WhatsApp moderators can read your messages if someone you talk to reports them
businessinsider.in
businessinsider.in
Wait until journalists find out about the chat export feature of WhatsApp. Or the share button. Think how much juicy clickbait could be written about those features.
how is this news? it's the equivalent of taking a screenshot of a whatsapp thread and reporting that, doesn't affect e2e encrpytion in any way.
If someone reports you, they (the people receiving the report) will be able to read the messages. This is the same if you use iMessage, Signal or any other system. (ie you take your phone to the police and show them the messages, they will see your messages, obviously.)
The key difference is that facebook has a button to report the message to them.
Facebook is not a recipient and therefore should not be able to read e2e messages (that are not directed to them)
Edit: I just read that the reporting process includes sending unencrypted messages to WA as part of the report. So indeed the whole story is moot.
Of course there's a bit of a sliding scale here. If the recipient automatically and unknowingly sends all past messages to the cops when they try to report a single abusive message, it's not E2E but it sure is a back door. It's not clear from the article just how much history is sent with each report.
Are people really unaware that encryption doesn't limit the information they send to only ever be viewed by the intended recipient? That's not how and never has been how encryption works, it's not a mission impossible letter that self destructs.
The point of E2E encryption is that you trust a recipient and don't trust the medium data is sent through to the recipient. Once the recipient has the information, how well you assessed your trust in the recipient is what matters regarding the security of the information you sent. Nothing has ever prevented the recipient from breaking that trust and sharing information sent to them.
There are of course ways of reducing access to the recipient of the information through a specific technology (view once, time expirations, "self destruction", highly controlled viewing areas, etc), making it more difficult for the recipient to "proove" you sent the information and show the information relying more on the recipients word, but even that has never been that secure (Snapchat is a simple example of such).
> A Facebook representative told Insider that it allows users to report abuse, and those reports are then reviewed by contractors. When a user reports abuse, WhatsApp moderators are sent "the most recent messages sent to you by the reported user or group, according to WhatsApp's FAQ.
> WhatsApp is founded on so-called "end-to-end" encryption, which means that messages are scrambled before being sent and only unscrambled when they're received by the intended user. But when a user reports abuse, unencrypted versions of the message are sent to WhatsApp's moderation contractors, ProPublica reports.
^ This is the Head of WhatsApp at Facebook specifically calling out Apple for their client-side scanning, pointing out that Apple should instead have a way to report content; so, while he technically could be lying, I doubt that's true.
The wired/gizmodo article tries its best to imply that it does.
the main claim comes from one of the moderators saying that: "the ai keeps sending us mundane pictures, like kids in bathtubs". This has allowed people to claim that facebook are scanning every image/message. Where as, obviously given the paltry number of moderators, your going to us AI to triage messages. Otherwise you'd have to spend more cash on staff
I think there is another bit where someone says they can trace the journey of the image. Its pretty trivial to do this with metadata, given that whatsapp leaks a fair bit of metadata its not suprising.
That time I understood the whole e2e is for outsiders. Essentially, you cant have this data, only we do. First dibs and all.
> ...when a user reports abuse, unencrypted versions of the message are sent to WhatsApp's moderation contractors, ProPublica reports.
So in the end, it is possible to abuse this on to anyone and the messages can be sent to Facebook unencrypted.
Did WhatsApp (Facebook) disclose this anywhere? If not then, Oh dear.
E2E only protects between the endpoints, not after.
I even recall recommending Signal to friends -- nope. We use WhatsApp it's E2E so even safer than Signal or Telegram that are deceitful as you have to use secret chat to get E2E! All these FB messenger advocates seem to have the same arguments and yet none of the knowledge about how it works and this ludicrous "trust" in FaceBook.
At least authoritarian regimes are distrustful of Telegram and Signal -- banning them.
Just a minor correction, Telegram is the one that is only E2E encrypted via their secret chat feature. Signal is E2E encrypted at all times, and open source.
The article is written confusingly. It looked as if Facebook has private keys, and WhatsApp is not end to end encrypted.
But considering this:
>> Those contractors, which Facebook acknowledges, reportedly spend their days sifting through content that WhatsApp users and the service's own algorithms flag.
Does Facebook use automated tools and perform “Client-side Scanning” ?
That also defeats the purpose of end to end encryption.
It's just that the receivers are leaking.
Completely abusable... So E2E encryption doesn't really save us here.