Binaries aren't magic.
Binaries aren't magic.
Is the claim the full WhatsApp stack is open to regular indepedent third party security audits from multiple firms?
The client-server architecture is irrelevant here.
Read this, then flip the roles: https://paragonie.com/blog/2016/03/client-authenticity-is-no...
Reverse engineer the client-side app. You now know what the client-side app (the part that people want to be open source) is doing. You don't need to know what the server's code is doing.
If the client is open source: What the server is doing is irrelevant as long as the client is secure.
If the client is closed source: What the server is doing is irrelevant as long as the client is secure.
If the server can compromise the client, whether or not the client is open source does not matter.
People who believe that open source is a prerequisite for security are disregarding the entire discipline of reverse engineering which is a large chunk of software security expertise.