• # je ne sais pas...

    Posté par . En réponse au journal WhatsApp active le chiffrement de bout en bout. Évalué à -1.

    Autant le business d'Apple constituant à enfermer ses utilisateurs dans un environnement technologique exclusivement sous son contrôle me semble compatible avec un chiffrement total des communications, autant celui de FaceBook, qui exploite les données de ses utilisateurs, ne me semble pas être consolidé par ce chiffrement de bout en bout.

    wikipedia nous dit,

    Signal messages and calls are routed through Open Whisper Systems' servers. Open Whisper Systems has set up dozens of servers to handle the encrypted calls in more than 10 countries around the world to minimize latency.[1]

    All client-server communications are protected by TLS.[49][40] Once the server removes this layer of encryption, each message contains either the phone number of the sender or the receiver in plaintext.[50] This metadata could in theory allow the creation of "a detailed overview on when and with whom users communicated".[50] Open Whisper Systems have asserted that their servers do not keep this metadata or any logs about who called who and when.[51]

    Le truc intéressant c'est le 'double rachet',

    Signal instant messages are encrypted with the Signal encryption protocol, which combines the double ratchet, prekeys, and a 3-DH handshake.[41] It uses Curve25519, AES-256, and HMAC-SHA256 as primitives.[42] The protocol provides confidentiality, integrity, authentication, participant consistency, destination validation, forward secrecy, backward secrecy (aka future secrecy), causality preservation, message unlinkability, message repudiation, participation repudiation, and asynchronicity.[43] It does not provide anonymity preservation, and requires servers for the relaying of messages and storing of public key material.[43]

    Qui en jumpant plus loin nous donne,

    the double ratchet features properties that have been commonly available in end-to-end encryption systems for a long time: encryption of contents on the entire way of transport as well as authentication of the remote peer and protection against manipulation of messages. As a hybrid of DH and KDF ratchets, it combines several desired features of both principles. From OTR messaging it takes the properties of forward secrecy and automatically reestablishing secrecy in case of compromise of a session key, forward secrecy with a compromise of the secret persistent main key, and plausible deniability for the authorship of messages. Additionally, it enables for session key renewal without interaction with the remote peer by using secondary KDF ratchets. An additional key-derivation step is taken to enable retaining session keys for out-of-order messages without endangering the following keys.