@fedora

Страница 291 из 2988
Lesik
07.11.2016
22:31:55
Not on by default afaik
WhatsApp has encryption that you can't even be sure it exists. If we assume the worst case, surely non-default, proven encryption is better than no encryption at all.

Corentin
07.11.2016
22:32:04
Kohane
07.11.2016
22:32:26
Ugh, stop being so delusional.
Yes, I will throw more wood to the fire. Now my question is... How do you know that WhatsApp really encrypt messages? And who has the key to that encryption?

Google
Vitaly
07.11.2016
22:32:59
GPG is PITA to use for a casual user, sadly.
Install Mozilla Thunderbird and Enigmail extension.

Corentin
07.11.2016
22:33:23
Lesik
07.11.2016
22:33:40
Yes, I will throw more wood to the fire. Now my question is... How do you know that WhatsApp really encrypt messages? And who has the key to that encryption?
Is it a rhetorical question? Nobody can prove that WhatsApp's encryption is safe, because the code isn't available. The keys to the messages are, supposedly, on your phone only.

Install Mozilla Thunderbird and Enigmail extension.
Even with Enigmail it's too complicated for the average Joe.

Michał
07.11.2016
22:34:08
Install Mozilla Thunderbird and Enigmail extension.
I know about it, but try to explain to a random teenager how to use it, IMHO most of them will blindly accept any private keys, making MITM attacks trivial, therefore GPG would be essentially a waste of time for them

Dani~
07.11.2016
22:34:41
Lmao
Just wiped phone, reinstall whatsapp, no backup on cloud neither on phone, conversations are still there

Corentin
07.11.2016
22:34:46
Tldr

https://twitter.com/snowden/status/778592275144314884

Dani~
07.11.2016
22:35:10
So, I think, I've got some reason to be a bit paranoid lol

Lesik
07.11.2016
22:35:21
https://twitter.com/snowden/status/778592275144314884
Blindly following a celebrity's suggestions is never good. Think for yourself.

Google
Dani~
07.11.2016
22:35:27
Yeah, I double checked and double wiped

Lesik
07.11.2016
22:35:27
Same with Stallman.

Corentin
07.11.2016
22:35:29
Even if they stole your keys, they wouldn't be that stupid

(■_■¬)
07.11.2016
22:35:36
GPG is PITA to use for a casual user, sadly.
Now I'm almost sure you have never used encryption.

Michał
07.11.2016
22:35:37
IMHO if you actually need private conversation, you can use GPG over anything you want, but the other party needs to get some training about it as well

Corentin
07.11.2016
22:35:47
Lesik
07.11.2016
22:35:57
OK

Michał
07.11.2016
22:36:00
Now I'm almost sure you have never used encryption.
I did, but try to explain how to use it to a random person on the street.

Corentin
07.11.2016
22:36:03
They could upload your decrypted messages to Google Drive haha

I think Whatsapp is almost all good, except for the backup shit

Lesik
07.11.2016
22:37:06
They could upload your decrypted messages to Google Drive haha
Well you obviously have to trust your chat partner, this trust is always implied when we talk about security and encryption.

Corentin
07.11.2016
22:37:11
Here, you got one point

(■_■¬)
07.11.2016
22:37:21
I did, but try to explain how to use it to a random person on the street.
It is so easy! just some clicks here, some clicks there, that is.

Anxhelo
07.11.2016
22:37:24
Nothing is really 100% secure, there is always smth that can be done

Corentin
07.11.2016
22:37:45
Nothing is really 100% secure, there is always smth that can be done
Or something that can't be done and is just a human mistake

Michał
07.11.2016
22:38:13
It is so easy! just some clicks here, some clicks there, that is.
Yeah, but - as I've written earlier - explain to them why it's important to check that they need to ensure that public keys are authentic, or that they can't upload their private keys to Dropbox :D

Lesik
07.11.2016
22:38:17
Here, you got one point
Umm, as if the missing encryption isn't a point.

Google
Corentin
07.11.2016
22:39:05
Michał
07.11.2016
22:39:15
People do that? Upload their keys on Dropbox? ?
you've got a phone and a PC, and want to send emails from both of them, and there's this cool tool to synchronize your settings...

Anxhelo
07.11.2016
22:39:15
Dani~
07.11.2016
22:39:43
Michał
07.11.2016
22:39:44
so you see, there are a lot of pitfalls that we won't even think about

Corentin
07.11.2016
22:39:59
Worst: to Onedrive
Directly to nsa servers

Anxhelo
07.11.2016
22:41:06
Only on pc

Corentin
07.11.2016
22:41:59
Michał
07.11.2016
22:42:03
I use Dropbox only to sync items I get from creative market lol
That's you, now take a look at all those people who have no idea what encryption even is and are blindly clicking "Accept certificate" in case of https errors when they log to their bank account in Starbucks wifi

Kohane
07.11.2016
22:42:15
Dani~
07.11.2016
22:42:28
Anxhelo
07.11.2016
22:42:33
You're kidding, right?
So I have heard, don't know the real source

Lesik
07.11.2016
22:42:52
Don't they use signal's encryption algorithm?
Well, supposedly. There's no way you could check.

You're kidding, right?
No, it's true (supposedly).

Kohane
07.11.2016
22:43:23
Dani~
07.11.2016
22:43:30
One of our clients indeed have this panorama (please, don't laugh, nda stuff, what (?) ) Onedrive Folder: encrypted invoices with gpg gpg.priv gpg.pub password-of-gpg.txt

Anxhelo
07.11.2016
22:44:00
Dani~
07.11.2016
22:44:09
Nexus doesn't have sd lol

Google
Anxhelo
07.11.2016
22:44:18
Corentin
07.11.2016
22:44:20
Double check data partition

Dani~
07.11.2016
22:44:33
empty

i broked it my self xD

that was the reason of the wipe

Corentin
07.11.2016
22:44:48
Then do that again and then perform network analysis

Dani~
07.11.2016
22:44:51
cuz i fucked up the partition table

Corentin
07.11.2016
22:45:09
Because I assure you they don't do that

Admin
ERROR: S client not available

Corentin
07.11.2016
22:45:31
Unless you can prove they do

If you manage to prove it man you're rich

Kohane
07.11.2016
22:45:44
Well, supposedly. There's no way you could check.
The only "proof" of that encryption is a little notification saying "now messages are encrypted end to end". Nothing else. And given I never seen the keys, to me it's just marketing.

Anxhelo
07.11.2016
22:45:58
So they can target ads ?
Not on me, ublock origin + noscript

Corentin
07.11.2016
22:46:00
And signal team

Dani~
07.11.2016
22:46:08
If you manage to prove it man you're rich
are they offering money for this stuff or what?

Dani~
07.11.2016
22:46:23
I'll do this weekend if I've got enough time

android7 is giving me some... headache

Google
Corentin
07.11.2016
22:46:38
are they offering money for this stuff or what?
Just send "encryption in Whatsapp is bullshit and I can prove it" to vice motherboard

Dani~
07.11.2016
22:46:58
xDD

Corentin
07.11.2016
22:47:17
And there they have their best article of the year

Anxhelo
07.11.2016
22:47:29
android7 is giving me some... headache
Meanwhile, I'm here on kitkat 4.4.2 ?

Dani~
07.11.2016
22:49:26
Meanwhile, I'm here on kitkat 4.4.2 ?
I was going to say... "you don't lose nothing" but indeed, you lose a lot of stuff xDD

Lesik
07.11.2016
22:49:38
Both sides claim they worked together to implement Signal's encryption algorithm into WhatsApp. And while I personally kinda trust OpenWhisperSystems (the developers of Signal) not to lie about this, good security isn't based on trust but on proof. Besides, after the successful collaboration, Facebook could've just removed the secure encryption by OpenWhisperSystems or added some code to it so that a master Facebook key can decrypt all messages also. Don't forget that they (Facebook) can program too and it's easy for them to change everything OpenWhisperSystems implemented.

Sorry my phone died so I'm a little en retard on the topic.

Kohane
07.11.2016
22:50:31
And a white paper
White paper? What white paper? Where?

Anxhelo
07.11.2016
22:50:54
I was going to say... "you don't lose nothing" but indeed, you lose a lot of stuff xDD
I have tried to build 5 ROM-s for my phone, a Lenovo A916, starting from 5.1.1 to 6.0.1, everything worked apart from sim cards :( lenovo hasnt made the code public for me to fix anything

Kohane
07.11.2016
22:51:00
Corentin
07.11.2016
22:51:11
Just reinstalled Whatsapp

Lost all my history

Lesik
07.11.2016
22:51:17
Don't say that, sounds really odd.
"Phone died"? It's a common phrase.

Corentin
07.11.2016
22:51:54
And 1 message from a friend

Corentin
07.11.2016
22:52:11
"can't retrieve message at the moment. More infos"

With a link to this

Kohane
07.11.2016
22:52:28
Anxhelo
07.11.2016
22:52:28
fucked then
Yeah, can live with that :p

Lesik
07.11.2016
22:53:01
No. The retard part
I'm pretty sure "en retard" is a common saying too, do you guys not know it?

I say it often in "real life".

Страница 291 из 2988