时间:2025-10-20 00:59:51 来源:网络整理编辑:探索
Neither WhatsApp nor The Guardianare having a good day.The UK-based newspaper published a scathing e
Neither WhatsApp nor The Guardianare having a good day.
The UK-based newspaper published a scathing exclusive report early Friday morning, purporting to reveal disturbing news about the encryption used by WhatsApp's, the Facebook-owned messaging service. Almost as soon as the article went live, however, security experts took to the internet to publicly question the nature of its claims.
Late in the day Friday, Open Whisper Systems, the team behind the end-to-end encryption service used by WhatsApp and secure messaging client Signal, published a blog post in response to the article. The post refuted The Guardian's claims at length, expressing the team's disappointment with the way in which the news was reported.
SEE ALSO:Older smartphones get locked out of WhatsAppAccording to The Guardian's article, WhatsApp has a glaring security flaw in the manner its end-to-end encryption is set up, which creates a wide-open backdoor which "allows snooping" by Facebook — and, by extension, government agencies or others who might gain access to it by legitimate or nefarious means.
The Guardianstory reports that WhatsApp's encryption is vulnerable when a user sends a message to a contact who is offline. When that happens, the end-to-end encryption is, in a sense, broken, since one of the ends no longer exists. In that case, the service creates a new set of encryption keys for the offline user so the message can they can still get it when they come back online. (For a primer on encryption, check out this helpful video or view it at the bottom of this post.)
However, WhatsApp doesn't alert either the sender or the recipient about of the change, and the messages are caught in a kind of limbo in the meantime, the security of which is unclear -- at least until the recipient comes back online. According to the Guardian, this "effectively allows WhatsApp to intercept and read users’ messages."
By comparison, Signal doesn't automatically resend offline messages like WhatsApp does, theoretically making those messages more secure.
Information security experts were turned off by the article. Complaining on Twitter, they were critical ofThe Guardian's reporting. Frederic Jacobs, who actually worked on Signal with Open Whisper Systems, the service's developer, even added his voice to the discussion:
It's ridiculous that this is presented as a backdoor. If you don't verify keys, authenticity of keys is not guaranteed. Well known fact.
— Frederic Jacobs (@FredericJacobs) January 13, 2017
The Guardianreport cited UC Berkely PhD student Tobias Boelter as having discovered the backdoor and claimed to have an "exclusive" on his findings. But that's not quite true.
As reported, Boelter notified Facebook of the vulnerability back in April 2016. The company then called the issue "expected behavior," confirming the existence of the issue and admitting it to be a feature of the service instead of a "backdoor," telling him "...for now it's not something we're actively working on changing."
In addition to contacting Facebook, Boelter detailed his findings on the vulnerability in a blog post. It wasn't published on an outlet like The Guardian— but Boelter's reports on the subject have been online for the better part of a year.
When contacted by Mashablevia email, Boelter clarified his role in the report. "I gave a 5-minute lightning talk at 33c3 in Hamburg on December 30, 2016 and was contacted by a reporter working for the Guardian afterwards," he said.
Following the article's publication, Boelter posted on the topic once again, discussing the nature of the issue and admitting the different interpretation of what it represents to end users.
After reaching out to a WhatsApp spokesperson for comment, Mashablereceived this response:
The Guardianposted a story this morning claiming that an intentional design decision in WhatsApp that prevents people from losing millions of messages is a “backdoor” allowing governments to force WhatsApp to decrypt message streams. This claim is false [emphasis theirs].
WhatsApp does not give governments a “backdoor” into its systems and would fight any government request to create a backdoor. The design decision referenced in the Guardianstory prevents millions of messages from being lost, and WhatsApp offers people security notifications to alert them to potential security risks. WhatsApp published a technical white paper on its encryption design, and has been transparent about the government requests it receives, publishing data about those requests in the Facebook Government Requests Report.
Later in the day, co-founder of WhatsApp Brian Acton posted a direct response on Reddit, again calling the story "false" and emphatically stating, "WhatsApp would fight any government request to create a backdoor."
In WhatsApp's white paper describing the service, it explicitly states, "WhatsApp servers do not have access to the private keys of WhatsApp users, and WhatsApp users have the option to verify keys in order to ensure the integrity of their communication."
Whether or not this so-called "backdoor" is an issue or a feature depends on your interpretation. In any case, it's probably the best thing to happen to Signal lately.
TopicsCybersecurityWhatsApp
The five guys who climbed Australia's highest mountain, in swimwear2025-10-20 00:48
湖人 114:112 險勝凱爾特人 ,塔圖姆空砍 41 分 ,如何評價這場比賽 ?(庫裏空砍30分尼克斯勝勇士)2025-10-20 00:17
原創 四萬沒問題!除了詹姆斯,現役還有哪些球星能衝擊30000分 ?(詹姆斯沒投籃)2025-10-20 00:14
原創 籃網將歐文送至獨行俠 ,火箭卻成最大贏家 ,費蒂塔實在憋不住笑了(nba20212025-10-19 23:49
J.K. Rowling makes 'Harry Potter' joke about Olympics event2025-10-19 23:47
英超第20輪,熱刺VS阿森納 ,北倫敦德比戰主隊恐吃敗仗2025-10-19 23:31
贏下德比 !利物浦2023年聯賽首勝 ,這一幕,經典!2025-10-19 23:28
2023年印度羽毛球公開賽2025-10-19 22:58
Michael Phelps says goodbye to the pool with Olympic gold2025-10-19 22:57
湯神末節16分 !詹姆斯得分王 !湖人輸給了罰球…(勇士vs雄鹿庫裏得分)2025-10-19 22:25
Metallica to seek and destroy your eardrums with new album this fall2025-10-20 00:38
歐文不在,小托馬斯放開掄 !庫裏傷退,勇士贏球不足喜 !湖人輸球,老詹表態隻想贏 !(庫裏爆砍41分勇士逆轉雄鹿)2025-10-20 00:26
NBA最新實力榜!太陽蟬聯榜首 ,勇士第3,籃網下滑至17 ,湖人20(籃網時隔18年再登頂東部第一!最可怕的是這點)2025-10-20 00:23
英超最新積分榜!阿森納6分領跑 ,熱刺12025-10-20 00:14
You can now play 'Solitaire' and 'Tic2025-10-19 23:33
2023交易截止日複盤:杜歐來襲西部內卷 洛城雙雄瘋狂掃貨(2021年nba交易截止日交易匯總)2025-10-19 23:31
2/15周三精彩賽事 :8場足球賽事解析(多特VS切爾西 ,內附分數)2025-10-19 23:24
NBA官宣最新實力榜 :黑馬力壓籃網 ,勇士僅排13,湖人下滑7位(NBA官方戰力榜:籃網第一)2025-10-19 23:15
Cat gets stuck in the most awkward position ever2025-10-19 23:07
NBA官方實力榜:綠軍重回榜首籃網升至第6 勇士第18湖人第25(籃網戰勝勇士)2025-10-19 23:04