The Guardian: WhatsApp backdoor allows snooping on encrypted messages

by Volker Weber

WhatsApp’s end-to-end encryption relies on the generation of unique security keys, using the acclaimed Signal protocol, developed by Open Whisper Systems, that are traded and verified between users to guarantee communications are secure and cannot be intercepted by a middleman. However, WhatsApp has the ability to force the generation of new encryption keys for offline users, unbeknown to the sender and recipient of the messages, and to make the sender re-encrypt messages with new keys and send them again for any messages that have not been marked as delivered.

I see this as a potential threat, but not an imminent one. Solution: install Signal.

More >

Update: Statements from WhatsApp (via respected dpa journalist @CDernbach and UC Berkeley researcher Tobias Boelter. Plus a video with Tobias' talk.

[Danke, Stephan]

Comments

And I am still not on the right track...

Hubert Stettner, 2017-01-13

Nun, ich kann das technisch nicht nachvollziehen. Aber in dem update steht:

Wir verschlüsseln zwar, behalten aber einen Zweitschlüssel.

Johannes Matzke, 2017-01-14

Interesting comment from Signal on this piece from The Guardian: https://whispersystems.org/blog/there-is-no-whatsapp-backdoor/

Willy Reuter, 2017-01-15

Ja, das hatten wir gestern: https://vowe.net/archives/016177.html

Volker Weber, 2017-01-15

Recent comments

Karl Heindel on Useful gestures for iPad Pro at 15:57
Volker Weber on Useful gestures for iPad Pro at 13:30
Robert Kurt on Useful gestures for iPad Pro at 13:28
Ingo Seifert on Useful gestures for iPad Pro at 10:00
Jochen Schug on Useful gestures for iPad Pro at 07:05
Oliver Stör on Useful gestures for iPad Pro at 23:31
Thomas Holzapfel on Ab morgen :: Surface Pro 6 und Surface Laptop 2 at 16:46
Volker Weber on Ab morgen :: Surface Pro 6 und Surface Laptop 2 at 15:07
Thomas Holzapfel on Ab morgen :: Surface Pro 6 und Surface Laptop 2 at 14:57
Volker Weber on Siri has completely replaced Alexa at 14:55
Volker Weber on Ab morgen :: Surface Pro 6 und Surface Laptop 2 at 14:47
Thomas Holzapfel on Ab morgen :: Surface Pro 6 und Surface Laptop 2 at 14:43
Volker Weber on Lass das Swipen und like das Leben at 09:43
Jens Arne Männig on Lass das Swipen und like das Leben at 09:37
Andreas Linde on Weitergehen. Keine Haufen bilden. at 09:13
Manfred Wiktorin on Lass das Swipen und like das Leben at 09:10
Ole Saalmann on Weitergehen. Keine Haufen bilden. at 08:31
Mariano Kamp on Weitergehen. Keine Haufen bilden. at 08:00
Volker Weber on Weitergehen. Keine Haufen bilden. at 07:43
Mariano Kamp on Weitergehen. Keine Haufen bilden. at 22:59
Jonas Rathert on Stream Spotify on Apple Watch at 22:46
Thomas Cloer on Siri has completely replaced Alexa at 16:49
Andreas Pfau on Siri has completely replaced Alexa at 13:02
Benno Christen on Weitergehen. Keine Haufen bilden. at 12:48
Oliver Stör on Weitergehen. Keine Haufen bilden. at 11:16

Ceci n'est pas un blog

I explain difficult concepts in simple ways. For free, and for money. Clue procurement and bullshit detection.

vowe

Contact
Publications
Stuff that works
Amazon Wish List
Frequently Asked Questions

rss feed  twitter  amazon

Local time is 18:19

visitors.gif

buy me coffee