Whatsapp’s end-to-end encryption is flawed, but others should follow its lead

I’ll say it: Whatsapp’s addition of end-to-end encryption is a big effing deal. The move puts top-notch security into the hands of some 600 million users, at essentially zero cost and friction for consumers. It protects users from snooping by governments, internet service providers, and hackers. It sets a precedent for other internet companies and competitors, encouraging them to adopt similar technologies.
But let’s call a spade a spade and take a moment to talk about what this development isn’t. Andy Greenberg of Wired eloquently explained why the integration between the Textsecure encryption technology and the world’s most popular chat app matters. But for him to call Textsecure “practically uncrackable” is highly irresponsible.
Textsecure has many things going for it. It is open source, which means the developer community can examine its source code to find loopholes. While Apple’s iMessage features encryption as well, there’s no telling what backdoor may be present to get around the security features.
Textsecure also has something called “forward secrecy,” which means it changes your personal encryption key every time you start a new chat session. iMessage doesn’t do that, and the implications are severe: if hackers get access to your encryption key, they can steal your entire chat history. Finally, Textsecure stores the encryption keys on your device, and in theory this means Whatsapp has no way of knowing the content of your messages.
Chink in the armor
And yet researchers have identified in a paper a vulnerability called an Unknown Key-Share attack. In essence, a hacker can pretend to be the person you’re talking to, since Textsecure has no way of authenticating the identity of the other party. Even the solution proposed by the researchers may not work, especially in the event the device itself is compromised by malware, which could also defeat Textsecure’s forward secrecy feature.
“The solution proposed by the authors — displaying of an out-of-band QR code to help validate the identity and keys — can be similarly compromised by mobile malware to spoof a fake QR code, if the mobile application is not properly protected,” says Joseph Gan, CTO and co-founder of Singapore mobile security firm V-Key (disclosure: V-Key’s main product is a service that protects apps and its data even in the event a device is hacked into).
He adds: “Mobile malwares are not ‘one-time’ attacks but almost always fall into the category of advanced persistent threats; hackers that gain access to the mobile device will not only gain access to the current keys, but will also be able to maintain their access in order to access to future keys and messages.”
And while the Textsecure codebase may be open for all to scrutinize, users are essentially putting their trust in Whatsapp and Facebook to implement the software properly and not introduce loopholes, be it deliberately or by accident.
Still progress

This chart by EFF shows how hacker-proof each chat app is.
But despite these weaknesses, the Textsecure integration is a boon for user privacy. According to an Electronic Frontier Foundation chart, a lot of popular messaging apps like Google Hangouts, Kik, Secret, and QQ don’t even encrypt transmitted messages. This means entire chats occurring over a public wifi network can be snooped on. Even Whatsapp did not value your privacy until recently – it only introduced basic encryption at the end of 2012, and an easily crackable one at that.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.







