{"id":209663,"date":"2021-03-24T14:59:24","date_gmt":"2021-03-24T11:59:24","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/indias-new-idea-for-tracing-whatsapp-messages-is-deeply-flawed\/"},"modified":"2021-03-24T14:59:24","modified_gmt":"2021-03-24T11:59:24","slug":"indias-new-idea-for-tracing-whatsapp-messages-is-deeply-flawed","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/indias-new-idea-for-tracing-whatsapp-messages-is-deeply-flawed\/","title":{"rendered":"#India\u2019s new idea for tracing WhatsApp messages is deeply flawed"},"content":{"rendered":"<p>&#8220;<strong>#India\u2019s new idea for tracing <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">WhatsApp<\/a> messages is deeply flawed<\/strong>&#8221;<\/p>\n<div>\n                            It\u2019s no secret by now that India wants to trace the origin of messages on apps such as WhatsApp and Signal. In its new social media policing rule, the government said that while it doesn\u2019t want to categorically break the\u00a0encryption, it wants to know who generated a particular message first.<\/p>\n<p>A report by <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cio.economictimes.indiatimes.com\/news\/social-media\/govt-proposes-alpha-numeric-hash-to-track-whatsapp-chat\/81643144\">the Economic Times<\/a> yesterday suggested that some officials are proposing that WhatsApp should assign and store an alphanumeric hash to each message so as it could be traced back to the originator if it causes unlawful activity.<\/p>\n<p>An official who is involved in the\u00a0traceability discussion said that the government is \u201cwilling to work with WhatsApp to come up with a solution to enable traceability of messages without breaking encryption\u201c.<\/p>\n<p>However, there are a few problems with this approach. In an end-to-end encrypted system, every message is different for the system as it can\u2019t read your messages. So if you send \u201cHi\u201d two times, it doesn\u2019t recognize it as the same message.<\/p>\n<p><span>Prasanth Sugathan, Legal Director, Software Freedom Law Centre ( SFLC.in), a New Delhi based organization that concentrates on digital law, said that perpetrators could change the message slightly or simply copy it to cause the change of the hash:<\/span><\/p>\n<blockquote><p><span>The government is presuming that every forwarded message is forwarded as it is. Hashing is message-specific. Change a letter in a message and its hash will change. This means that if a malicious party wants to send a viral message, they would do it just by changing the hash of a message every time or after a few times it has been forwarded. Thereby, changing the first originator every time such a\u00a0message has been forwarded. There is a high likelihood that this would lead to a very messy implementation.<\/span><\/p>\n<\/blockquote>\n<p>In 2018, WhatsApp faced a lot of backlash from India after forwarded messages containing false information caused over 30 lynchings in the nation. However, the company has taken multiple steps to limit forwards, so it would be naive to assume every message moves in a chain.<\/p>\n<figure class=\"post-image post-mediaBleed aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1195179 lazy\" alt=\"\" width=\"600\" height=\"315\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/03\/Frequent-Forward.png\" data-lazy=\"true\" srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/03\/Frequent-Forward.png 600w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/03\/Frequent-Forward-280x147.png 280w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/03\/Frequent-Forward-514x270.png 514w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/03\/Frequent-Forward-257x135.png 257w\"\/><figcaption><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/thenextweb.com\/in\/2021\/03\/24\/indias-new-idea-for-tracing-whatsapp-messages-is-deeply-flawed\/#\" data-url=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fthenextweb.com%2Fin%2F2021%2F03%2F24%2Findias-new-idea-for-tracing-whatsapp-messages-is-deeply-flawed%2F&amp;via=thenextweb&amp;related=thenextweb&amp;text=Check out this picture on: Whatsapp frequently forwarded label\" data-title=\"Share Whatsapp frequently forwarded label on Twitter\" data-width=\"685\" data-height=\"500\" class=\"post-image-share popitup\" title=\"Share Whatsapp frequently forwarded label on Twitter\"><i class=\"icon icon--inline icon--twitter--dark\"\/><\/a>Whatsapp frequently forwarded label<\/figcaption><\/figure>\n<p>Now if a government identifies a problematic message, and if it requires to find who first sent it, it\u2019s hard to do without reading the content of the chat and breaking encryption in effect.<\/p>\n<p><span>Matthew Hodgson, CEO of Element, a secure messaging app based on <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Matrix_(protocol)\">the Matrix protocol<\/a>, said that hashing messages could <\/span>reduce the privacy of users and undermine the encryption of messaging apps:<\/p>\n<blockquote><p>This could be used by a malicious party to blackmail an innocent party by proving that they sent a given message (e.g. to persecute a whistleblower who sends a tip to a journalist, or to quote a private message out of context to embarrass the sender). Worse, it could be used by Facebook or other data brokers to gather much richer metadata about which users forward which messages to each other \u2013 further profiling users and violating their privacy.<\/p>\n<\/blockquote>\n<p>There\u2019s a possibility that the government might suggest key escrow, a method to give authorized third-party entities access to content without breaking encryption. But as <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.nytimes.com\/1994\/06\/12\/magazine\/battle-of-the-clipper-chip.html\">the Clipper Chip case of the US in the 90s suggests<\/a>, key escrows have many gaping holes in terms of unauthorized usage and security.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">In the 90s, Clinton &amp; his vice president Al-gore were promoting NSA&#8217;s Clipper Chip as a standard. This encryption chip was going to provide encryption but will have escrow keys stored by govt to de-crypt any encrypted info. India&#8217;s new rules are similar<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/jzFUBC1yAR\">https:\/\/t.co\/jzFUBC1yAR<\/a><\/p>\n<p>\u2014 Srinivas Kodali (@digitaldutta) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/digitaldutta\/status\/1373525172108492804?ref_src=twsrc%5Etfw\">March 21, 2021<\/a>\n<\/p><\/blockquote>\n<p>\u00a0<\/p>\n<p>Then there is the legal issue of determining if the originator of a message is the culprit.<\/p>\n<p>In an interview with <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.medianama.com\/2020\/12\/223-exclusive-delhi-police-has-tools-extract-data-from-smartphones-iphones\/\">Medianama<\/a> last year,\u00a0<span>Anyesh Roy, the head of Delhi Police\u2019s Cyber Crime Cell unit, said that WhatsApp provides metadata for law enforcement to catch criminals \u2014 but not the originator. In <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.forbesindia.com\/article\/take-one-big-story-of-the-day\/can-traceability-and-endtoend-encryption-coexist-heres-the-legal-view\/67001\/1\">a recent article by Forbes<\/a>, lawyers noted that India\u2019s rules to determine if the originator is the perpetrator are murky and courts will have to look at them case by case.\u00a0\u00a0<\/span><\/p>\n<p>In another scenario, if a person is sharing illegal content, police would only have information about the person under arrest and who sent them the content. But because hashes are different for different messages, it might be difficult to catch all the people\u00a0distributing the file.<\/p>\n<p>India\u2019s suggestion of hashing messages looks like a half-hearted attempt to solve the distribution of false information at the moment. It has more questions \u2014 technically and legally \u2014 than answers at the moment. It\u2019s probably time to go back to the drawing board.<\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/thenextweb.com\/in\/2021\/03\/24\/indias-new-idea-for-tracing-whatsapp-messages-is-deeply-flawed\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#India\u2019s new idea for tracing WhatsApp messages is deeply flawed&#8221; It\u2019s no secret by now that India wants to trace the origin of messages on apps such as WhatsApp and Signal. In its new social media policing rule, the government said that while it doesn\u2019t want to categorically break the\u00a0encryption, it wants to know who&#8230;<\/p>\n","protected":false},"author":1,"featured_media":209664,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/img-cdn.tnwcdn.com\/image\/tnw?filter_last=1&fit=1280,640&url=https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2018\/07\/WhatsApp-police-hed.jpg&signature=e4b7c34c732ccc5d3b7d9727e6e91907","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[72047],"class_list":["post-209663","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-whatsapp"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/209663","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=209663"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/209663\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/209664"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=209663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=209663"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=209663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}