Erik van Straten<p><span class="h-card" translate="no"><a href="https://mastodon.nl/@ellent" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ellent</span></a></span> : wow, that's a lot of snake oil in the FB article that The Verge refers to.</p><p>*THE* problem with consumers losing access to their phone (stolen, forgotten in the subway, dropped in the toilet etc.) is typically that *ALL* secrets are gone - except a screen unlock code, while *possibly* the user may remember the password of their iCloud or Google account (or may have access to a rescue code).</p><p>B.t.w., passkey synchronisation suffers from the same problem: asking people to remember one or more additional *strong* passwords is doomed to fail in too many cases; fortunately black magic comes to the rescue.</p><p>From <a href="https://engineering.fb.com/2024/10/22/security/ipls-privacy-preserving-storage-for-your-whatsapp-contacts/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">engineering.fb.com/2024/10/22/</span><span class="invisible">security/ipls-privacy-preserving-storage-for-your-whatsapp-contacts/</span></a>:<br>❞<br>But losing your phone could mean losing your contact list as well. Traditionally, WhatsApp has lacked the ability to store your contact list in a way that can be easily and automatically restored in the event you lose it.<br>[...]<br>If you lose your phone, your contact list can be restored on a newly registered device.<br>[...]<br>Certain events [...] trigger the creation of a new cryptographic keypair that is associated with your phone number.<br>❝</p><p>So al the military grade encryption, HSM's and Cloudflare supervision eventually depends on a PHONE NUMBER - with, in modern computer terms, a VERY limited number of possible combinations of digits.</p><p>And all that apart from the fact that phone numbers may be spoofed and "SIM-swapping" attacks happen to be a lot easier than most people are aware of.</p><p>What could possibly go wrong?</p><p>P.S. Of course I may be totally mistaken, for example because additional protections are in place. However, I do not see them mentioned in the FB article.</p><p><a href="https://infosec.exchange/tags/WhatsApp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WhatsApp</span></a> <a href="https://infosec.exchange/tags/AddressBook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AddressBook</span></a> <a href="https://infosec.exchange/tags/Contacts" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Contacts</span></a> <a href="https://infosec.exchange/tags/Meta" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Meta</span></a> <a href="https://infosec.exchange/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://infosec.exchange/tags/Cloudflare" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cloudflare</span></a> <a href="https://infosec.exchange/tags/HSM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HSM</span></a> <a href="https://infosec.exchange/tags/SnakeOil" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SnakeOil</span></a> <a href="https://infosec.exchange/tags/MilitaryGradeEncryption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MilitaryGradeEncryption</span></a> <a href="https://infosec.exchange/tags/WriteOnceReadMany" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WriteOnceReadMany</span></a> <a href="https://infosec.exchange/tags/BlockChain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BlockChain</span></a> <a href="https://infosec.exchange/tags/Transparency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Transparency</span></a> <a href="https://infosec.exchange/tags/Passkeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passkeys</span></a> <a href="https://infosec.exchange/tags/Synchronisation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Synchronisation</span></a> <a href="https://infosec.exchange/tags/E2EE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>E2EE</span></a></p>