Until proven otherwise, I think it is absolutely fair to say WhatsApp messages are, indeed, encrypted end-to-end with no possibility for FB to read the contents.
So, to answer your question: encrypted by users, and the users have the keys. FB doesn't. WhatsApp is definitely good for most things private. Moreso than e.g. Facebook wall or messenger itself, as per TFA.
Sneaky fine print is one thing. Plain lying is another.
This is the theory. Now, in practice you can see exactly the same.
https://www.thesun.co.uk/news/2606495/facebook-can-read-your...
it's hard for me to think of something I would want to say that's too sensitive to send over sms but not too sensitive to send over an encrypted chat maintained by Facebook.
Let's say you have the source code. You have the source code audited. You have reproducible builds, so you know that the source code is what was used to generate that set of binaries.
How do you know that the platform vendor isn't substituting some other code at runtime? How do you know that the hardware doesn't have a back door? How do you know that the compiler isn't inserting malicious code into the app?
At the end of the day, the only way to prove that something is doing the right thing is to watch what it does. Everything else is an educated guess.
People have built third-party WhatsApp clients, even as Facebook has tried to combat them. What Whatsapp does has been observed to the point where people are able to interact with the server at various points in time. There have been vulnerabilities reported in WhatsApp; no software is perfect, and WhatsApp has made the choice to collect more metadata than, for instance, Signal.
But up until now, nobody has found any evidence that WhatsApp is not end-to-end encrypted as it claims to be. And there are ways for people to find that out, and a lot of incentives for people to do so. Nothing is perfect, and at some point you have to decide to trust someone. I understand that trusting Facebook is fraught. But there are people with good reputations who do good work, like Moxie and tptacek, who do have expertise and can recommend WhatsApp (with an important list of caveats). Whatsapp is not perfect, but most of the options out there are much, much worse.
user1 -- server -- user2
Does this mean user1 to user2 or user1 to server and user2 to server. Both of them are end to end when you define end as client(user1, user2) or server. Again, it was proven several times that real user to user encryption is very rare, I am only aware of SILC doing that. I do not know enough about WhatsApp to believe it is user to user and I do not trust Facebook with anything. You can prove me wrong though.
Of course, this made Facebook people extremely angry, and they had lots of arguing about it. In the end the man left (losing a lot of money in the process)and of course they can read your messages now.
They had specifically been working on that for something like a year or so. A team inside facebook was created just for that.
Messages are not encrypted by users, they are encrypted by a closed source application that facebook controls 100%. They just modify the software and force an update. It is not magic.
If you can write the source code you can do anything you want.
While that's true on one hand, it's also misleading on the other. When whatsapp was acquired in 2014, it wasn't e2e encrypted. Only by 2016 that it was utilizing full e2e encryption.
So while founders did care about privacy, for first 8 years of product life e2e encryption wasn't a thing. It's much easier to add very complex feature like e2e encryption once you have infinite amount of money, coming from facebook.
>In the end the man left (losing a lot of money in the process)
Not earning extra 100s millions of dollars, after you earned many billions, is not something easy to get a sympathy for. Amount of money they left on the table is mostly a rounding error for their bank account.
They didn't even have TLS in the early versions...
https://web.archive.org/web/20110523235136/http://www.yourda...
Facebook's history is a long string of pretty significant scandals that are forgotten a year later because they're not about X, which would be something much more serious and deserving of great reprieve...
> No matter how disillusioned you are with Facebook, directly and overtly lying to customers about encryption would be next level
This feels like an ethical line drawn on your own, and a technical distinction (which we, as technically-inclined people, are wont to make) that means little in the practical legal and sociopolitical frameworks of what constitutes a breach of contract and cause for punishment.
> Sneaky fine print is one thing. Plain lying is another.
Have you read the entirety of FB's fine print regarding its services, including WhatsApp? I haven't.
https://faq.whatsapp.com/general/28030015/
Instead of us going back and forth about this, perhaps a lawyer can weigh in: is there any way Facebook would survive a lawsuit if this were patently false? Meaning, they delibrerately put in a backdoor to the encryption and are reading messages, knowingly, as intimated in this thread.
And would this be "another day in the life", or would it be a transgression of new levels for Facebook?
It is my conviction that companies try and do what they can to stay within the confines of a hypothetical lawsuit. That's what legal departments are for, essentially. If this were a lie, I would be very, very interested in knowing how they got that document past legal. But perhaps a real lawyer can elucidate matters?