BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.troopers.de//tr26-cfp//speaker//MSQ9MB
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-tr26-cfp-UZR8NA@cfp.troopers.de
DTSTART;TZID=CET:20260625T110000
DTEND;TZID=CET:20260625T120000
DESCRIPTION:With 3 billion active users spanning every geography\, age grou
 p\, and technical sophistication level\, WhatsApp carries more private hum
 an communication than any platform in history. View Once is its promise to
  journalists\, activists\, abuse survivors\, and ordinary users that sensi
 tive media will be seen once and disappear forever.\nWe broke that promise
 . Four times.\nOver two years of research and responsible disclosure\, we 
 dismantled View Once through four successive exploits\, each one forcing a
  deeper dive into WhatsApp's internal architecture: E2EE encryption with t
 he Signal Protocol's Double Ratchet algorithm\, multi-device support with 
 the Sesame Algorithm\, and WhatsApp's inter-device Sync protocol. We detai
 l these exploits technically and walk through the disclosure process and i
 ts outcomes. The first three were properly fixed. WhatsApp surprisingly ga
 ve up on fixing the fourth.\nThe talk is deeply technical\, but the deepes
 t finding is not. This inconsistency stems from a single methodological fl
 aw: no defined security model for View Once. Without a target\, every fail
 ure becomes a "best effort" shrug. We call this Cheshire Cat Security. Whe
 n you don't know where you're going\, any road gets you there.\nWe close b
 y proposing a relevant security model for View Once\, articulating what we
  believe it should defend against\, what should be explicitly scoped out\,
  and how existing DRM technology already provides the foundation to build 
 it right.
DTSTAMP:20260510T025658Z
LOCATION:Track 1
SUMMARY:WhatsApp View Once: Four Exploits and a Funeral - Tal Be'ery
URL:https://cfp.troopers.de/tr26-cfp/talk/UZR8NA/
END:VEVENT
END:VCALENDAR
