WhatsApp explained: backdoors and bad guys
UK attempts to force open messaging app in wake of attacks follows failed efforts in US
British politicians have demanded that WhatsApp and other messaging applications provide access to police and security forces to monitor terrorist communications in the wake of last week’s attack on the Houses of Parliament. However, tech experts argue that opening backdoors in popular messaging services using end-to-end encryption throws up a number of problems.
How does WhatsApp work and what is end-to-end encryption?
WhatsApp is the world’s most popular messaging app with more than 1bn users. A year ago, it rolled out end-to-end encryption for users across all devices including iPhones, Android, Windows and BlackBerry phones.
This means that only the sender and recipient of a WhatsApp message or call can access the text, photos, videos or recordings — and, crucially, not even WhatsApp itself.
Eavesdroppers, including cybercriminals, hackers, telecoms companies, internet providers or government spies cannot access and read the content of the messages either.
What does the UK government want?
Amber Rudd, the UK home secretary, has asked that police and intelligence agencies are given access to WhatsApp messages to solve and foil crimes and acts of terrorism.
She plans to meet technology company executives later this week to pressure them into allowing this. She has not ruled out legislative changes that would compel companies to comply.
In essence, she is asking for a “backdoor”, a hole in WhatsApp’s encryption methods that would allow a select group of people under certain circumstances, such as the authorities during a police investigation, to read communications between suspected criminals.
She said it was “completely unacceptable” that government could not read messages on WhatsApp. “We need to make sure that organisations like WhatsApp, and there are plenty of others like that, don’t provide a secret place for terrorists to communicate with each other.”
Is WhatsApp pushing back against this?
WhatsApp cannot at present provide access to such messages. It has said in a statement that it was “horrified” by the London attack and that it was “co-operating with law enforcement”.
To give the UK government what it wants, the company would need to create a way to de-encrypt the service, meaning its end-to-end privacy guarantee would no longer be absolute.
But security experts agree there is no such thing as a “one-off backdoor”. If a workaround exists, it puts all its users at risk of being hacked.
Several technology executives, including Apple’s Tim Cook and WhatsApp chief executive Jan Koum, have warned that it is impossible to give some people access to encrypted devices or messages, without opening up an entry point for “bad guys” such as hackers or spies from other countries.
Mr Koum has said previously that backdoors put “our freedom and liberty . . . at stake”.
Security experts agree this sets a dangerous precedent.
“Compelling companies to put backdoors into encrypted services would make millions of ordinary people less secure online. We all rely on encryption to protect our ability to communicate, shop and bank safely,” said Jim Killock, executive director of the Open Rights Group.
How is this similar to what happened with Apple and the FBI?
Apple’s iOS software is fully encrypted, just like WhatsApp, which means no one can access any data on your iPhone, including text messages, photos, calls and contacts, unless they have your phone’s passcode — not even Apple.
Technologically, the two platforms are similarly secured against hacking or eavesdropping.
In late 2015, a US judge ordered Apple to help the FBI in its investigation into a shooting in California, in which 14 people were killed.
The court said Apple must provide “reasonable technical assistance” to break into the suspected criminal’s iPhone 5c, or in other words, to break its own encryption.
The two cases are similar in that governments have asked both companies to lower safeguards and put in a backdoor that does not currently exist.
Apple refused to comply with the FBI’s request, since it did not have the technical ability to break into a locked iPhone and would have to create one. Mr Cook said: “The US government has asked us for something we simply do not have, and something we consider too dangerous to create.”
So far, WhatsApp has not publicly pushed back on Ms Rudd’s plans, but its position on backdoors has been clear in the past.
Following Mr Cook’s letter on the issue last February, Mr Koum with Google’s chief executive Sundar Pichai and ex-NSA whistleblower Edward Snowden came out in support of the iPhone maker.
“I have always admired Tim Cook for his stance on privacy and Apple’s efforts to protect user data and couldn’t agree more with everything said in their Customer Letter today. We must not allow this dangerous precedent to be set,” he wrote in a Facebook post.