Last week,The Guardianpublished a bombshell "exclusive" report claiming to reveal disturbing information about a "backdoor" into WhatsApp's encrypted messaging platform. According to the story, the vulnerability could potentially expose the service's user base of over a billion to "snooping" by prying eyes.
SEE ALSO:Sad! Trump reportedly forced to give up the phone he tweets withThe article was met with near-immediate backlash from information security experts and cryptologists, who took to Twitter to voice their complaints. Many alleged the article misrepresented a feature of the encryption WhatsApp's parent company, Facebook, called "expected behavior."
Statements from WhatsApp and Open Whisper Systems, the development team behind WhatsApp's encryption, decried the story as well, calling it "false" and "disappointing."
Now, many of those critical voices are calling for action. An open letter signed by 40 security experts requests that The Guardianretract the story, issue an apology and make efforts to ensure that similar reports won't be filed in the future without proper due diligence.
Secure communication is crucial. Plea from cryptographers & researchers on Guardian's irresponsible WhatsApp piece: https://t.co/4r2QAuByrf pic.twitter.com/YB0Y2PrPzj
— Zeynep Tufekci (@zeynep) January 20, 2017
The letter addressed to the "GuardianEditors" was written by sociologist Zeynep Tufekci, who characterizes the report as being "the equivalent of putting 'VACCINES KILL PEOPLE' in a blaring headline over a poorly contextualized piece."
She later claims the story has already led to real-world ramifications, citing reports of the Turkish media labeling WhatsApp as unsafe, prompting concerned users to move their vulnerable communications to "services that are strictly less secure than WhatsApp."
"People’s lives and safety are at stake," she writes.
Thanks to Guardian's irresponsible & baseless WhatsApp reporting, I'm flooded w reports of vulnerable folk switching to less secure options.
— Zeynep Tufekci (@zeynep) January 16, 2017
According to Tufekci, the problem here isn't just the tone of The Guardian's story — the information contained within is either willfully or unintentionally misleading its audience.
"The behavior described in your article is not a backdoor in WhatsApp [emphasis hers]," she writes, claiming that her position holds the "overwhelming consensus of the cryptography and security community."
The Guardian's article cites findings from UC Berkley doctorate student Tobias Boelter. He claims that WhatsApp's vulnerability stems from its end-to-end encryption's handling of messages sent to offline users in the event of a change of phone or SIM card. Rather than requiring its users to reconfirm their security keys in order for the message to be received, WhatsApp sends along the undelivered message automatically, informing the recipient afterward that the security key changed.
He (and then The Guardian) compared that system to another secure messaging app, Signal, which is held by many to be the gold standard for end-to-end encryption. Rather than letting the messages through, Signal blocks them until the keys can be reconfirmed.
That said, Signal and WhatsApp's end-to-end encryptions use the same protocol from Open Whisper Systems — this is the only way their systems differ.
And according to Tufecki, this isn't a "backdoor" — it's a means to increase reliability for WhatsApp users, who often have different priorities than those depending on Signal. "The very thing that makes Signal a recommendation for people at high risk — that it drops messages at any sign of hiccup — prevents a large number of ordinary people from adopting it," she writes.
She calls Boelter "a single well-meaning graduate student," whose inexperience and enthusiasm at finding a potential issue with one of the world's most popular app's security likely led him to "overestimate the practical impact" of the vulnerability.
Rather than holding him responsible, she criticizes The Guardianfor its lack of due diligence in confirming Boelter's findings with other experts (both WhatsApp and Open Whisper Systems claimed they were not contacted before the article was published) and calls for the publication, which she still says she harbors "great respect for," to retract the story.
When reached for comment by Mashable, a Guardianspokesperson provided us with this statement:
"We ran a series of articles highlighting and discussing a verified vulnerability in WhatsApp and its potential implications. WhatsApp was approached prior to publication and we included its response in the story, as well as a follow up comment which was received post-publication. While we stand by our reporting we have amended the article's use of the term 'backdoor' in line with the response and footnoted the articles to acknowledge this. We are aware of Zeynep Tufekci's open letter and have offered her the chance to write a response for the Guardian. This offer remains open and we continue to welcome debate."
We were unable to reach Tufecki for comment, but a recent Tweet makes her position on The Guardian's offer to write a response clear:
My writing a piece for the Guardian is not the answer. Guardian needs to retract, explain, learn from. https://t.co/RrK6IZ1PMB
— Zeynep Tufekci (@zeynep) January 20, 2017
With interest in secure messaging high in today's turbulent political climate, it's important for users to educate themselves on the systems they trust with their most vulnerable information. While the response to The Guardian's report from the security community was strong and swift, the potential vulnerability to WhatsApp still exists, even if it is tiny. To help decide if WhatsApp's system works for you, we suggest reading more about it in the Electronic Frontier Foundation's report on the topic.
TopicsCybersecurityWhatsApp
(责任编辑:時尚)
More than half of women in advertising have faced sexual harassment, report says
If you are a woman in advertising, chances are you've faced workplace sexual harassment at one point
...[详细]
為了生存
,我們每天都要好好奮鬥。而奮鬥的前提則是要有一個好的身體,而好的身體則是需要營養來維持的。那這營養從何而來呢
?當然是飲食。所以 ,就從現在起,請跟著小編仔細學一下超萌貓爪小蛋糕這道菜的做法,相信
...[详细]
隨著時代的發展 ,我們身邊可能沒有幾個會做菜的。大家一起吃大排檔,外賣。這沒有什麽不對
,但是外麵的食品不一定就很幹淨
,有時候自己動手做一下飯菜不僅可以品味美食 ,還能收獲健康,下麵小編就給大家介紹炒土豆胡
...[详细]
身體健康的人,都是十分會“吃”的人 。這就是告訴我們自己要學會做菜,下麵小編就給大家簡單的介紹地瓜餡糯米煎粑,看完後希望大家嚐試做一下。1.地瓜二個 。2.去皮。3.蒸熟。4.蒸好的地瓜掏成地瓜泥
。放點糖
...[详细]Slack goes down again, prompting anxiety everywhere
Panic briefly took over on Tuesday when everyone's favorite messaging app/millstone went down tempor
...[详细]
十一長假已經進入了倒計時階段,塵封已久的你,想必已經計劃好外出遊玩了吧
。外出遊玩,你必然嚐到當地的美食。不過如果你水土不服,肯定很難受吧 。所以 ,你最好還是在家做好吃的帶出去。下麵 ,就讓我來給你介紹一下
...[详细]
從小到大衣食住行被父母包辦的你 ,現在混進社會了
,還能夠單獨做點什麽事呢
?尤其是吃飯,你能夠自己解決嗎?或許你可以天天在外麵吃,但是這種行為不但浪費金錢,而且還毀健康。所以 ,年紀輕輕的你應該學會自己做飯
...[详细]
想要做好這道佳肴 ,需要你在做菜之前都會把菜和所需要的東西準備好 ,下麵我們給大家介紹沙茶羊肉空心菜的做法,看完以後自己一定要嚐試一下啊。1.1準備一個碗 , 碗裏順序放入清水 , 冰塊 , 羊肉 , 稍
...[详细]Olympian celebrates by ordering an intimidating amount of McDonald's
It's no secret that Olympians have to eat clean for years to ensure they're at peak physical conditi
...[详细]
我們很多時候都想學習做飯,但是又不知道如何學習。小編在這裏給大家介紹一下學習方法和心得 ,其實自己首先要開始動手做一道菜,下麵介紹家常絲瓜炒雞蛋的做法,先自己動手嚐試做一下。1.棱絲瓜去棱去皮,洗淨切片
...[详细]