Wednesday 6 April 2016

WhatsApp Encryption: All You Need To Know

After adding the feature to share files over WhatsApp, the developers have now added a new and probably the best feature to WhatsApp. The end-to-end encryption. This feature will ensure that the user's messages are only read by the person for whom the message is meant to be. The messages can't be read by anyone else, not by WhatsApp, not any cyber criminal, not even by any law enforcement agency.

Jan Koum, one of the founders of WhatsApp made the announcement regarding this over his Facebook page saying that the company has been working on this feature for the last two years. "We’ve been working for the past two years to give people better security over their conversations on WhatsApp… People deserve security. It makes it possible for us to connect with our loved ones. It gives us the confidence to speak our minds. It allows us to communicate sensitive information with colleagues, friends, and others. We’re glad to do our part in keeping people’s information out of the hands of hackers and cyber-criminals"-Jan Koum.

So, what does the end-to-end means, and, how exactly it works on WhatsApp?
WhatsApp encryption uses ' The Signal Protocol'. It has been designed by Open Whisper Systems.
Explaining, WhatsApp says that "once the session is established, clients do not need to rebuild a new session with each other until the existing session state is lost through an external event such as an app reinstall or device change." Explaining how the messages are encrypted, WhatsApp said- "clients exchange messages that are protected with a Message Key using AES256 in CBC mode for encryption and HMAC-SHA256 for authentication. The Message Key changes for each message transmitted, and is ephemeral, such that the Message Key used to encrypt a message cannot be reconstructed from the session.” It also says that calls, large file attachments are also end-to-end encrypted. One drawback of this feature is that it may cause the delivery of messages a bit late.

Users should know that this feature is enabled by default in WhatsApp. so, if you have the latest app installed on your smartphone, then your chats are already been encrypted. Unlike Telegram, the encryption cannot be specialized for time required, i.e. you can't turn off this feature.

Users should also know that they need to be on same version of the software to use this feature. so, if you and your friend have recently updated their software and you chat with him/her you will see a message saying "Messages you send to this chat and calls are now secured with end-to-end encryption. Tap for more info." when you tap on the message, a pop up menu that will explain about the end-to-end encryption. To verify if the encryption is working good, the user needs to click over the verify button. This will take the user to a page with a QR code and a string of 60 numbers.
And if your friend is near you, scan their QR code with your phone with the given option. if the code matches, a green tick comes and you are good to go.


0 comments:

Post a Comment

Powered by Blogger.