On cryptographic security of end-to-end encrypted connections in WhatsApp and Telegram messengers

The aim of this work is to analyze the available possibilities for improving secure messaging with end-to-end connections under conditions of external violator actions and distrusted service provider. We made a comparative analysis of cryptographic security mechanisms for two widely used messengers:...

Full description

Bibliographic Details
Published in:Безопасность информационных технологий
Main Authors: Sergey V. Zapechnikov, Polina O. Kozhukhova
Format: Article
Language:English
Published: Joint Stock Company "Experimental Scientific and Production Association SPELS 2017-11-01
Subjects:
Online Access:https://bit.mephi.ru/index.php/bit/article/view/275
_version_ 1856915231465275392
author Sergey V. Zapechnikov
Polina O. Kozhukhova
author_facet Sergey V. Zapechnikov
Polina O. Kozhukhova
author_sort Sergey V. Zapechnikov
collection DOAJ
container_title Безопасность информационных технологий
description The aim of this work is to analyze the available possibilities for improving secure messaging with end-to-end connections under conditions of external violator actions and distrusted service provider. We made a comparative analysis of cryptographic security mechanisms for two widely used messengers: Telegram and WhatsApp. It was found that Telegram is based on MTProto protocol, while WhatsApp is based on the alternative Signal protocol. We examine the specific features of messengers implementation associated with random number generation on the most popular Android mobile platform. It was shown that Signal has better security properties. It is used in several other popular messengers such as TextSecure, RedPhone, GoogleAllo, FacebookMessenger, Signal along with WhatsApp. A number of possible attacks on both messengers were analyzed in details. In particular, we demonstrate that the metadata are poorly protected in both messengers. Metadata security may be one of the goals for further studies.
format Article
id doaj-art-25bbdcd047804f62a839c1ed47e79f84
institution Directory of Open Access Journals
issn 2074-7128
2074-7136
language English
publishDate 2017-11-01
publisher Joint Stock Company "Experimental Scientific and Production Association SPELS
record_format Article
spelling doaj-art-25bbdcd047804f62a839c1ed47e79f842025-08-19T20:19:24ZengJoint Stock Company "Experimental Scientific and Production Association SPELSБезопасность информационных технологий2074-71282074-71362017-11-01244354310.26583/bit.2017.4.04271On cryptographic security of end-to-end encrypted connections in WhatsApp and Telegram messengersSergey V. Zapechnikov0Polina O. Kozhukhova1National Research Nuclear University MEPhI,National Research Nuclear University MEPhI,The aim of this work is to analyze the available possibilities for improving secure messaging with end-to-end connections under conditions of external violator actions and distrusted service provider. We made a comparative analysis of cryptographic security mechanisms for two widely used messengers: Telegram and WhatsApp. It was found that Telegram is based on MTProto protocol, while WhatsApp is based on the alternative Signal protocol. We examine the specific features of messengers implementation associated with random number generation on the most popular Android mobile platform. It was shown that Signal has better security properties. It is used in several other popular messengers such as TextSecure, RedPhone, GoogleAllo, FacebookMessenger, Signal along with WhatsApp. A number of possible attacks on both messengers were analyzed in details. In particular, we demonstrate that the metadata are poorly protected in both messengers. Metadata security may be one of the goals for further studies.https://bit.mephi.ru/index.php/bit/article/view/275cryptographyend-to-end connectionencryptionWhatsAppTelegram
spellingShingle Sergey V. Zapechnikov
Polina O. Kozhukhova
On cryptographic security of end-to-end encrypted connections in WhatsApp and Telegram messengers
cryptography
end-to-end connection
encryption
WhatsApp
Telegram
title On cryptographic security of end-to-end encrypted connections in WhatsApp and Telegram messengers
title_full On cryptographic security of end-to-end encrypted connections in WhatsApp and Telegram messengers
title_fullStr On cryptographic security of end-to-end encrypted connections in WhatsApp and Telegram messengers
title_full_unstemmed On cryptographic security of end-to-end encrypted connections in WhatsApp and Telegram messengers
title_short On cryptographic security of end-to-end encrypted connections in WhatsApp and Telegram messengers
title_sort on cryptographic security of end to end encrypted connections in whatsapp and telegram messengers
topic cryptography
end-to-end connection
encryption
WhatsApp
Telegram
url https://bit.mephi.ru/index.php/bit/article/view/275
work_keys_str_mv AT sergeyvzapechnikov oncryptographicsecurityofendtoendencryptedconnectionsinwhatsappandtelegrammessengers
AT polinaokozhukhova oncryptographicsecurityofendtoendencryptedconnectionsinwhatsappandtelegrammessengers