Tired of ads? Enjoy an ad-free experience by signing up.
Terence Lee · · 5 min read

Whatsapp’s end-to-end encryption is flawed, but others should follow its lead

4813392151_410cf9a73b_b

I’ll say it: Whatsapp’s addition of end-to-end encryption is a big effing deal. The move puts top-notch security into the hands of some 600 million users, at essentially zero cost and friction for consumers. It protects users from snooping by governments, internet service providers, and hackers. It sets a precedent for other internet companies and competitors, encouraging them to adopt similar technologies.

But let’s call a spade a spade and take a moment to talk about what this development isn’t. Andy Greenberg of Wired eloquently explained why the integration between the Textsecure encryption technology and the world’s most popular chat app matters. But for him to call Textsecure “practically uncrackable” is highly irresponsible.

Textsecure has many things going for it. It is open source, which means the developer community can examine its source code to find loopholes. While Apple’s iMessage features encryption as well, there’s no telling what backdoor may be present to get around the security features.

Textsecure also has something called “forward secrecy,” which means it changes your personal encryption key every time you start a new chat session. iMessage doesn’t do that, and the implications are severe: if hackers get access to your encryption key, they can steal your entire chat history. Finally, Textsecure stores the encryption keys on your device, and in theory this means Whatsapp has no way of knowing the content of your messages.

Chink in the armor

And yet researchers have identified in a paper a vulnerability called an Unknown Key-Share attack. In essence, a hacker can pretend to be the person you’re talking to, since Textsecure has no way of authenticating the identity of the other party. Even the solution proposed by the researchers may not work, especially in the event the device itself is compromised by malware, which could also defeat Textsecure’s forward secrecy feature.

“The solution proposed by the authors — displaying of an out-of-band QR code to help validate the identity and keys — can be similarly compromised by mobile malware to spoof a fake QR code, if the mobile application is not properly protected,” says Joseph Gan, CTO and co-founder of Singapore mobile security firm V-Key (disclosure: V-Key’s main product is a service that protects apps and its data even in the event a device is hacked into).

He adds: “Mobile malwares are not ‘one-time’ attacks but almost always fall into the category of advanced persistent threats; hackers that gain access to the mobile device will not only gain access to the current keys, but will also be able to maintain their access in order to access to future keys and messages.”

And while the Textsecure codebase may be open for all to scrutinize, users are essentially putting their trust in Whatsapp and Facebook to implement the software properly and not introduce loopholes, be it deliberately or by accident.

Still progress

This chart by EFF shows how hacker-proof each chat app is.

This chart by EFF shows how hacker-proof each chat app is.

But despite these weaknesses, the Textsecure integration is a boon for user privacy. According to an Electronic Frontier Foundation chart, a lot of popular messaging apps like Google Hangouts, Kik, Secret, and QQ don’t even encrypt transmitted messages. This means entire chats occurring over a public wifi network can be snooped on. Even Whatsapp did not value your privacy until recently – it only introduced basic encryption at the end of 2012, and an easily crackable one at that.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

TIA Writer

Terence Lee

I like analyzing and digging into the real goings-on in the tech industry. Holds these crypto: BTC, Eth, Matic