The entire story was based on the question of "what do you do when someone you're communicating with using encryption changes keys?" Whatsapp chose to dynamically use the new key, rather than fail & force the user to verify the new key in some out-of-band way. This was described as a "backdoor" in the guardian story. That was simply false. Even calling it a vulnerability is a mis-understanding of how cryptography works and of the risk involved in that design decision.
That said, the open letter plainly states "WhatsApp effectively protects people against mass surveillance."
How do they know? From this, and the entire tone of the letter, it looks to me like they're still implicitly trusting that WhatsApp does what it claims to do. I see absolutely no reason to do so, and am utterly baffled that top security experts do.
You don't need access to the source code to perform this analysis.
Furthermore, if you can verify that the app does what it advertises, you don't need to trust their infrastructure. E2E takes care of that.
I think it's much easier to conclude that WhatsApp protects peoples messages from leaking or being abused by providers and other "softer" merits.
Yes, it is.
Mass surveillance is, by its very nature, defeated by E2E encryption even without identity verification.
Are you thinking of targeted surveillance?
You can argue that WhatsApp itself de facto doesn't effectively protect (against mass surveillance) because it only works with instant messages and a lot of data isn't instant messages. You can argue that there is still mass surveillance of metadata. And that governments could enact secret laws to force vendors to engage directly in mass surveillance of their customers through the OS (less likely in the US, more so in China, especially as Google isn't present).
Sure, it's a nitpick. It's implied that it's effective because it's a good way to use E2E. But it not necessarily explored in the article whether it effectively protects people. I'm sure someone thinks that PGP was effective against mass surveillance too. So it becomes and issue over what you think is worth protecting.
Did you do that before signing the letter?
> Furthermore, if you can verify that the app does what it advertises...
Without reproducible builds you can only verify the specific version of the app on your device. It's quite a leap from there to say 'Whatsapp is safe for you, too, regardless of your use-case'.