, security has become a spectacle. Welcome to the show, watch our CSI-esque presentation of how we penetrate your defenses with style...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    9. Re:Take a note of who is doing the requesting by Opportunist · · Score: 1

      Find a way to convince me to actually believe that they complied.

      Why would FB acquire WA? Because they really loved to have a messenger service in the portfolio but without any interest in leeching the data? C'mon.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    10. Re:Take a note of who is doing the requesting by cryptizard · · Score: 2

      Because they want the IP and engineers to make their messaging better?

    11. Re:Take a note of who is doing the requesting by Xylantiel · · Score: 1

      Um, Facebook (the company) owns whatsapp, so facebook owns their data. Transfer complete. The rest is just a shell game subject to how much money they want to spend on litigation.

    12. Re:Take a note of who is doing the requesting by cryptizard · · Score: 1

      The question is whether Facebook shares it with third parties. Of course Facebook "owns" the data, no one is arguing that.

    13. Re:Take a note of who is doing the requesting by BarbaraHudson · · Score: 1
      And they have an agenda, just like everyone else. To say

      The fact that warnings exist means that such attacks would almost certainly be quickly detected by security-aware users. This limits this method

      ... shows that there's either more a play here, or they are f*cking retards. And yes, both Mozilla and EFF belong on the list of assholes if they agree with this statement.

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
    14. Re:Take a note of who is doing the requesting by cryptizard · · Score: 1

      What don't you agree with in that quote? This is not a scenario where every person has to be security aware, if only ONE person ever catches WhatsApp doing this then it would break the whole thing wide open. You don't have to rely on every user being security-aware, only that at least one person will notice if they are actually using this attack on anything approaching a broad scale.

    15. Re:Take a note of who is doing the requesting by TanjaTheMoogle · · Score: 1

      What are you even talking about. A bunch of people that signed the editorial are academic cryptographers who work for universities. What big business are you talking about now?

      Universities, in general, do not fund themselves. I'm sure that "big business" has some influence on where research funds are allocated.

    16. Re:Take a note of who is doing the requesting by cryptizard · · Score: 1

      Not really. The huge majority of research funding comes from the government (NSF, DoD, DARPA, NIH, DoE, etc.)

    17. Re: Take a note of who is doing the requesting by Anonymous Coward · · Score: 0

      In your defense though, I wouldn't call you a crackpot. Hawking can't even prove his own theories so I wouldn't hold that against you either.

    18. Re:Take a note of who is doing the requesting by BarbaraHudson · · Score: 1

      Seriously? You are so wrong it's not a joke. "If only one person realizes that an email is a phishing scam, it would break the whole thing wide open." "If only one person realized that a major news site hosted malware, it would break the whole thing wide open." "If only one person realized the app they downloaded was malware, it would break the whole thing wide open." "If only one person realized that Microsoft was forcing unwanted upgrades on them it would break the whole thing wide open." (It took millions ...)

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
    19. Re:Take a note of who is doing the requesting by Anonymous Coward · · Score: 0

      At the very least this meant for me that I would want to see why Bruce considers it a non-issue.

      He's not going to disclose the 'consultant fee' he got from Zuck... erm, I mean from an independent non-profit organization.

    20. Re:Take a note of who is doing the requesting by Anonymous Coward · · Score: 0

      > At the very least this meant for me that I would want to see why Bruce considers it a non-issue.

      So, I trust that you did a little digging and came across and read

      https://whispersystems.org/blog/there-is-no-whatsapp-backdoor/

      yes?

    21. Re:Take a note of who is doing the requesting by TanjaTheMoogle · · Score: 1

      Duly noted. But do you believe that big business has nothing to do with those organizations? No influence on those organizations?

      I'm not trying to flame or start a big argument, but I'm just curious.

    22. Re:Take a note of who is doing the requesting by cryptizard · · Score: 1

      Having a lot of personal experience with the NSF, I can confidently say no. Businesses have nothing to do with the NSF. All the leadership are academics, all the grants go to academic institutions, and almost all of the money comes directly from the federal government. At no point are any business interests substantially involved.

  2. Link to actual letter by Anonymous Coward · · Score: 5, Insightful

    http://technosociology.org/?page_id=1687

    Rather than recursive links to other slashdot articles on the subject

    1. Re:Link to actual letter by Anonymous Coward · · Score: 0

      Thanks mate, much obliged.

    2. Re:Link to actual letter by lamber45 · · Score: 1

      Looks like the link to the original report (not in the Guardian article, but posted a couple times in the comments) might be Slashdotted. I found an archived copy at Internet Archive. It was posted last April and updated last May.

  3. Retracting the Truth by Anonymous Coward · · Score: 3, Insightful

    Why the heck would they retract the truth?
    If your threat model includes government spying, WhatsApp is not secure since the government can force WhatsApp to reissue your key and then scoop us the resulting messages.
    The editorial spin on this story from slashdot is very disappointing.

    1. Re:Retracting the Truth by ledow · · Score: 1

      If WhatsApp want to sniff your messages, they can. They update the app to just not encrypt.

      If government forces them to do that, they can.

      In and of itself, that's an entirely different threat model.

      What this says is not "WhatsApp is 100% secure to use" (because security experts are not stupid enough to ever say that).

      They are saying "This compromise that you claim lets anyone open your encrypted messages? Yeah, it's rubbish unless you literally take over WhatsApp servers."

      There is no service in the world that cannot be subject to government interference, and no software in the world that cannot be subject to the software authors themselves putting in a backdoor.

      At best, you can try and shut down if you're asked to do so, and hope that trusted companies are covering your back.

    2. Re:Retracting the Truth by chispito · · Score: 2

      Why the heck would they retract the truth? If your threat model includes government spying, WhatsApp is not secure since the government can force WhatsApp to reissue your key and then scoop us the resulting messages. The editorial spin on this story from slashdot is very disappointing.

      There is no back door. The security issue that stemmed all of this is that whatsapp will deliver messages that were sent while a user moves from one device to another. So, if I send it to you while your phone is busted and you reinstall on a new phone, you get the messages. The recepient key changes, and the sender is notified of this.

      The security angle is that with SMS verification you could intentionally intercept someone else's messages. Well, message (singular) because as stated, it notifies the sender of a key change.

      --
      The Daddy casts sleep on the Baby. The Baby resists!
    3. Re:Retracting the Truth by arth1 · · Score: 2

      There is no back door. The security issue that stemmed all of this is that whatsapp will deliver messages that were sent while a user moves from one device to another. So, if I send it to you while your phone is busted and you reinstall on a new phone, you get the messages. The recepient key changes, and the sender is notified of this.

      The problem, if I understand this correctly, is that the sender is notified after the message has been recrypted and sent to the recipient.
      If it alerted and required an accept before the message was sent to the new key, I don't think anyone would have a problem with it.

    4. Re:Retracting the Truth by chispito · · Score: 1

      The problem, if I understand this correctly, is that the sender is notified after the message has been recrypted and sent to the recipient. If it alerted and required an accept before the message was sent to the new key, I don't think anyone would have a problem with it.

      But it is not a back door. It's a very limited channel to obtaining a few messages that requires you to have some way of verifying the account (SMS interception). If you are going to build a back door to something, this is about the worst way possible.

      --
      The Daddy casts sleep on the Baby. The Baby resists!
    5. Re:Retracting the Truth by LeonPierre · · Score: 1

      The point of the "compromise" is not to let "anyone" open your encrypted messages, it is exactly for letting WhatsApp (the people that already control their servers) open your encrypted messages.

      And while this design flaw is being touted as a convenience feature, there's no telling what other flaws can be used along with this one for additional exploitation.

      And warning the user of a possible compromise AFTER the message has been sent? Yea that's real good security right there.

      --
      "If it ain't broke, it doesn't have enough features yet"
    6. Re:Retracting the Truth by arth1 · · Score: 3, Informative

      I think back door is a completely wrong description, but I still think it is a security concern.
      If a notification that the recipient key has changed only occurs after delivering the message anyhow, it kind of defeats having key verification in the first place.

      It's like if your bank re-routes your money transfer to a different recipient account than what you initially specified, and notifies you after the fact, instead of asking you if it's okay before doing so.

    7. Re:Retracting the Truth by Anonymous Coward · · Score: 0

      Even that aside the security researches here are the cause, they themselves have mostly only got their names so well known because they made such a fuss about finding completely impossible to exploit in the real world vulnerabilities and make sure their names were in the press over them.

      If they're not happy that The Guardian has publicised an actual vulnerability but one that is hard to exploit in the real world then they only have themselves to blame as they set that fucking bar in the first place. Without it we wouldn't know who most these people even are because it was the entire basis of them building their careers.

      What they're basically saying is "We have a monopoly on getting attention for ourselves with impossible to exploit in the real world vulnerabilities, how dare you steal one from us!".

      This is sour grapes and nothing more.

    8. Re:Retracting the Truth by squiggleslash · · Score: 1

      They're saying that technically accurate or not, the article is misleading and doesn't give context. In particular, this supposed threat is almost impossible to exploit in practice, as it requires the attacker:

      1. Knows exactly when you're going to swap a SIM card over or otherwise change phones
      2. Also knows you simultaneously have a bunch of messages waiting to be sent, that the attacker actually cares about.
      3. Also knows that you have gone into settings, and unchecked a setting that would normally be checked that warns you if a change in encryption keys has occurred
      4. Has access to all the infrastructure in the middle.

      That's a tall order. It'd be easier to just steal your phone, or hit you on the head with a blunt instrument XKCD style until you talk.

      The letter also points out that the article discourages people from using a popular messaging platform over this issue whose security is generally first rate, encouraging them to seek alternatives that either may be insecure, or may be taken as a sign of guilt (eg Signal), making it easier to pinpoint dissidents with something to hide.

      So, yeah, the article may be technically correct, the best kind of correct, but if it leaves people with a false impression, then it's probably right to withdraw it.

      --
      You are not alone. This is not normal. None of this is normal.
    9. Re: Retracting the Truth by fubarrr · · Score: 1

      No

      1. if you did 4, you dont need to do 1 at all

      2. if you did 4, you dont need to do 1 at all

      3. if you did 4, you dont need to do 1 at all

      4. if you did 4, you dont need to do 1,2,3

    10. Re: Retracting the Truth by squiggleslash · · Score: 1

      Without 1, 2, or 3, you have problems bypassing the peer to peer encryption, so yes, you need 1, 2, and 3, for 4.

      --
      You are not alone. This is not normal. None of this is normal.
  4. Mr. Potato Head... Mr Potato Head!!! by Anonymous Coward · · Score: 0

    Back doors are NOT SECRETS!!!

  5. Remember by GeekWithAKnife · · Score: 4, Insightful


    WhatsApp is big money...and combined with the fact it's hard to prove that a vulnerability was intentional and thus a "back door" it's hard for Joe Average to tell who's right.

    Don't worry about this stuff. Just keep using WhatsApp. It's just as secure as everything else, honest.

    Telling people not to use WhatsApp is apparently "endangering people"...as it is a "crucial issue".

    Summary; do not use Signal, ChatSecure, OTR or Telegram. Use WhatsApp, it's clearly safer #because_danger (??).


    Personally I never thought WhatsApp was secure even after this (maybe backdoor-ed) end to end encryption - Consider many people use WhatsApp? it's the number one target IM. If it ever was secure it won't be so tomorrow.

    --
    A 'singular oddity' is an event that cannot be explained and only happens when you are alone.
    1. Re:Remember by darkmeridian · · Score: 1

      Why would I use Telegram if I were concerned about security? It has a closed-source, roll your own crypto system. WhatsApp and Signal use OpenWhisper.

      Anyway, WhatsApp might have security vulnerabilities or backdoors but the reported "backdoor" isn't a backdoor. It's a design choice, and there is an option for security-conscious people to see when a new crypto key is generated.

      --
      A NYC lawyer blogs. http://www.chuangblog.com/
    2. Re:Remember by Agripa · · Score: 1

      Telling people not to use WhatsApp is apparently "endangering people"...as it is a "crucial issue".

      I do not know if it is happening here but there is actually precedent for security agencies doing this. The next best thing to compromising a secure system is to make the users believe that you have so they change to something less secure.

  6. Comment removed by account_deleted · · Score: 3, Interesting

    Comment removed based on user account deletion

  7. No time by Nidi62 · · Score: 2

    In these days of 24 hour news cycles and online publication, journalists and editors don't have time to do basic things like fact check with experts or even spell/grammar check. With no print deadlines they can throw up anything online at any time and easily edit it later, and preferably give it a nice clickbait title. It's the race to be first that journalism has always had but taken to an extreme combined with the fact that many journalists don't have the background or interest in the field the topic they are writing on is in.

    --
    The only thing necessary for evil to triumph is for it to be pitted against a slightly greater evil
    1. Re:No time by CaptainDork · · Score: 1

      I agree with your assessment but would suggest you remove the words, "journalists."

      There aren't any.

      That shit died when advertisers, CEOs and shareholders grabbed "news" by the fucking balls.

      --
      It little behooves the best of us to comment on the rest of us.
  8. So it is not a BUG, but a Feature by Anonymous Coward · · Score: 0

    APPS on phones are a treat to all. EULA makes it worst.

  9. Ugh, the vaccine metaphor. We hates it. by Anonymous Coward · · Score: 0

    The issue with the vaccine metaphor is that there is an element of truth to the anti-vax argument and people hold onto the spectre of it because they distrust the reporting around the issue, pointing to past failures in medicine, food, consumer product disclosures, etc. Yes, some people are killed by vaccines. Some kids are crippled. Bad things do indeed happen on occasion, and the rarity of these things IS sometimes in question. Anyone with a brain can look at the extremely remote chance of a bad outcome and still select for the greater good, but that doesn't fully eradicate the underlying issue : distrust based on conjunctiva and history.

    In the case of whatsapp it's irresponsible reporting to use the term 'backdoor' regardless of the chance of compromise using the vector. So really the underlying issue is non-technical reporting on a technical concern, which again can serve to lower trust and fuel speculative paranoia. That's not to say all paranoia is wrong, because MANY apps DO contain backdoors or dubious security that amounts to it. Certainly that doesn't seem to be the case here, though. How journalists categorize and present information is a greater responsibility than a reader's to understand technical issues, statistical risk, etc, obviously.

  10. Re:Why? "Signal not an option for many people"... by Anonymous Coward · · Score: 0

    it's not an option for google and facebook to keep control of your messages

  11. Re:Why? "Signal not an option for many people"... by The-Ixian · · Score: 1

    I guess because it is .001% harder to use...

    I was going to say "because it isn't integrated into your FB contacts" but that might not be true... depending on how you sync your contacts.

    --
    My eyes reflect the stars and a smile lights up my face.
  12. hyperbole much? by dAzED1 · · Score: 1

    "Telling people to switch away from WhatsApp is very concretely endangering people." -- err, what?!? How in the world is that "concretely endangering people?!?"

    1. Re:hyperbole much? by cryptizard · · Score: 2

      Good question that can be immediately answered by reading the actual editorial.

  13. Exactamundo... by Anonymous Coward · · Score: 1

    I wonder how much WhatsApp paid for their fealty?

  14. Re:Why? "Signal not an option for many people"... by cryptizard · · Score: 3, Insightful

    Read the article. The people they are concerned about are journalists and activists in repressive countries who use WhatsApp because it provides encrypted messaging. If they switch to Signal, which almost no one uses, just being observed using it may be enough cause for the government to pick them up. If they are able to use WhatsApp, however, they are hiding among the millions of other people that use it for no special reason other than it is a good messaging app.

  15. Disagree.. I cry bs, its not a feature its a flaw. by Anonymous Coward · · Score: 0

    A hole in the ground is a hole, and may be dangerous upon face value whether or not its pointed out. IT still may b a danger.
    why is this different?
    A gun is dangerous in any hands for any task its designed for.
    Just because we are warned by this, educated by it and or bombarded by the bs, duz that make it any less dangerous?
    Things like whats-app cater to those millennials that just don't care. Placate, placate but fuck the time taken to research its legitimacy.
    Take for example, whats going on with the MJ dispensaries on the west coast. Some are hit because most chose not to look @ the bigger picture with regard to disaster recovery (millennials), and are thus placed into a difficult position due to the lack of forethought/hindsight..
    bottomline is,, If it's not local, produced from a secure org, and or it has to many unanswered questions about it's operations, is it really worth it?

  16. Re:Why? "Signal not an option for many people"... by Anonymous Coward · · Score: 0

    Signal stopped working on my android phone about 2 months ago, and they whom produce it, even after it was pointed out not installing, wil do nothing to fix it.
    or atleast have not since its breaking

  17. Re:Why? "Signal not an option for many people"... by sl3xd · · Score: 1

    The story may be different if Signal was a federated protocol with entirely decentralized servers (like email).

    However, it's not, and there's a single point of failure that can be blocked.

    WhatsApp became popular and widespread before many repressive governments realized what it could do, so they can't block it without widespread outcry.

    Not so with Signal, which is blocked, and therefore not an option.

    --
    -- Sometimes you have to turn the lights off in order to see.
  18. Re: Why? "Signal not an option for many people"... by Mr_Silver · · Score: 1

    What's the point of being on an Instant Message service if none of the people you actually want to message are on it?

    --
    Avantslash - View Slashdot cleanly on your mobile phone.
  19. This whole goddam article ... by CaptainDork · · Score: 1

    ... including the comment section, is like using a fucking elephant gun to kill a piss ant.

    --
    It little behooves the best of us to comment on the rest of us.
  20. Re:Why? "Signal not an option for many people"... by Xylantiel · · Score: 1

    The point is that if WhatsApp is not blocked and Signal is, using WhatsApp is better than other options. You say yourself that the single block-able route is not the difference, its that one is blocked and the other isn't. As for the article, I would say that if someone's life or freedom depends on whether WhatsApp is secure -- they better well understand how this vulnerability applies to them based on their specific usage pattern, not based on some generalization from a newspaper article.

  21. Re:Why? "Signal not an option for many people"... by Anonymous Coward · · Score: 0

    From the letter.

    Signal is well-designed. Many in the security community use and consistently recommend it. However, the very thing that makes Signal a recommendation for people at high risk—that it drops messages at any sign of hiccup—prevents a large number of ordinary people from adopting it. Our community has used Signal for a long time, and have been trying to convert people to it, but its inevitable delivery failures (some by design, to keep users safer, and some due to bandwidth or other issues) mean that we often cannot convince people to use it despite spending a lot of effort trying to convince them—even people who have a lot at stake.

    The reason people, including journalists and activists, use WhatsApp over Signal isn’t because people are flaky, but because in the real world, reliability, usability and a large user base are key to security. Activists and journalists communicate a lot with ordinary people, and need to be certain that their messages are communicated as reliably as possible, using the same system as their recipient will use–hence the advantage of WhatsApp with its huge user base.

  22. Did Schneier really put his name to this? by Aaron+B+Lingwood · · Score: 1
    From Schneier:

    How serious this is depends on your threat model. If you are worried about the US government -- or any other government that can pressure Facebook -- snooping on your messages, then this is a small vulnerability. If not, then it's nothing to worry about.

    --
    [Rent This Space]
  23. Maybe the guardian article was alarmist but... by melting_clock · · Score: 1

    Educating the public to privacy and security issues is a worthwhile exercise. Maybe it isn't a backdoor but people seem to be increasingly concerned when it is suggested that their messages can be intercepted and read by third parties. This can only be a good thing. Our privacy has been eroded by several large corporations and a weird fascination with social media. Several companies want access to all of our data but the number of high profile breaches illustrate a significant risk in trusting others with anything particularly sensitive.

    If people want their messaging to be secure and private, they need to understand that end to end encryption is required and the standard for this method must be that it is not exploitable, through poor security implementation or backdoors. Sending commercially sensitive business information through an insecure communications method is just stupid and might not be legal in some circumstances. We also have our own sensitive financial or personal information that could be misused in the wrong hands. Getting people to Consider security and privacy issues a little more is a positive.

  24. Re:Why? "Signal not an option for many people"... by Anonymous Coward · · Score: 0

    Would you link to the bug report? Thanks in advance.

  25. Re:Why? "Signal not an option for many people"... by Anonymous Coward · · Score: 0

    > The story may be different if Signal was a federated protocol with entirely decentralized servers (like email).
    > However, it's not, and there's a single point of failure that can be blocked.

    You should read the "Censorship circumvention" section from this post from 2016-12-21: https://whispersystems.org/blog/doodles-stickers-censorship/

    Specifically:

    "With today's release, domain fronting is enabled for Signal users who have a phone number with a country code from Egypt or the UAE. When those users send a Signal message, it will look like a normal HTTPS request to www.google.com. To block Signal messages, these countries would also have to block all of google.com."

    I respectfully ask the "OMG, Google will use this to traffic analyze your cat to direct you to Google Branded Catfoods and advance their Sinister Plans!" hysterics to please move on to some other comment. You simply don't have a coherent threat model. :)

  26. Whatsapp vs. Signal by TheOuterLinux · · Score: 2

    Honestly, why would anyone use Facebook software and not be concerned? I think Mark Z is in trouble from all ends at the moment and is butt buddies with those he shouldn't be. They even said in the post to not incurage people to stop using Whatsapp because Signal isn't available to everyone. That right there should tell you if that's the best argument they can give to the average nontechnical person, that Signal should be the preferred choice anyway. If a country is blocking Signal then they are blocking Whatsapp and if they are blocking one and not the other, then it's compromised. That is just common sense. People don't like to hear it because there is a difference between a privacy advocate and the paranoid, and I think the paranoid are reacting to the realization that their cool app doesn't work like they want. People should use Tox clients anyway. You get encrypted texting, calling, webcam, and file sharing. And there's no signup or phone number verification at all. It's available for all platforms like Windows, Mac, Linux, Android, and iOS. The client names aren't the same for all though, but the protocol or whatever is still Tox. https://www.ostechnix.com/tox-... TheOuterLinux.com

  27. Which is why... by dargaud · · Score: 1

    ...we need the ability to disable permissions right upon installation of the app. When android says the app requires wifi password, camera, SD card access, your firstborn, address book access and more, there should be a box next to the permission to disable right then. I know there are apps that allow you to do that, but you need to remember to run them afterwards, you need root, and you need to redo it in case of upgrade.

    --
    Non-Linux Penguins ?
  28. People? by Anonymous Coward · · Score: 0

    A public "back door" is still bad. People in the know use Signal, the shhwp, use the culls.

  29. The report is bullshit by allo · · Score: 1

    What WhatsApp does is reducing their E2E security to the security level of TLS. This means nobody can read the content except the server. With TLS, because its plaintext there, with WhatsApp because they can change the crypto keys and nobody cares (and most people do not even the the message).
    When you accept, that it's only transport security but not end-to-end anymore, you can use a lot more messengers, as most use TLS (i.e. because apple forces them to do).

  30. Retraction? by Anonymous Coward · · Score: 0

    Guardian, do not retract your story. These people are not trustworthy, and neither is Slashdot management. The description they use on the likelihood of the backdoor of being used is dishonest. The US government will use any backdoor possible, as they have completely abandoned their responsibility to protect their own constitution.

  31. The Schneier group in a nutshell: by BitterKraut · · Score: 1

    "WhatsApp has enough security for those who don't need any."

  32. Dear Security Researchers. by Godwin+O'Hitler · · Score: 1

    Yeah, sure. I can’t for the life of me understand who could get worried about this.

    --
    No, your children are not the special ones. Nor are your pets.