Except that there is no way to prove this. There is no way to prove that it isn't also sending a copy from the client back to the server. Whatsapp could deploy individualized specific clients to target users, perhaps at the behest of governments. The only full answer is totally open-source software with users able to cryptographically verify that they are downloading and running the same software as everyone else.
Absolutism isn't helpful IMHO, there is no true security in this world only degrees of trust and risk. You can always go one step further in securing a product but the first step still matters.
I think there's real value in companies implementing e2e (and it's hard! it's super hard politically to get this done when the business sees little value for the effort and I know this because I've successfully fought to get e2e into a product).
The reality from my point of view is that it takes idealists inside to convince a commercial entity to lock themselves out of value (commercial surveillance) they could capture. I find a company's stance on e2e to be a valuable signal.
https://faq.whatsapp.com/en/general/26000050
Something is being watched. I imagine they are hashing images and comparing them to a database.
Thank you.
What you want belongs as an operating system or app distribution mechanism concern. A third party OS extension might make sense. Even that's a bit fraught if there is any kind of dynamic code execution (aka code that appears at runtime, say, a web view).
How can Facebook/WhatsApp do this on Android or iPhone?
Though, my limited understanding of iMessage is that if you were to sniff the network traffic you could detect this.
This is not a secret, it's documented behavior. https://support.apple.com/en-us/HT202303 And it's not theoretical, because Apple does decrypt iMessage communications in response to law enforcement requests: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Edit:
> Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.
So Messages in iCloud is end-to-end encrypted, but if you enable iCloud Backup (a different product/feature), then your backup will include the key used to encrypt it.
Clearly the only solution is to forage your own silicon for artisanal fabrication of your own chips.
https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...
I changed phones a while ago. Lost hundreds of thousands of messages. Didn't inconvenience me in the least. Anything important is on less ephemeral services like email or backed up manually.
A subpoena is another form of security, at least as far as a free society is concerned.