[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y ] [Home]
4chanarchives logo
Is whatsapp really secure? Can we really be sure that this end
Images are sometimes not shown due to bandwidth/network limitations. Refreshing the page usually helps.

You are currently reading a thread in /g/ - Technology

Thread replies: 16
Thread images: 1
File: logo-promo.jpg (57 KB, 937x492) Image search: [Google]
logo-promo.jpg
57 KB, 937x492
Is whatsapp really secure? Can we really be sure that this end to end encryption guarantee us that goverment and whatsapp team won't be able to see conversations?
Or it's all just for PR and in fact it's a botnet?
>>
>>54389783
protip: the government doesn't care about monitoring you unless you are trying to kill people, or do highly, blatantly illegal shit
>>
>>54389783
If it's proprietary software, you can never be sure, full stop. You can hope your trust isn't abused.
>>
>>54389790
In here police does monitor you if you talk about drugs and stuff on phone.
I don't do much illegal things for now, but I knew people who get raided like that. Still I would rather keep myself and friends safe in case if I did more stuff in the future.
>>
>>54389837
Dealers in London advertise over whatsapp and all deals are made over whatsapp. No codes used, you call the drugs by their actual names. They've been doing it for a while and theyre still doing it.
>>
>>54389790
>>54389837
Actually this messenger thingies *collecting* your info, and in the future all of it can be used against you.
And they don't even need to spend man-hours to find something in big collection of logs, wordfilter or simple AI will do all the job.
Well, use it, if you sure, that government will never do anything unjust to you.
>>
>>54389981
Do you have any source about that?
Brazil just banned Whatsapp for few days because they couldn't provide them with chat logs of some drug dealers.
http://techcrunch.com/2016/05/02/brazil-orders-cell-phone-carriers-to-block-whatsapp-for-72-hours/?ncid=txtlnkusaolp00000595
>>
>>54389879
The prisons are full of drug dealers, I don't think the police are keen on arresting any more
>>
>>54389783
Just use Signla ya dingus.
>>
>>54389790
fuck off orweill, go read the xkeyscore leaks
>>
>>54389783
Closed source software running on a google OS.
So, Yes.
>>
>>54390308
I prefer Telegram.
>>
>>54389783
That verifiability is what makes Signal superior. It is a pity WhatsApp is closed-source. I have pointed that out to them in meetings, and they are well aware of that drawback.

However, decompiles do show that WhatsApp seems to be on the level. They have been working with Moxie and Trevor; their choice of the Axolotl (Signal) ratchet and Noise protocol shows that they seriously do know what they're doing and they gave a damn in getting it right (unlike Wickr, Telegram, Kix or any of the others). It is now truly end-to-end verifiable. I've talked to some of the engineers involved and they have very, very strong opinions about mass surveillance: I believe they would walk out the door if they were asked to install a back door.

I don't trust it as much as Signal, but I do believe that at the present moment, it is secure, and I commend them for rolling out end-to-end encryption to their millions of users who just have it, and don't need to care about it.

The next phase is metadata protection. That's a lot harder in a messenger, particularly a mobile messenger where you want to conserve battery and data usage but also want fairly low communication latency, but the adversary can read, correlate and manipulate all comms (please note: plain onion routing does NOT protect against that threat).

Research is still ongoing. I could probably do it for you today if 10000-15000ms was low enough latency for you. It's not low enough for a critical mass of users, I know that, so on we go to try to find something without the vulnerabilities of Cmix and also without needing to flood-fill. I'm currently focusing on (Fidonet-inspired) node-point routing architectures, where desktop full 'nodes' don't have quite the resource constraints of, and can help make up for, the mobile 'points': but we don't want to trust the upstream node(s).

We also need a blinded transport protocol: akr has a Noise variant which uses Elligator for the first ephemeral. I like that idea.
>>
>>54389790
protip the government can't find shit
>>
>>54389783
It's banned here in Brazil for 24h because they refused to give information to help a investigation kek
>>
Yes, it is probably secure, no, there is no (simple) way we can know for sure. If you want something more vetted, use Signal. It's open source, and it's what the crypto in Whatsapp is based on.
Thread replies: 16
Thread images: 1

banner
banner
[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y] [Home]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
If a post contains personal/copyrighted/illegal content you can contact me at [email protected] with that post and thread number and it will be removed as soon as possible.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com, send takedown notices to them.
This is a 4chan archive - all of the content originated from them. If you need IP information for a Poster - you need to contact them. This website shows only archived content.