Skip to content
By using Twitter’s services you agree to our Cookies Use. We and our partners operate globally and use cookies, including for analytics, personalisation, and ads.
  • Home Home Home, current page.
  • About

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
musalbas's profile
Mustafa Al-Bassam
Mustafa Al-Bassam
Mustafa Al-Bassam
@musalbas

Tweets

Mustafa Al-Bassam

@musalbas

London, UK
www0.cs.ucl.ac.uk/staff/M.AlBass…
Joined May 2013

Tweets

  • © 2018 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @

Promote this Tweet

Block

  • Tweet with a location

    You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    By embedding Twitter content in your website or app, you are agreeing to the Twitter Developer Agreement and Developer Policy.

    Preview

    Why you're seeing this ad

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    Mustafa Al-Bassam‏ @musalbas May 9

    PSA: Disable WhatsApp chat log backups to Google Drive and Apple iCloud if you care about the end-to-end encryption.pic.twitter.com/giG07NlFiz

    6:40 AM - 9 May 2018
    • 337 Retweets
    • 466 Likes
    • Yavor Buyukliev Fluffy Space Marine Tollkornbrot Nermin Canik Bhishma shiba inu expert David Rosenblum Cathedral Journo mon mohapatra
    21 replies 337 retweets 466 likes
      1. New conversation
      2. Mustafa Al-Bassam‏ @musalbas May 9

        Mustafa Al-Bassam Retweeted Mustafa Al-Bassam

        (See: https://twitter.com/musalbas/status/954160112758816768 …)

        Mustafa Al-Bassam added,

        Mustafa Al-Bassam @musalbas
        What if a billion people had access to easy end to end encrypted messaging, except it was useless because a majority of them unknowingly backed up their and their friend's chats and group chats to Google Drive unencrypted, so the government can just subpoena Google.
        Show this thread
        1 reply 12 retweets 36 likes
        Show this thread
      3. Mustafa Al-Bassam‏ @musalbas May 10

        And no, WhatsApp backups aren't end-to-end encrypted, to all of the people in my mentions incorrectly assuming that. If they were, they'd ask you to set an encryption key when you backup...pic.twitter.com/RMF60w8fqg

        3 replies 104 retweets 135 likes
        Show this thread
      4. Mustafa Al-Bassam‏ @musalbas Jun 5

        "Manafort was backing up information from his WhatsApp to to Apple’s iCloud, where data is not encrypted and is thus available to police armed with a valid search warrant."https://motherboard.vice.com/en_us/article/zm8q43/paul-manafort-icloud-whatsapp-bad-opsec-witness-tampering …

        11 replies 140 retweets 249 likes
        Show this thread
      5. End of conversation
      1. Hans‏ @SherlockHans May 10
        Replying to @musalbas

        Well, *technically* it still is end to end encrypted, the ends just fail horribly

        0 replies 0 retweets 1 like
        Thanks. Twitter will use this to make your timeline better. Undo
        Undo
      1. New conversation
      2. Louis Unknown‏ @mygbb May 9
        Replying to @musalbas

        Well it's still encrypted with the phone key when sent to Google Cloud.

        2 replies 0 retweets 0 likes
      3. Georges Bolssens‏ @marvelade May 10
        Replying to @mygbb @musalbas

        Test case : Get another phone and try to restore the messages from the backup. If that works, your phone key has nothing to do with it.

        1 reply 0 retweets 3 likes
      4. Louis Unknown‏ @mygbb May 10
        Replying to @marvelade @musalbas

        Did that. You need to have access to the old phone. Or the sim card.

        1 reply 0 retweets 0 likes
      5. rugk‏ @rugkme May 10
        Replying to @mygbb @marvelade @musalbas

        and they likely store the encryption key on the sim card, right? Suure… very obvious that they do that…

        1 reply 0 retweets 2 likes
      6. Georges Bolssens‏ @marvelade May 10
        Replying to @rugkme @mygbb @musalbas

        Being able to transfer a SIM card to a different phone and still gets all your messages "decrypted" sounds shady to me... Wild guess: they save the ICCID of your SIM and the IMEI of your phone and if you can provide either "passcode", you get your *unencrypted* messages back.

        1 reply 0 retweets 0 likes
      7. Louis Unknown‏ @mygbb May 10
        Replying to @marvelade @rugkme @musalbas

        Well I can think of some SIM credentials key can be part of decoding key. But oh well, forget what I said. 🤐 #shamepic.twitter.com/5A7hLigUAu

        1 reply 0 retweets 4 likes
      8. rugk‏ @rugkme May 10
        Replying to @mygbb @marvelade @musalbas

        yeah, why even bother adding bad SIM stuff (whatever) encryption, when you can just store it in plaintext LOL

        0 replies 0 retweets 0 likes
      9. End of conversation
      1. Marcus Westermark‏ @CallMarcus Jun 5
        Replying to @musalbas @juhamac

        let's separate the use cases. WhatsApp is a fair for protecting legit content, when the who and when is not important. Signal will address additional privacy needs.

        0 replies 0 retweets 0 likes
        Thanks. Twitter will use this to make your timeline better. Undo
        Undo
      1. New conversation
      2. Kevin‏ @cinematicme Jun 5
        Replying to @musalbas

        Just stop using @WhatsApp, use Signal

        1 reply 0 retweets 1 like
      3. Federico Armellini‏ @ArmeF97 Jun 5
        Replying to @cinematicme @musalbas @WhatsApp

        It's not so secure... The desktop version has been already exploited

        1 reply 0 retweets 0 likes
      4. Kevin‏ @cinematicme Jun 5
        Replying to @ArmeF97 @musalbas @WhatsApp

        It hasn’t on mobile, there’s telegram too but why you would trust a company owned by Facebook to provide secure messaging services is beyond me. WhatsApp CEO left because Facebook wanted to weaken the encryption.

        1 reply 0 retweets 1 like
      5. Federico Armellini‏ @ArmeF97 Jun 5
        Replying to @cinematicme @musalbas @WhatsApp

        Where do you read that I trust whatsapp?

        1 reply 0 retweets 0 likes
      6. Kevin‏ @cinematicme Jun 6
        Replying to @ArmeF97 @musalbas @WhatsApp

        If.....you don’t trust whatsapp.....do you use it for end to end encrypted convos? I’m confused here. But, wanted to drop this in here.https://slate.com/business/2018/06/facebook-whatsapp-turmoil-takeaway-mark-zuckerberg-cant-be-trusted.html …

        1 reply 0 retweets 1 like
      7. Federico Armellini‏ @ArmeF97 Jun 6
        Replying to @cinematicme @musalbas @WhatsApp

        I don't use whatsapp, I don't see where I wrote that I use whatsapp

        0 replies 0 retweets 0 likes
      8. End of conversation
      1. New conversation
      2. Hackology‏ @Hackology May 9
        Replying to @musalbas @mythicalcmd

        You can't restore them to another number because they are binded with it ...added protection is the pin and email requried to restore (pin)

        1 reply 0 retweets 1 like
      3. rugk‏ @rugkme May 10
        Replying to @Hackology @musalbas @mythicalcmd

        buuuuuut… that's still not e2e encrypted.

        1 reply 0 retweets 1 like
      4. Hackology‏ @Hackology May 12
        Replying to @rugkme @musalbas @mythicalcmd

        It's not... Because restoring won't work if it is

        0 replies 0 retweets 0 likes
      5. End of conversation

    Loading seems to be taking a while.

    Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

      Promoted Tweet

      false

      • © 2018 Twitter
      • About
      • Help Center
      • Terms
      • Privacy policy
      • Cookies
      • Ads info