Anyway, i guess this is mostly a rant. But fuck WhatsApp, they actually manage to somehow be worse than Facebook messenger. At least messenger let's you appear offline.
Anyway, i guess this is mostly a rant. But fuck WhatsApp, they actually manage to somehow be worse than Facebook messenger. At least messenger let's you appear offline.
It won't work for calling (as it's not supported on Whatsapp Web), but images and groups (which I use) both work perfectly.
And yeah, it's be forwarded and re-sent through the phone/VM. But this is the best trade-off I've found for dealing with people that refuse to leave WhatsApp. I look accommodating and don't just cut out someone I presumably need to care about, but also limit how much data FB gets.
And while I haven't tested this, I'm now curious how always having WhatsApp Web active affects my "Last Seen" time...
1. https://www.cnet.com/news/whatsapp-to-charge-iphone-users-an...
Unless there’s been an incident I’m not aware of, all I’m seeing is you claiming that WhatsApp/OWS engineers are lying with the only substantiation being questionable ethical practices of the parent company.
[0] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...
They used to have encrypted backups, but at some point in time, the Android backup (and AFAIK the iOS backup as well) dropped encryption. And since 99% or so of users back-up to the cloud, it means that Google and Apple have the unencrypted history for essentially everyone (remember, every message has two sides - they only need one side from each message)
Either way, secure messaging requires care from both sides; even if you both use Signal your counterpart can, say, let some spyware screenshot her jailbroken Android, and then it’s all for nothing. The only way of avoiding that is probably handling communication on a dedicated device, or a thoroughly locked down software ecosystem.
Anecdotally, a couple years ago I lost the entirety of my WhatsApp conversations and contacts after changing phone: I missed the opportunity to enter a code at some point and it got wiped without any way to recover it. I don’t know if that was an indication of backup encryption, but it sure felt like security trumping convenience.
Is this actually the case? I know they say it's not protected by E2EE, but my understanding is:
- images are unencrypted (just like they're accessible on your phone's external storage, where many apps can read them) - the text messages are encrypted, but the key is escrowed with Facebook, who will provide it to anyone who can pass SMS verification
This means that an attacker has to get access to both your Whatsapp account and your Google/Apple account. This isn't a very high hurdle (for governments, this likely just means two subpoenas, and for other attackers, it just means getting access to your phone number through one way or another, because in many cases that will let them hijack most of your accounts), but it seems slightly better than unencrypted.
Google won’t just give it to you - if you want it, you have to impersonate the WhatsApp app.
The local backup on your device is encrypted. Facebook will give it to anyone who can read their SMS message, as long as they also impersonate WhatsApp.
The bottom line is that without much work, google has full access to your data in whichever way they desire, but you only have access through the sanctioned app.
Which means for a state level actor, it’s at most one subpoena and likely they have streamlined that XKeyScore style, so not even that.
Any idea why they do that, instead of applying exactly the same encryption? Also, is there any place where this is documented (where I can point people to that ask me the same question)?
I've seen no credible or verifiable claim that Facebook currently has access to the keys.
That said: credible and preferably verifiable sources are very welcome.
However, depending on your threat model WhatsApp might still be a huge problem, and this is public information so you can verify it for yourself:
If anyone you communicate (or you) enable backups in WhatsApp, any chats that person is part of is uploaded to Google as unencrypted data, i.e. I believe the upload channel is encrypted but it is stored in a way that everyone who can force Google to give them access can read them.
Which means that you group chats might very well be readable to Google and everyone they have to obey without you even knowing.
https://security.stackexchange.com/questions/188040/whats-sa...
You can use Watomatic to give these people an auto-reply each time they send you a message, and tell them about the better alternative you prefer to communicate with.
Then never launch the app again.