Tag: encryption

  • Google Fi is fi-nally getting end-to-end encryption for phone calls

    Google Fi is fi-nally getting end-to-end encryption for phone calls

    If you’re concerned about the privacy of your voice communications, Google has a new way to guarantee that no one can snoop in on your calls anymore.
    Of course, there’s only so much the search giant can control, so the newly announced end-to-end encryption feature will merely work on the company’s own Fi MVNO (mobile virtual network operator) starting sometime “in the coming weeks.”

    Both the caller and the callee will need to be Google Fi subscribers and use Android phones for everything to work as advertised, at least to begin with. There’s not a lot to the technology that Big G plans to deploy before long, and all you have to know is that everything discussed during fully encrypted one-to-one voice calls will stay between you and the person you’re talking to.

    To avoid potential confusion or misunderstandings, a bunch of new “audio and visual cues” will make it crystal clear both before engaging in and during end-to-end encrypted calls that you’re wholly and entirely protected from spying ears.

    Namely, look for a lock symbol and straightforward “Encrypted by Google Fi” text on your phone’s screen or be aware of a “unique ringing tone” to make sure the functionality is indeed up and running. Obviously, the feature itself is hardly groundbreaking, as Google points out by highlighting that end-to-end encryption has become an “industry standard” in recent years for messaging apps.

    Slowly but surely, things are moving in the right direction from a privacy and security perspective as far as voice services are concerned as well, thanks to the likes of Facebook and now Google. The search giant’s Duo app actually launched with built-in end-to-end encryption for audio and video calls all the way back in 2016, so if anything, we’re surprised it took so long to implement this for Fi users.

  • WhatsApp rolls out end-to-end encryption for backup services

    WhatsApp rolls out end-to-end encryption for backup services

    Although WhatsApp already offers end-to-end encryption for messages sent, received, and stored on a device, many users are taking advantage of the backup functionality to save the history of their chats in case they lose their phones.

    Up until today, these backups did not feature end-to-end encryption like the messages stored on the phone but going forward that will no longer be the case. WhatsApp announced that it’s now rolling out an extra, optional layer of security meant to protect backups stored on two specific services with end-to-end encryption: Google Drive and iCloud.

    Those who’d like to start using the new feature and secure their end-to-end encrypted backup with either a password or a 64-digit encryption key can do so now. Obviously, neither WhatsApp nor the backup service provider will be able to read backups or access the key required to unlock it.

    End-to-end encryption for backup stored on Google Drive and iCloud will be rolled out gradually to those using the latest version of WhatsApp. Once you update your app, head to Settings / Chats / Chat Backup / End-to-end Encrypted Backup, tap Continue and follow the prompts to create a password or key.

    Keep in mind that you won’t be able to restore your backup if you lose your WhatsApp chats and forget your password or key. WhatsApp won’t reset your password or restore the backup for you, so keep them safe.

  • Google rolls out Messages end-to-end encryption to everyone

    Google rolls out Messages end-to-end encryption to everyone

    Google Messages is finally getting end-to-end encryption, which means your messages will be secure from prying eyes. Google has been testing improved security for its Messages app since last year, but only a limited number of users had access to end-to-end encryption.

    Starting this week, Google is rolling out end-to-end encryption to all Messages users. However, to take advantage of the new feature, a few aspects are required. First off, you and the person you message must both use the Messages app and have chat features enabled.

    Secondly, you must use data or Wi-Fi for RCS ( messages. Keep in mind though that end-to-end encryption does not cover SMS/MMS messages and group messages. You’ll be able to tell when end-to-end encryption is enabled if you have an arrow icon with a lock on it on the send button when you write a message.

    When you lose chat features and end-to-end encryption will no longer be enabled, you won’t have a lock icon next to the timestamp of the conversation’s latest message or on the send button when you write a new message.

    According to Google, this type of encryption converts data into scrambled text, which can only be decided with a secret key. The latter is a number created only on your phone and the device you message. The secret key is not shared with Google, anyone else, or other devices, and it’s generated again for each message.

    Last but not least, the secret key is always deleted from the sender’s device when the encrypted message is created, as well as from the receiver’s device when the message is decrypted.

  • RCS becomes a little more Apple-flavored after adding end-to-end encyption

    RCS becomes a little more Apple-flavored after adding end-to-end encyption

    When Google first started disseminating Rich Communication Services (RCS) to Android users, Google tried to copy several iMessage features. Because it uses a data hook up instead of a cellular connection, RCS can deliver much larger messages (8,000 characters up from 160), handle larger video and image files, show read receipts and more.

    One thing that RCS didn’t have that iMessage did was end-to-end encryption. With this feature, a message you send could only be read by the recipient. In May 2020, the buzz around the water cooler was that Google was testing end-to-end encryption for RCS and today the beta label was removed.

    As Google Senior Vice President Hiroshi Lockheimer (@lockheimer) posted on Twitter today, one to one messages on RCS now are equipped with end-to-end encryption. Keep in mind that this means group messages are not included. The first bunch of RCS users to get the feature are those who had not opted into the Google Messages beta indicating that this could be part of a new wide RCS rollout.

    for end-to-end encryption to work with RCS, both ends of the conversation need to have RCS enabled, and you’ll know if a message you’re sending is encrypted end-to-end if you see a lock icon on the send button.

    Little by little, Google is trying to end the blue bubble jealousy that Android users have suffered with through the years. If two RCS users are exchanging a chat, both will have blue text bubbles just like when an iPhone user is sending an iMessage to another iPhone user.

    Originally, all of the major carriers were going to be involved in the Cross Carrier Messaging Initiative (CCMI) allowing each wireless provider to offer a single new RCS app. Ironically, Google was not part of the CCMI which seemed strange in the first place considering that RCS was its baby.

    And earlier this year, the CCMI was canceled as Verizon said, “The owners of the Cross Carrier Messaging Initiative decided to end the joint venture effort. However, the owners remain committed to enhancing the messaging experience for customers including growing the availability of RCS.”

    T-Mobile also released a statement at the time that stated, “We’re committed to delivering RCS interoperability and are working with other providers to make it happen. T-Mobile customers with Android devices can currently enjoy RCS messaging across our network as well as with many other customers worldwide by interoperating with Google.”

    The major U.S. carriers were hoping to profit from the monetization of the CCMI by allowing their customers to chat with their favorite brands without having to switch apps. Users would be able to schedule appointments, pay bills, order rideshare and more through RCS thanks to the CCMI

    Analyst Lynnette Luna of GlobalData noted that RCS is really important to Google, but pointed out that because of Apple’s iMessage platform, there is no reason for Apple to get involved in RCS, and Apple has half of the U.S. smartphone market. She did say that Google continues to push RCS in the U.S. and that is because the company hopes to make money by pushing business to consumer ads.

    Luna added at the time that she didn’t expect Verizon, AT&T or T-Mobile to make a big push for RCS in the states. Consider though that in Japan, 60% of RCS messages are clicked on compared to the 0.001% that click on mobile banner ads. You can understand why Google has such high hopes for RCS as a platform for business.

    And with 1 to 1 chats now encrypted end-to-end, Google could still use RCS to pad the top line some more.

  • WhatsApp is working on encrypted chat backups, disappearing photo feature

    WhatsApp is working on encrypted chat backups, disappearing photo feature

    We’ve got a bit of welcome news from a WhatsApp leak today, especially in this era of constant bombardment with news about data spills and app security breaches all over the place.

    “WhatsApp is working on cloud backups encryption,” the independent but reliable source WABetaInfo claims in the Twitter leak. Apparently, WhatsApp is introducing a new password-protected chat backup feature on their messaging app. You can choose to lock any of your chats behind a password, and not even WhatsApp will have access to these private passwords. Upon reinstallation of WhatsApp, or installation on a new device, you will receive a password prompt to unlock your protected messages.

    Although the chat database is already encrypted, the encryption does not extend to shared media, and according to WABetaInfo, the algorithm is reversible and not end-to-end encrypted.

    The cloud-backup encryption feature should become available on a future update for both Android and iOS.

    This is not the only security update news we’ve got from WhatsApp, however. A few days ago, it was revealed WhatsApp is also testing a function for sending messages which disappear after 24 hours, as well as self-destructing photos—Snapchat-style.

    In order to use any of these features, though, you will have to agree to WhatsApp’s new privacy policy before the May 15 deadline. Failing to do so will make you lose the functionality of the app and all upcoming features.

  • Zoom lied about using end-to-end encryption and is lightly spanked by the FTC

    Zoom lied about using end-to-end encryption and is lightly spanked by the FTC

    Announced on Monday, a settlement between video conferencing app Zoom and the FTC revealed that since 2016, Zoom had been lying about providing ‘end-to-end, 256-bit encryption’ to protect the security of users’ communication. The truth was that Zoom was actually giving users a lower level of security. As the FTC said on Monday, “Zoom maintained the cryptographic keys that could allow Zoom to access the content of its customers’ meetings, and secured its Zoom Meetings, in part, with a lower level of encryption than promised.”

    The FTC complaint chronicles the rapid growth of the company. In July 2019 it had 600,000 paid subscribers and 88% of its paid subscribers were small businesses with 10 or fewer employees. By December of 2019, 10 million people around the world were participating in a Zoom chat daily. And by the time COVID-19 hit the U.S. big time in April 2020, the number of people around the globe participating on a Zoom chat everyday had skyrocketed to a whopping 300 million.

    During this amazing period of growth, Zoom made various representations about the strength of its security measures. On its websites and in its security guides Zoom said that it takes “security seriously,” that it “places privacy and security as the highest priority.” Zoom also made it known that “it is committed to protecting your privacy.” Since 2016 Zoom has been making claims that its chats offer end-to-end encryption. One way that it did this was by placing an icon of a green padlock in the top left corner of a Zoom Meeting. When a user hovered near the icon, he or she would see a popup that read “Zoom is using an end-to-end encrypted connection.”

    But as the FTC notes, “Zoom did not provide end-to-end encryption for any Zoom Meeting that was conducted outside of Zoom’s Connector product. On a blog post written by Zoom’s Chief Product Officer, the company finally admitted that “while we never intended to deceive any of our customers, we recognize that there is a discrepancy between the commonly accepted definition of end-to-end encryption and how we were using it.” The FTC also noted that the claim made last year by Zoom that its recorded meetings were stored encrypted as soon as the Meeting was over simply was not true. As it turns out, recorded Meetings were kept in Zoom’s own server unencrypted for up to 60 days before they were transferred to Zoom’s secure cloud storage where they were stored encrypted.

    The Democrats on the FTC panel are not happy about the settlement since they feel that it does not punish Zoom enough for its lies. Democratic Commissioner Rebecca Kelly Slaughter said, “Zoom is not required to offer redress, refunds, or even notice to its customers that material claims regarding the security of its services were false. This failure of the proposed settlement does a disservice to Zoom’s customers, and substantially limits the deterrence value of the case.” However, Zoom does face lawsuits from customers and investors and these could result in the company being ordered to make financial restitution to those who were hurt by the firm’s dishonesty.

    The proposed settlement that Zoom has agreed to includes beefing up its security including the use of multi-factor authentication as a way to prevent unauthorized access to the Zoom network. The settlement is open for the public to comment on it for 30 days; once that time is up, the Commission gets to vote on making it final. The 30 days begins once the settlement is published in the Federal Register. Zoom will have to notify the FTC if there are any data breaches. All software updates will need to be examined by Zoom for any security flaws. And a third-party will need to sign-off on Zoom’s security program once the settlement is finalized and for every two years after that for a total of 20 years.

  • Korean bank deploys optical encryption from Ciena

    Korean bank deploys optical encryption from Ciena

    KB Kookmin Bank, Korea’s largest financial institution, is deploying Ciena’s encryption capabilities for secure, high-capacity data centre interconnect (DCI), in a bid to better protect customer data.

    The encryption solution protects KB Kookmin Bank’s data transmissions from its offices and enables secure data centre interconnect (DCI) between its data centers.

    Several security solutions exist to protect data at-rest that secure servers, databases, routers, and switches by managing user access and credentialing. However, large amounts of critical data are in-flight and transported beyond the walls of the data center, traversing a larger, wide area network. Ciena’s optical-layer encryption solution gives KB Kookmin Bank an additional level of protection and protects data in flight as it leaves the private cloud and is transported between locations and data centers. Ciena’s solution adheres to local and international regulations and legislations, including the Federal Information Processing Standard (FIPS) 140-2 encryption certification.

    Additionally, Ciena’s software-based MyCryptoTool gives KB Kookmin Bank a dedicated management user portal that allows end-users to remotely control all of the security parameters associated with their encrypted services.

    “We are committed to providing the best possible service to our customers, which includes data protection and security. Ciena’s optical encryption solution provides an extra layer of protection and gives our customers the confidence to know their personal information is safe,” said Kim Ki-Hyun, CIO of KB Kookmin Bank.