Tag: encryption

WhatsApp and Signal are bringing forth desktop video calling

Articles

WhatsApp desktop with videoconference support press image courtesy of WhatsApp

WhatsApp now does one-to-one video videocalls on the desktop

How to Make WhatsApp Voice and Video Calls on Desktop (lifehacker.com.au)

From the borse’s mouth

WhatsApp

Introducing private and secure calling from the desktop – WhatsApp Blog

Signal

A new platform is calling: Help us test one-to-one voice and video conversations on Signal Desktop (Blog Post from Signal)

My Comments

Signal desktop one-on-one videoconferencing press picture courtesy of the Signal Foundation

… as does Signal

WhatsApp and Signal, both messaging and calling systems that implement end-to-end encryption, are dependent on a primary client which is the user’s smartphone. But both platforms also implement secondary software native to most desktop operating systems so that users can interact with these platforms on their regular computer.

But the desktop programs for these services are dependent on the primary smartphone which has the user’s mobile number and encryption keys to work properly. The software was initially set up for personal and group chat abilities only but has now been “built out” to support one-on-one audio and video calls using the desktop client software.

WhatsApp and Signal's relationship with their desktop clients

How WhatsApp and Signal work with their desktop client software

Some users prefer to use a desktop or laptop computer to make or take videocalls due to the larger screen these devices offer. As well, there is an increasing number of Windows-powered 2-in-1 convertibles that can easily answer this need.

What has now happened for WhatsApp and Signal is that the latest versions of their desktop client software is now supporting voice and video calling. At the moment, this will support one-on-one voice and videocalling.

Signal have even worked on the WebRTC real-time-communications protocol and contributed their improvements to the source code for that protocol. This is to make things work smoothly for one-user many-device operation, something that could apply to a lot of videocall apps based on this technology.

Both companies will need to work towards supporting group videocalls on their desktop software as well as on the primary mobile devices. This is more so as the desktop computing environment shows appeal towards multiparty videocalls.

As well, the WhatsApp and Signal efforts are about implementing voice and videocalls in a multiple-device sense where there is a primary device operated by the user. This may legitimise other similar use cases like automotive or group-videophone (connected-TV / set-top device) use cases.

Zoom to introduce end-to-end encryption

Articles

Zoom (MacOS) multi-party video conference screenshot

Zoom to provide end-to-end encryption for those video conferences

Zoom end-to-end encryption is finally rolling out next week | Android Authority

Zoom to preview free end-to-end encryption for meetings | ITNews

Zoom Is Adding End-To-End Encryption to Your Endless Meetings | Gizmodo

Zoom finally rolls out end-to-end encryption, but you have to enable it | Mashable

From the horse’s mouth

Zoom

Zoom Rolling Out End-to-End Encryption Offering (Blog Post)

My Comments

Since the COVID-19 coronavirus plague had us housebound even for work or school, we have ended up using videoconferencing platforms more frequently for work, school and social life. The most popular of these platforms ended up being Zoom which effectively became a generic trademark for multiparty videoconferencing.

But the computer press and consumer-privacy regulators identified that most of these videoconferencing platforms had security and user-privacy / company-confidentiality weaknesses. One of these that has beset Zoom was the lack of end-to-end encryption for multiparty videocalls. This ended up being a key issue due to most of us ending using these platforms more frequently and the increased use of Zoom and similar platforms for medical and legal telexonsultations.

Now Zoom, as part of its recent Zoomtopia feature-launch multiparty videoconference, has launched a number of new features for their platform. These include virtual participant layouts similar to what Microsoft Teams is offering.

But the important one here is to facilitate end-to-end encryption during multiparty videoconferences. This will be available across all of Zoom’s user base, whether free or paid. For the first 30 days from next week, it will be a technical preview so they can know of any bugs in the system.

The end-to-end encryption is based around the meeting host rather than Zoom generating the keypairs for the encryption protocol, which would occur as a videoconference is started and as users come on board. It is a feature that Zoom end-users would need to enable at account level and also activate for each meeting they wish to keep secure. That is different from WhatsApp where end-to-end encryption occurs by default and in a hands-off manner.

At the moment, updated native Zoom clients will support the end-to-end encryption – you won’t have support for it on Zoom Web experiences or third-party devices and services that work with Zoom like the smart displays or Facebook’s Portal TV videophone. This situation will be revised as Zoom releases newer APIs and software that answers thsi need.

If a meeting is operating with end-to-end encryption, there will be a green shield with a lock symbol in the upper left corner to indicate that this is the case. They can click on the icon to bring up a verification code and have that confirmed by the meeting host reading it out loud.

Free users will be required to use SMS-based verification when they set up their account for end-to-end encryption. This is a similar user experience to what a lot of online services are doing where there is a mobile phone number as a second factor of authenticity.

At least Zoom is taking steps towards making its multiparty videoconference platform more safe and secure for everyone.

More companies participate in Confidential Computing Consortium

Article

Facebook, AMD, Nvidia Join Confidential Computing Consortium | SDx Central

AMD, Facebook et Nvidia rejoignent une initiative qui veut protéger la mémoire vive de nos équipements  (AMD, NVIDIA and Facebook join an initiatiative to protect the live memory of our equipment) | O1Net.com (France – French language / Langue française)

From the horse’s mouth

Confidential Computing Consortium

Web site

My Comments

Some of online life’s household names are becoming part of the Confidential Computing Consortium. Here, AMD, Facebook, NVIDIA are part of this consortium which is a driver towards secure computing which is becoming more of a requirement these days.

What is the Confidential Computing Consortium

This is an industry consortium driven by the Linux Foundation to provide open standards for secure computing in all use cases.

It is about creating a standard software-development kits that are about secure software execution. This is to allow software to run in a hardware-based Trusted Execution Environment that is completely secure. It is also about writing this code to work independent of the system’s silicon manufacturer and to work across the common microarchitectures like ARM, RISC-V and x86.

This is becoming of importance nowadays with malware being written to take advantage of data being held within a computing device’s volatile random-access memory. One example of this include RAM-scraping malware targeted at point-of-sale / property-management systems that steal customers’ payment-card data while a transaction is in progress. Another example are the recent discoveries by Apple that a significant number of familiar iOS apps are snooping on the user’s iPhone or iPad Clipboard with their iPhones without the knowledge and consent of the user.

As well, in this day and age, most software implements various forms of “memory-to-memory” data transfer for many common activities like cutting and pasting. There is also the fact that an increasing number of apps are implementing context-sensitive functionality like conversion or translation for content that a user selects or even for something a user has loaded in to their device.

In most secure-computing setups, data is encrypted “in-transit” while it moves between computer systems and “at rest” while it exists on non-volatile secondary storage like mechanical hard disks or solid-state storage. But it isn’t encrypted while it is in use by a piece of computer software to fulfil that program’s purposes. This is leading to these kind of exploits like RAM-scraping malware.

The Confidential Computing Consortium is about encrypting the data that is held within RAM and allowing the user to grant software that they trust access to that encrypted data. Primarily it will be about consent-driven relevance-focused secure data use for the end-users.

But the idea is to assure not just the security and privacy of a user’s data but allow multiple applications on a server-class computer to run in a secure manner. This is increasingly important with the use of online services and cloud computing where data belonging to multiple users is being processed concurrently on the same physical computer.

This is even relevant to home and personal computing, including the use of online services and the Internet of Things. It is highly relevant with authenticating with online services or facilitating online transactions; as well as assuring end-users and consumers of data privacy. As well, most of us are heading towards telehealth and at-home care which involves the handling of more personally-sensitive information relating to our health through the use of common personal-computing devices.

The fact that Facebook is on board is due to the fact the social network’s users make use of social sign-on by that platform to sign up with or log in to various online services. In this case, it would be about protecting user-authentication tokens that move between Facebook and the online service during the sign-up or log-in phase.

As well,  Facebook has two fingers in the consumer online messaging space in the form of Facebook Messenger and WhatsApp products and both these services feature end-to-end encryption with WhatsApp having this feature enabled by default. Here, they want users to be sure that the messages during, say, a WhatsApp session stay encrypted even in the device’s RAM rather than just between devices and within the device’s non-volatile storage.

I see the Confidential Computing Consortium as underscoring a new vector within the data security concept with this vector representing the data that is in the computer’s memory while it is being processed. Here, it could be about establishing secure consent-driven access to data worked on during a computing session, including increased protection of highly-sensitive business and personal data.

Popular Internet-based communications platforms to be secure

WhatsApp Android screenshot courtesy of WhatsApp

WhatsApp – the pioneer for security-focused online communications for consumers

Some of the popular over-the-top messaging and VoIP platforms are being equipped for personal privacy and security.

This was a feature typically pitched at high-stakes business users but is now being pitched at everyday consumers thanks to the saga occurring in the USA between FBI and Apple where the FBI were wanting the encrypted data held on a suspect’s iPhone.

At the moment, WhatsApp and Viber are offering secure-communications features but this could be rolled out by other messaging/VoIP/videocall platform vendors like Skype, Facebook or Apple. For that matter, WhatsApp have recently made their platform from a subscription-funded platform to a free-to-user platform. They will continue to raise money by offering business-focused WhatsApp communications services.

Platform-wide best-case encryption by default

One of the main features is platform-wide end-to-end encryption which is implemented to “best-case standards” by default.

This means that the data that represents your calls and messages is encrypted by the end devices. Along with that, the user’s public and private keys associated with the encryption algorithm don’t stay on the company’s servers, thus not being at risk of a subpoena or other court order or government mandate. Rather, these are created by the end-user’s device and kept there.

The reference to “best-case” operation in this situation is that if the users are communicating with the latest version of the software that supports newer encryption algorithms, these algorithms are used for the encryption process. This even applies to group conversations where the “best-case” encryption method is implemented if all the correspondents are using the client apps that support that algorithm.

Authentication of contacts and their devices

As part of key exchange between contacts, there is an emphasis on authenticating one’s contacts with some systems like WhatsApp preferring a “face-to-face” method or others like Viber requiring you to read and confirm a password during a call. The former method that WhatsApp implements is for you to scan a QR code

Here, this is about whether you are really talking with the user on their device, in order to circumvent situations like lost or stolen phones, users installing their SIM cards in different devices and “man-in-the-middle” attacks. It was highlighted in Graham Cluley’s blog article about improving your security with WhatsApp.

This will typically be highlighted through the use of an indicator in your contact list that shows if a contact has been authenticated or if they have switched devices.

Concealed text/image conversations

Viber - Hide This Chat

Viber with its ability to conceal a conversation

Viber introduced to their platform the ability for one to conceal a text/image conversation which can come in handy if you are exploiting their functionality to use tablets or regular computers as endpoints for Viber conversations.

Here, you can conceal the conversation so that others cannot see it unless they enter a user-set PIN or password. Situations where this can be necessary could include an innocuous activity like arranging that surprise event through a personal conversation held in a workplace to a traveller who leaves their iPad in their hotel room which can easily be visited by Housekeeping staff.

On the other hand, you could be able to specify whether a text/image chat is to be kept on each other’s devices or to disappear like what has been valued with Snapchat.

Features that could surface in the name of security

As other online-communications platforms jump on to the secure-communications bandwagon, there could be the rise of different features or variations on the above features.

For example, a communications-platform client could implement client-level user authentication where the software can be set up to require the user to log in to the client to start a conversation. Or the primary communications device like the smartphone has to be near a secondary communications client like a laptop before the user can run the software. This feature may be considered of importance with tablets and regular computers likely to be used by other users.

To some extent, an operating system that implements multiple-user operation could allow an online-communications client to switch user profiles and phone numbers so it works totally personally to the user.

There could be the ability for a user to mandate device-level authentication or encryption before a conversation takes place with a contact. This could allow for one to be sure they are talking to the right correspondent.

Other methods of verifying contacts and devices could surface such as the use of NFC “touch-and-go” or Bluetooth data exchange as a way of authenticating users’ devices. The software could also exploit other hardware or software “secure elements” like Trusted Platform Modules as an alternative to SIM cards for Wi-Fi-only tablets or regular computers.

This could even extend to such things as “trusted networks” or “trusted locations” where your caller can know that you are talking privately, based on factors like wireless-network parameters or proximity to particular Bluetooth devices.

Conclusion

What is now happening is that secure online conversations, once a feature that was enjoyed by big business and government, is now becoming available to every individual in the street for free. This allows them to have online conversations without being eavesdropped upon.

The French have fielded another alternative to TrueCrypt

Article (French language / Langue Française)

VeraCrypt, une alternative française à TrueCrypt | Le Monde Informatique

From the horse’s mouth

Idrix

VeraCrypt product page

My Comments

TrueCrypt is a source-available encryption engine used primarily in Windows 7 and 8 as part of the BitLocker volume encryption function that the operating systems offer. Lately, further maintenance of this encryption engine had ceased with accusations of the likes of NSA putting pressure on the developers to cease maintaining it.

A few other third-party encryption engines have surfaced from Europe such as the VeraCrypt engine from France and a fork of this engine constructed in Switzerland. This is in response to Europeans having a distrust for “big government” having access to personal data due to being burnt by the Hitler, Mussolini and Franco regimes in the West and the Communist governments in Russia and the East.

Idrix has worked on the French VeraCrypt project which is pitched as being easy to use for small business, non-profit organisations and individual users. Like all encryption software, it doesn’t support the ability to “trans-crypt” i.e. convert an encrypted volume over to another encryption mechanism.

It will be initially issued for the Windows regular-computer platform but a port is being expected soon for the MacOS X (Apple Macintosh) and Linux platforms. As well, it is being made available for free and as open-source software.

But what I see of this is an attempt for European companies to “break through” the US stranglehold that can accompany the computer software scene and for European culture and norms to be respected in this field.

Chinese spies now charged with cyber espionage

Articles

IT-focused News

FBI Issues Wanted Posters For Five Chinese Army Officers | Gizmodo

DOJ’s charges against China reframe security, surveillance debate | PC World

US authorities name five Chinese military hackers wanted for espionage | The Register (UK)

General News

US Charges China With Cyber-Spying On American Firms | NBC News

Previous coverage on this topic

Symantec Symposium 2012 – My Observations From This Event

The issue of cybercrime now reaches the national level

My Comments

I have heard and will cite previous coverage about the issue of nation states engaging in cyber espionage against other nation states and businesses within these other nation states. For example, I attended the Symantec Symposium in 2012 and listened to the keynote speech by a guest speaker from the Australian Federal Police and he mentioned about organised crime and nation states engaging in the cyber-espionage or sabotage. He even said that it isn’t just servers or regular computers that were at risk but mobile devices like smartphones, point-of-sale / point-of-payment equipment and other dedicated-purpose computing devices being also at risk.

Subsequently, I watched the ABC Four Corners “Hacked” broadcast which covered the issue of cybercrime reaching a national level. This telecast covered key points including a small business who manufactured electronic equipment for defence purposes that fell victim to a Chinese cyber attack along with the theft of blueprints for ASIO’s new offices,

The recent indictment of Chinese military officers by the US government, along with FBI serving “wanted notices” on these officers has underscored the issue of nation states being involved in cyber espionage. It highlights the theft of intellectual property that private companies or government departments hold close to their heart for economic or strategic advantage.

It was even looked at in the context of the National Security Authority debate regarding cyber surveillance by that government department of Uncle Sam’s especially when there was the leaks that were put out by Edward Snowden, The US President Barack Obama even wanted to establish a global discussion regarding the cyber hacking and surveillance.

It got to the point where Mark Zwillinger, the Department Of Justice lawyer ran this line:The only computers these days that are safe from Chinese government hackers are computers that are turned off, unplugged, and thrown in the back seat of your car. Personally I would take this further by saying that the only computers these days safe from the Chinese government hackers are those that are turned off fully, unplugged and securely locked in the boot (trunk) of a sedan (saloon) or similar car.

As well, it would have us “wake up and smell the bacon” when it comes to nation states, especially those that don’t respect human rights, engaging in cyber warfare.

Vodafone Germany to provide SIM-based end-to-end encryption for smartphones

Article

Vodafone Germany looks to provide end-to-end encryption with SIM signatures • The Register

My Comments

The SIM card could be the heart of corporate-grade end-to-end mobile data security

The SIM card could be the heart of corporate-grade end-to-end mobile data security

If a company or person wanted to have highly-secure data or voice communications on their smartphone or tablet, they had to install an “over-the-top” software package and establish a separate password or key for the secure path..

Now Vodafone Germany, who is part of the Vodafone mobile-telephony conglomerate, have worked on a SIM-based setup that they can easily provide as part of a value-added service. This is based around all the passwords and keys being part of the SIM card and software held on the handset making use of these keys along with native apps to provide the secure tunnel.At the moment, this is offered to larger corporate and government customers but could be offered to small business accounts especially as some of these businesses also provide goods and services to the large corporate and government user base

One reason I would suspect that Vodafone have worked on this concept is to provide an easy-to-deploy end-to-end encryption service for consumers and small business in the wake of the Snowden affair. At the moment, the setups would be designed to work with Android devices but with Blackberry and Windows Phone ports being considered. In the case of Windows Phone, this could allow for the concept to be taken further to Windows-based tablets, laptops and desktops which are used for a lot of business computing.

A limitation that I see with the SIM-based solution is that it is dependent on a device having an integrated 3G or 4G modem thus wouldn’t be considered truly “transport independent”. I see this as being of importance as people use Wi-Fi hotspots provided by many different venue hosts and not many of these are kept secure by the venue owners thus making the customers’ data vulnerable. Similarly, this will also be of concern for client-to-box VPN setups where the “other end” of the VPN tunnel connects to the Internet via a fixed WAN connection like cable, DSL or fibre-optic.

This could be a step for mobile carriers and telcos to provide the encryption needed for secure communications especially in the wake of some serious spying scandals.