WhatsApp Launches End-To-End Encryption - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
Mobile // Mobile Applications
News
4/6/2016
09:06 AM
Connect Directly
LinkedIn
Twitter
RSS
E-Mail
50%
50%

WhatsApp Launches End-To-End Encryption

Facebook's popular messaging client WhatsApp has enabled encryption by default for its 1 billion users.

Tesla Model 3, BMW i3: 10 Electric Vehicles To Own
Tesla Model 3, BMW i3: 10 Electric Vehicles To Own
(Click image for larger view and slideshow.)

As encryption sees broader deployment, the US government's struggle to maintain access to electronic communication lapsed unexpectedly last month when the FBI found a way to access the encrypted iPhone of one of the San Bernardino shooters.

That breakthrough, believed to be a vulnerability identified by a third party, prompted the Justice Department to abandon its legal effort to force Apple to create a modified version of iOS that would undo the company's security measures.

While it appears that the exploit provided to the FBI will allow the agency to access at least a few protected iPhones that have stymied investigations in various states, the tension between authorities and those offering privacy technology will only become more acute.

Sometime this week, Senators Richard Burr (R-N.C.) and Diane Feinstein (D-Calif.) are expected to release a draft of a bill that seeks to limit encryption.

But Facebook's WhatsApp, which is in use by 1 billion people, isn't waiting. The messaging service on Tuesday said it has enabled end-to-end encryption for messages and files sent through the service. Users of the most current version of WhatsApp Messenger on supported platforms -- Android, BlackBerry, iPhone, Nokia, and Windows Phone -- will be protected automatically. And WhatsApp, like Apple, will not have access to the keys necessary to decrypt its users' messages.

(Image: bombuscreative/iStockphoto)

(Image: bombuscreative/iStockphoto)

"From now on when you and your contacts use the latest version of the app, every call you make, and every message, photo, video, file, and voice message you send, is end-to-end encrypted by default, including group chats," company co-founders Brian Acton and Jan Koum said in a blog post.

The pair acknowledge the legitimate work of law enforcement to keep people safe, but note that "efforts to weaken encryption risk exposing people's information to abuse from cybercriminals, hackers, and rogue states."

Given the FBI's worries about being left in the dark by encryption, it's somewhat ironic that funding to develop the Signal Protocol came from the government-backed Open Technology Fund, as Christopher Soghoian, principal technologist at the ACLU, noted on Twitter.

WhatsApp's embrace of encryption was more than a year in the making. In November 2014, WhatsApp and secure communications firm Open Whisper Systems announced their intent to work together to integrate Open Whisper Systems' open source Signal Protocol (formerly TextSecure) encryption into WhatsApp. At the time, WhatsApp had some encryption support in its Android client.

WhatsApp is far from the first chat app to implement encryption. Apple's iMessage and FaceTime, Signal, Telegram, and Wickr are among the better known apps for secure communications.

Are you prepared for a new world of enterprise mobility? Attend the Wireless & Mobility Track at Interop Las Vegas, May 2-6. Register now!

Encryption should not be confused with a guarantee of security. It's one security feature among many that may not be adequately implemented. Apple's iMessage protocol, for example, is said to be "cryptographically broken," according to cryprographer Ian Miers. 

WhatsApp may have its own deficiencies. Like some other popular secure messaging apps, it's not open source, which means its code can't be independently verified. Signal, which is open source, scores better than WhatsApp on the Electronic Frontier Foundation's Secure Messaging Scorecard. However, WhatsApp's integration of the Signal Protocol should improve its standing.

What makes WhatsApp's embrace of strong encryption noteworthy is its scale. Apple has sold over 821 million iPhones, not all of which are still in use. WhatsApp is used by over a billion monthly active users around the world, people who now have privacy by default.

Thomas Claburn has been writing about business and technology since 1996, for publications such as New Architect, PC Computing, InformationWeek, Salon, Wired, and Ziff Davis Smart Business. Before that, he worked in film and television, having earned a not particularly useful ... View Full Bio

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
SaneIT
50%
50%
SaneIT,
User Rank: Ninja
4/8/2016 | 8:25:49 AM
WhatsApp encryption
As the saying goes, locks keep honest people out.  I understand the draw toward encrypting communication.  I don't think anyone wants all of their conversations wide open for the world to see but on the other hand believing that anything is cryptographically safe is a bit short sighted.  This will help in preventing your conversations being snooped on in a lazy manner and may save you from a broader attack but if you're being targeted for surveillance or someone is actively spying on you for those doing it legally this is a small road block.  For those doing it not so legally it might make them move on to the next target but it doesn't leave your conversations totally secure.
jastroff
50%
50%
jastroff,
User Rank: Ninja
4/12/2016 | 10:13:50 AM
Re: WhatsApp encryption
@SaneIT  - very interesting point, and places the technology in the larger context of security and privacy

>> that anything is cryptographically safe is a bit short sighted.  This will help in preventing your conversations being snooped on in a lazy manner 
SaneIT
50%
50%
SaneIT,
User Rank: Ninja
4/13/2016 | 10:29:50 AM
Re: WhatsApp encryption
I've seen twice in the past week that there are plans to "weaken" encryption through polices that the keys be given to law enforcement, that alone means you're not invisible even if the encryption is end to end.  I'm not at all saying that encryption is a lost cause, I think that most communication should be encrypted as a method of removing low hanging fruit but if someone really wants to know your business you need a more comprehensive plan to keep prying eyes out.
News
How to Create a Successful AI Program
Jessica Davis, Senior Editor, Enterprise Apps,  10/14/2020
News
Think Like a Chief Innovation Officer and Get Work Done
Joao-Pierre S. Ruth, Senior Writer,  10/13/2020
Slideshows
10 Trends Accelerating Edge Computing
Cynthia Harvey, Freelance Journalist, InformationWeek,  10/8/2020
White Papers
Register for InformationWeek Newsletters
Video
Current Issue
[Special Report] Edge Computing: An IT Platform for the New Enterprise
Edge computing is poised to make a major splash within the next generation of corporate IT architectures. Here's what you need to know!
Slideshows
Flash Poll