WhatsApp moderators can read your messages if someone you talk to reports them
gizmodo.com
gizmodo.com
You can also copy the whole conversation and send it to the police, or post them on a forum, etc.
WhatsApp moderators can't read your messages, but they can read what the person you talk to send them. E2E encryption means that only the ends should be able to decrypt and read the contents, but what they do with them is another different topic.
How do you know?
Is this surprising? Any third party can read part of an e2e encrypted communication if one of the participants forwards it.
I'm not too sure at what point the artificial intelligence program gets involved though.
>"the most recent messages”
and
>“information on your recent interactions with the reported user.”
which is unclear, but not unknown, and as far as this article claims they don't actually send anything else, though they do combine it with whatever metadata they have on the users involved.
It's not just when a recipient reports them it seems but also when they have been flagged by their algorithm. If that were true, the claim that the conversation is e2e encrypted simply cannot be true, unless the algorithm runs on the client.
its far far more simple to run it server side on the reported message.
What you’re describing doesn’t work with E2E encryption. I really doubt it works that way.
This smells like message franking, but I can’t be sure.
given that facebook has less than 1k moderators, do you honestly think that they'd just let the moderators sift through everything manually?
obviously you'd classify stuff first, checking against known images is easy. Classifying new images is a lot harder, plus the ethics of training and labelling a dataset for accurate detection is pretty hard, also almost impossible to do legally.
I suspect the next best thing is detecting nudity and age of the subject, and taking the hit that you're going to prioritise a lot of malicious reports, rather than genuine.
The article says that by reporting a user, the software on the site of the reporting user silently sends data to WhatsApp. The reporting user does not know what data is sent.
take a look https://twitter.com/WABetaInfo/status/1435221936888483847
When a user reports a post it is (unsurprisingly) forwarded to the moderators.
Additionally, there is some kind of AI CSAM detector, which automatically forwards posts.
In both cases, it also forwards the previous five messages from the thread to the moderators.
> Instead, WhatsApp reviewers gain access to private content when users hit the “report” button on the app, identifying a message as allegedly violating the platform’s terms of service. This forwards five messages — the allegedly offending one along with the four previous ones in the exchange, including any images or videos — to WhatsApp in unscrambled form, according to former WhatsApp engineers and moderators. Automated systems then feed these tickets into “reactive” queues for contract workers to assess.
From the actual ProPublica report. If their published understanding is correct, E2EE is not broken, but rather end users who are one of the ends of E2EE are sending the decrypted content to be moderated. The AI bit is a filter to reduce the amount of content passed on to human moderators.
From near that second quote:
> Artificial intelligence initiates a second set of queues — so-called proactive ones — by scanning unencrypted data that WhatsApp collects about its users and comparing it against suspicious account information and messaging patterns (a new account rapidly sending out a high volume of chats is evidence of spam), as well as terms and images that have previously been deemed abusive.
That part is AI driven, but my reading is that the moderators do not get access to the encrypted data (the actual messages) only the behavior patterns, and from that make a determination of what to do.
> Most can agree that violent imagery and CSAM should be monitored and reported; Facebook and Pornhub regularly generate media scandals for not moderating enough. But WhatsApp moderators told ProPublica that the app’s artificial intelligence program sends moderators an inordinate number of harmless posts, like children in bathtubs. Once the flagged content reaches them, ProPublica reports that moderators can see the last five messages in a thread.
I don't feel like it's unreasonable for a company to have a system where a user can say "Hey someone is sending me something unwanted using your service" and for that company to use technology to sort those complaints for humans to review and action appropriately based on their terms of service.
Nothing new here. I really dont get what the expectation of these things are for people. Are they not aware, someone can forward a message to a thrid party, people can and do screenshot text and forward it. Writing a message, and sending it encrypted to someone else doesnt protect you from what they might do with the message they now have.
You can't stop someone who knows what a message says from sharing the contents of that message without physically restraining and gagging them. They can send a screenshot out, take a photo of the screen, write down the message on paper, or just memorize it and tell others.
Gee, seeing how they defended Whatsapp tooth and nail time and time again, I'm inclined to not be surprised if it was added _during_.
If you think that they have backdoor access to messages, please investigate that, submit your findings as a different HN post, and then we can discuss it.
It seems like whatever the AI decides is questionable gets sent to moderators automatically, also revealing the thread history (at least partially) as well.
https://twitter.com/WABetaInfo/status/1435221936888483847
The pro publica article is pure click bait
THose who are claiming that they are running Machine learning at the edge, think about this:
how on earth can they trust the data coming from it?
We all know that ML is hard, we also know that to get accurate classification requires serious horsepower.
None of this can be run on phone hardware without people noticing.
If you were to design a system for handling reported data, who's hard constraint is _human_ eyeball time, would you run ML at the edge? No.
You'd make it so the "report this message" sent the last n lines and the attachment, and then run the ML optimised for accuracy (not speed or memory) on your hardware that you control and trust explicitly.
I would have thought all of this is obvious, given that facebook is all about avoiding spending money on human moderators. Edge ML is not going to help you do that.
If you and I are texting, privately, and you say something to me I don't like, I'll tell you., or I will stop talking to you. That's healthy social interaction. If I report it instead, that's not healthy social interaction, and it appears to me the tech companies designing these solutions to problems that were solved a decade ago are more than happy to oblige because it gives them an excuse to surveil and censor. They're encouraging unhealthy social interaction because it serves their ends to do so.
If an instant messaging application has moderators it's not an instant messaging application.
Private Whatsapp groups can include thousands of people and the topics can be anything from retail discount alerts, to COVID updates, to political organizing. That absolutely merits some kind of reporting capability, particularly if criminal activity is being conducted or is about to be conducted.
In these large groups that obviously need moderation, are the moderators appointed in some way by WhatsApp, or are they like classical rooms in that the founders of the room pick the moderation team.
Also, do one to one rooms have reporting functionality and who picks the moderator that it is reported to?
So I feel like there are reasons to have that.
https://twitter.com/wcathcart/status/1423701473624395784?s=2...
Translation: there are two ends, but one of the ends can send it to yet another end. That sounds like there are more than two ends.
It's essentially a forward to the party that supposedly can't see your messages, breaking what people understand by E2E.
Today this behavior is triggered when it's reported, tomorrow it'll be when the government, or worse, some AI, flags a user. You share a groupchat with the wrong person, or they have you in their contact list, boom, eavesdropped.
But some people will still claim it's only 2 ends just because it's not forwarded 100% of the time. I guess it's matter of semantics.
Please?
If you're not running the service yourself and taking care of end-to-end encryption, somebody can (and probably will) read your messages. Actual privacy of messaging does not exists today. Don't even bother looking for that.
EDIT: just to clarify, it might just be that somebody can access your data for a legitimate purpose (say an operator of the service) and then leak/sell the data.
This is the simplest thing that can happen and that DID happen. The united arab emirates paid a Twitter employee from UAE to leak data about anti-UAE-government from Twitter. People died because of this.