{"id":360,"date":"2021-02-11T14:57:17","date_gmt":"2021-02-11T17:57:17","guid":{"rendered":"http:\/\/sites.usp.br\/ubri\/?p=360"},"modified":"2021-02-11T14:59:56","modified_gmt":"2021-02-11T17:59:56","slug":"building-auditability-into-instant-messaging-apps-for-business","status":"publish","type":"post","link":"https:\/\/sites.usp.br\/ubri\/building-auditability-into-instant-messaging-apps-for-business\/","title":{"rendered":"Building auditability into Instant Messaging Apps for Business"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/sites.usp.br\/ubri\/wp-content\/uploads\/sites\/545\/2021\/02\/Auditable-IM.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-388 aligncenter\" src=\"https:\/\/sites.usp.br\/ubri\/wp-content\/uploads\/sites\/545\/2021\/02\/Auditable-IM-300x265.png\" alt=\"\" width=\"378\" height=\"334\" srcset=\"https:\/\/sites.usp.br\/ubri\/wp-content\/uploads\/sites\/545\/2021\/02\/Auditable-IM-300x265.png 300w, https:\/\/sites.usp.br\/ubri\/wp-content\/uploads\/sites\/545\/2021\/02\/Auditable-IM-768x678.png 768w, https:\/\/sites.usp.br\/ubri\/wp-content\/uploads\/sites\/545\/2021\/02\/Auditable-IM-400x353.png 400w, https:\/\/sites.usp.br\/ubri\/wp-content\/uploads\/sites\/545\/2021\/02\/Auditable-IM.png 791w\" sizes=\"auto, (max-width: 378px) 100vw, 378px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>The ability to verify the integrity and authenticity of messages exchanged via instant messaging apps has being gaining importance lately. One of the main reasons is that such applications are being more commonly used for business purposes [<a href=\"https:\/\/www.whatsapp.com\/business\/\">1<\/a>], and it is not uncommon that the messages exchanges are somehow used as proof in legal cases [<a href=\"https:\/\/www.telemessage.com\/whatsapp-ediscovery-cases-where-whatsapp-chats-was-used-as-evidence-in-court\/\">2<\/a>].<\/p>\n<p>A lurking danger in such scenarios, though, is the fact that most Instant Messaging apps (e.g., Telegram, WhatsApp and Signal) are designed with the specific purpose of preventing auditability: instead, they focus on plausible deniability, i.e., the security mechanisms employed deliberately fail to generate any evidence that confirm whether a given message was sent\/received by any of the communicating parties, even if that was actually the case, right after the delivery is successful. As a result, one can create forged or modified messages that are indistinguishable from the actual messages exchanged. Indeed, there are many examples in the literature of how this can be accomplished for popular apps like WhatsApp [<a href=\"https:\/\/www.slideshare.net\/abrahampasamar\/modifying-whatsapp-messages-for-dummies\">3<\/a>] and Telegram [<a href=\"https:\/\/www.larc.usp.br\/experimento_mensagens\/\">4<\/a>]. Therefore, and despite common believe and practice, messages willingly presented by users have little value as forensic evidence, and even less so if their contents are leaked by untrusted parties (e.g., as in the Brazilian case known as \u201cVaza Jato\u201d, roughly translated as \u201cCar Wash Leaks\u201d, were Telegram messages were obtained via mobile phone invasion [<a href=\"https:\/\/theintercept.com\/2019\/06\/09\/brazil-archive-operation-car-wash\/\">5<\/a>]).<\/p>\n<p>Leaving aside the (sometimes heated!) politics surrounding those cases, and aiming to address this technical issue, the goal of this research project is to create auditability features that can be easily activated and employed by users whenever they wish to trade plausible deniability for auditability, or are required to do so due to the target application\u2019s characteristics. The proposed solution combines: (1) Blockchains as the underlying data structures that regulate message exchanges among peers, so the order and integrity of those messages can be easily verified; (2) digital signatures from both sender and receiver, thus providing authenticity and non-repudiation to the message history; and (3) a mechanism for selective disclosure, meaning that a user can choose to reveal a subset of messages for the auditing party, keeping the rest of the conversation private. The different modules that constitute the solution are architecture-independent, so they can be integrated \u00a0into any instant messaging application (individually or all together).<\/p>\n<p>&nbsp;<\/p>\n<p><em>This research project is supported by the\u00a0<a href=\"https:\/\/ubri.ripple.com\/\">University Blockchain Research Initiative (UBRI)<\/a>.<\/em><\/p>\n<p><em>Contact information at USP:\u00a0<a href=\"http:\/\/lattes.cnpq.br\/6874544707185541\">Prof. Dr. Marcos A. Simplicio Jr\u00a0<\/a>&lt;mjunior(at)larc.usp.br&gt;<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong>See also:<\/strong><\/p>\n<ul>\n<li>KOMO, A. E. ; SIMPLICIO JR, M. A. (2019) Solu\u00e7\u00e3o para Habilitar Conversas Integras e Audit\u00e1veis em Aplicativos de Troca de Mensagens Instant\u00e2neas. In: XIX Simp\u00f3sio Brasileiro de Seguran\u00e7a da Informa\u00e7\u00e3o e de Sistemas Computacionais (SBSeg) &#8212; XIII Workshop de Trabalhos de Iniciac\u0327a\u0303o Cienti\u0301fica e de Graduac\u0327a\u0303o (WTICG), 2019, S\u00e3o Paulo. Anais Extendidos do XIX Simp\u00f3sio Brasileiro de Seguran\u00e7a da Informa\u00e7\u00e3o e de Sistemas Computacionais (SBSeg). Porto Alegre: Sociedade Brasileira de Computa\u00e7\u00e3o, 2019. v. 19. p. 1-10. Available: <a href=\"https:\/\/sbseg2019.ime.usp.br\/anais\/196912.pdf\">https:\/\/sbseg2019.ime.usp.br\/anais\/196912.pdf<\/a> (PT-BR)<\/li>\n<li>KOMO, A. E. ; ARAKAKI, B. O.; SIMPLICIO JR, M. A.; LEVY, M. R. (2018). Aplicativo de Troca de Mensagens Instant\u00e2neas Utilizando Comunica\u00e7\u00e3o P2P. Anais Estendidos do XVIII Simp\u00f3sio Brasileiro em Seguran\u00e7a da Informa\u00e7\u00e3o e de Sistemas Computacionais. Porto Alegre: Sociedade Brasileira de Computa\u00e7\u00e3o. Available: <a href=\"https:\/\/sol.sbc.org.br\/index.php\/sbseg_estendido\/article\/view\/4143\">https:\/\/sol.sbc.org.br\/index.php\/sbseg_estendido\/article\/view\/4143<\/a> (PT-BR)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>References:<\/strong><\/p>\n<p style=\"padding-left: 40px;\">[1] WhatsApp Business App. Available (online): <a href=\"https:\/\/www.whatsapp.com\/business\/\">https:\/\/www.whatsapp.com\/business\/<\/a><\/p>\n<p style=\"padding-left: 40px;\">[2] Pinchas (2019). WhatsApp eDiscovery &#8211; Cases Where WhatsApp Chats Were Used as Evidence in Court. Telemessage Blog, December 3, 2019. Available: <a href=\"https:\/\/www.telemessage.com\/whatsapp-ediscovery-cases-where-whatsapp-chats-was-used-as-evidence-in-court\/\">https:\/\/www.telemessage.com\/whatsapp-ediscovery-cases-where-whatsapp-chats-was-used-as-evidence-in-court\/<\/a><\/p>\n<p style=\"padding-left: 40px;\">[3] A. Pasamar (2016). Modifying WhatsApp messages for dummies. FAQin Congress &#8211; 5\/3\/2016. Available: <a href=\"https:\/\/www.slideshare.net\/abrahampasamar\/modifying-whatsapp-messages-for-dummies\">https:\/\/www.slideshare.net\/abrahampasamar\/modifying-whatsapp-messages-for-dummies.<\/a><\/p>\n<p style=\"padding-left: 40px;\">[4] Marcos A. Simplicio Jr. (2019). After all, how hard is to manipulate Telegram messages after an invasion? Is auditing possible? (<em>Afinal, o qu\u00e3o f\u00e1cil \u00e9 manipular mensagens do Telegram ap\u00f3s uma invas\u00e3o? D\u00e1 para auditar?<\/em>). <span class=\"aCOpRe\"> Laboratory of Computer Networks and Architecture (LARC), Universidade de S\u00e3o Paulo (USP), 10\/Jul\/2019. Available: <\/span>\u00a0<a href=\"https:\/\/www.larc.usp.br\/experimento_mensagens\/\">https:\/\/www.larc.usp.br\/experimento_mensagens\/<\/a> (PT-BR)<\/p>\n<p style=\"padding-left: 40px;\">[5] G. Greenwald, L. Demori, B. Reed (2019). How and Why The Intercept Is Reporting on a Vast Trove of Materials About Brazil\u2019s Operation Car Wash and Justice Minister Sergio Moro . The Intercept, June 9 2019. Available: <a href=\"https:\/\/theintercept.com\/2019\/06\/09\/brazil-archive-operation-car-wash\/\">https:\/\/theintercept.com\/2019\/06\/09\/brazil-archive-operation-car-wash\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; The ability to verify the integrity and authenticity of messages exchanged via instant messaging apps has being gaining importance lately. One of the main reasons is that such applications are being more commonly used for business purposes [1], and it is not uncommon that the messages exchanges are somehow used as proof in<a href=\"https:\/\/sites.usp.br\/ubri\/building-auditability-into-instant-messaging-apps-for-business\/\">[&#8230;]<\/a><\/p>\n","protected":false},"author":22273,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_links_to":"","_links_to_target":""},"categories":[4,11],"tags":[],"class_list":["post-360","post","type-post","status-publish","format-standard","hentry","category-noticias","category-research-pesquisa"],"_links":{"self":[{"href":"https:\/\/sites.usp.br\/ubri\/wp-json\/wp\/v2\/posts\/360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sites.usp.br\/ubri\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.usp.br\/ubri\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.usp.br\/ubri\/wp-json\/wp\/v2\/users\/22273"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.usp.br\/ubri\/wp-json\/wp\/v2\/comments?post=360"}],"version-history":[{"count":4,"href":"https:\/\/sites.usp.br\/ubri\/wp-json\/wp\/v2\/posts\/360\/revisions"}],"predecessor-version":[{"id":391,"href":"https:\/\/sites.usp.br\/ubri\/wp-json\/wp\/v2\/posts\/360\/revisions\/391"}],"wp:attachment":[{"href":"https:\/\/sites.usp.br\/ubri\/wp-json\/wp\/v2\/media?parent=360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.usp.br\/ubri\/wp-json\/wp\/v2\/categories?post=360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.usp.br\/ubri\/wp-json\/wp\/v2\/tags?post=360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}