I'm a big fan of Telegram for its top notch bot support, but I'm flagging this submission.
I'm a big fan of Telegram for its top notch bot support, but I'm flagging this submission.
Do you trust claims made by Facebook about privacy and encryption?
I trust facebook that when they say something is E2E encrypted, it really is (except in the case of targeted attacks). If it weren't, I would expect an internal whistleblower to very quickly report it.
Since both client and server side are proprietary, it can't be proven that the OpenWhisper implementation wasn't tampered with. and it's very disheartening to see Signal licking WhatsApp's metaphorical feet every step of the way.
Reading bytecode is trivial. Reading decompiled binaries is even not so bad. Hiding some tampering of the protocol in closed source clients is not that much easier than hiding it in open source clients. Especially if tens of thousands of engineers have access to the whatsapp source and change history and a deliberate backdoor would be international news.
Besides, security and privacy should be the default. It's not like the user experience of WhatsApp is drastically worse for having E2E.
Source, please.
> Besides, security and privacy should be the default.
Not at the cost of usability and freedom. Especially considering E2E encryption isn't necessary to protect against the attackers most people can expect.
> It's not like the user experience of WhatsApp is drastically worse for having E2E.
It absolutely is. WhatsApp doesn't even allow you to use multiple devices!
> It absolutely is. WhatsApp doesn't even allow you to use multiple devices!
I'm pretty sure you couldn't use multiple devices before they implemented E2E.
By the way, how does E2E cost freedom?
Not saying telegram is better. But this is a common use-case for whatsapp. (Whatsapp web transports all history).
So the E2EE argument is disingenuous if the client is closed imo.
The case for whatsapp web is absolutely true- and you can’t say that it 100% doesn’t have any remote admin features, because it’s closed.
EDIT: I'd like to clarify; many people's reasoning seems to be:
"Whatsapp == Signal" && "Signal > *"
But that's not at all true.
To my knowledge, that's not true. But even if true, that doesn't mean e2e encryption isn't in effect.
---
> The case for whatsapp web is absolutely true
The web interface is completely driven by your phone, acting as a remote control and WhatsApp still doesn't have access to your conversations.
https://signal.org uses the exact same model and it's open source, so you can review it.
It is true that WhatsApp being proprietary, Facebook could insert local content scanners that bypasses e2e encryption. Which they actually threatened to do in the past, not sure what the status of that is.
But in spite of this, WhatsApp is still much better than any other service that doesn't do e2e encryption by default. Yes, I'd prefer Signal.org personally, but it's not what my acquaintances use ¯\_(ツ)_/¯
And I'll never use Telegram, unless it reaches FB Messenger levels of popularity.
It's not true. I just recently switched phones. If you activate your phone on the app, you can't use the app on your previous phone without authenticating again, and it only shows your local history. I lost all my history when moving phones, as I chose not to back up my messages (who would?).
The trick is to use the local backup option (it's encrypted with a key from the whatsapp servers, but all the files are kept on your device), and use syncthing to copy the whole folder structure (containing the backup and the media) to the new phone before installing whatsapp. When first run, the whatsapp client detects the presence of that backup, asks whether you want to use it, gets the key from the whatsapp servers (after you authenticate your account), and restores the backup.
(By the way, Signal can do the same trick, but it's slightly less user-friendly: the encryption key does not come from the signal servers, it's a sequence of numbers you have to write down and type on the new phone.)
> https://signal.org uses the exact same model and it's open source, so you can review it.
To be clear, Signal's desktop interface does not work like WhatsApp's web interface: Signal is not completely driven by your phone. Signal Desktop can still send and receive messages even if the phone it is tied to is completely off.
I might have misunderstood what you're trying to say, but wanted to clarify this.
This is not true on Android. You cannot activate WhatsApp on 2 phones at once. If you try, the first will instantly deactivate and will not do any copying of messages. Message restore is from Google Drive backups. There is also a way to backup to a file, but it's an unsupported hack.