Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sure, but I think you might be missing an important aspect. The system is designed to not block communications upon key changes, just display an alert so the other user knows (And can verify out of band if they are about to discuss a sensitive topic). The initial "vulnerability" seemed to just be based on an opinion that it would be more secure if it did indeed block communications (until manual verification was performed) upon key changes.

You are correct that it is impractical to "exploit" the chosen design, I think the bigger issue their portrayal of this as a vulnerability rather than a security suggestion.



This is not the biggest flaw! It was that messages that are in flight (sent, but not yet delivered) still get delivered if the key changes. Only after delivery does the sender get notified of the key change. The last time, I gave example where a protest organizer (Bob) is detained by the (secret) police in the period leading up to a protest, and denied access to their password-protected phone that's switched off. All the police has to do is wait for a while, then pop the SIM into a new phone and presto, they get all the incriminating messages that were sent by co-conspirator Alice while Bob was detained. Only after delivery onto the police phone does Alice get notified that Bob's key has changed.


If I'm not mistaken, they called this a "flaw", not a "vulnerability", which definitely wouldn't have been correct. I personally would have preferred "trade-off" but I'm honestly not sure about the word "flaw".

My general point is, even if they made some technical errors as well, their consideration, I believe, was more about the consequences of their interpretation.


They called it a "backdoor", and reported it as a game-over vulnerability. Everything since then has been trying to walk the claim back.


> They called it a "backdoor", and reported it as a game-over vulnerability.

I didn't remember that and it seems to have been removed from the article (with a note on the end which I have missed). Well, that's just sensationalism and must have been picked up way earlier in a sane review process. I stand corrected.


"The original article – now amended and associated with the conclusions of this review – led to follow-up coverage, some of which sustained the wrong impression given at the outset. The most serious inaccuracy was a claim that WhatsApp had a “backdoor”, an intentional, secret way for third parties to read supposedly private messages. This claim was withdrawn within eight hours of initial publication online, but withdrawn incompletely. The story retained material predicated on the existence of a backdoor, including strongly expressed concerns about threats to freedom, betrayal of trust and benefits for governments which surveil. In effect, having dialled back the cause for alarm, the Guardian failed to dial back expressions of alarm."

From this linked article.


You can't separate the technical facts from the interpretation though, because they only brought it up to interpret it incorrectly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: