WhatsApp is more secure than iMessage: Mark Zuckerberg
facebook.com
facebook.com
Sure is. So is getting anyone to do more than the default.
I have an extended family SMS group, an "after hours" work SMS group, and an SMS group of some people I play online computer games with.
Nobody across any of these groups is happy with the down-sampled videos, the inconsistent emoji reactions, and other SMS oddities. It's a constant complaint across all groups.
I have suggested we switch to Telegram or Signal multiple times. Not a single person is happy with SMS. Not a single person has even bothered to install Telegram or Signal.
I started the project early 2020, obviously with no knowledge of what was around the corner. Then during lockdown managed to onboard ~11 family members entirely remote by sending them a simple invitation link (some via SMS, some via email). The best part of the whole thing was how it enabled my (then) 4 year-old to independently video call 80 year-old grandparents (using an old Android tablet).
Happy to report that a couple of years later it's still the primary method of communication between family members. Obviously it hasn't fully replaced WhatsApp/etc. which they still use for most of their contacts. But still, gotta start somewhere!
I submitted a feature request and it was promptly denied. I got the impression they never really wanted to support SMS from the beginning. It was just a carrot even then, and they weren't going to focus any more effort on it.
Reference: https://webapps.stackexchange.com/a/117130
I'm not trying to say that Facebook isn't reading your messages (I doubt they do tbh, because ->) but rather trying to demonstrate that they don't need to in order to make these creepy connections. This is the importance of metadata. Data you may not even know about!
Think about it this way: a private investigator sees who you talk with, how long, where you go, etc. But they don't have the actual record of your conversations. The PI is working on metadata. We find this creepy and invasive because we can recognize how this information can be used to gather intimate aspects of our lives. Companies like Facebook are essentially doing the same thing but at scale. And you can probably imagine how the scale both helps and hinders this invasion (but likely overall helps).
Just someone we played sports with. He didn't live in our city, moved away in his youth, and we had zero friends in common on facebook. Haven't seen him suggested as a friend since he disappeared as a suggestion a couple of weeks after that.
There is also the psychological aspect of we recognizing hits more than misses (in this case. Often it is the reverse but context matters).
The only difference is that Apple publishes their yearly Supplier Responsibility report, which, yes, does contain reports that their audits found violations. And then the violations are resolved or the supplier is banned. What more are they to do?
There is a long way to go, that’s why it’s a progress report. And yes, there are aspects that are left unmentioned, like the unionization debacle in the stores. But really Apple is not who you should be focusing on for slave labor.
https://www.apple.com/supplier-responsibility/pdf/Apple_SR_2...
Just traveled overseas and used a different sim card with my phone. Not only does this screw up iMessage while overseas (it shouldn't), but for 2 weeks after getting back iMessage would occasionally just not receive texts. Did 3 Network resets and the last one (at 2 week mark) finally fixed it.
I'm sure this is more verizon's fault, but Apple needs to work around it.
Turn off roaming on main SIM card and iMessage still works, but uses the data of the other SIM card.
Turned off roaming on the physical SIM and made data only go through eSIM, but it still got all messed up. :(
Very annoying UI to get started. You need to add new contact, then from massive list select country code and finally you get to paste number.
For iMessage - default yourself and others to use apple id email address.
On the other hand, I'm not sure how much to trust Zuck's claims of WhatsApp encryption, or if external people have attempted to verify the claims, but it seems like such a big deal to lie about, that it's probably true?
Of course, that's only going to provide you passive protection from things like automated scanning of messages. If you become a target, it seems as though there are always exploits floating around which can be used to hack your phone, and then all bets off.
On the other hand, if your adversary wants to get your stuff, they will find a way. The whole cryptography thing is just imposing cost on a potential attacker, not a universal warranty against any possible attack. Someone can still locate you and beat you with XKCD's $5 wrench for your password.
Ideally we'd have end-to-end encryption on everything without adding complexity for end-users. But a lot of that stuff seems to be hard to build and at least just as hard to retroactively bolt on to a system. iMessage (iChat) goes back a long time and supports many platforms (yes, within the apple ecosystem, that is) which means they can't easily nuke every legacy API at once.
This is true, and to add to it: for state level actors, “wanting to get your stuff” expands to passive collection of data as well as well trodden paths to more targeted surveillance. End to end at least throws up a few more barriers.
And you can of course always chose to run local, encrypted backups.
Whatsapp adding end to end encryption for backups is a big deal, though. The FBI pressured Apple to not do so for iMessage.
> But the amount of data available to law enforcement is potentially far greater — greater even than the user data provided by WhatsApp — if a targeted user backs up their iMessage activity to iCloud, Apple’s online storage platform. If that’s the case, the FBI document says, then law enforcement can request back-ups of the target’s device, including actual messages sent and received in iMessage if they’re backed up in the cloud.
> While Apple describes iCloud as an encrypted service, it comes with a giant loophole. Apple holds an encryption key that can unlock user data in iCloud, and so police departments or federal agencies can request that key with a search warrant or a customer’s consent to access certain user data. “You’re handing someone else the key to hold onto on your behalf,” says Mallory Knodel of the Center for Democracy and Technology. “Apple has encrypted iCloud but they still have the keys, and as long as they have the key, the FBI can ask for it.”
It's beyond me how WhatsApp has had so many exploitable memory bugs compared to e.g. Signal or Telegram. Is it really just because security researchers would rather look at WA than Signal because of it's bigger user base?
Furthermore (this may not be the case anymore), iMessage is more privileged than other apps and so once exploited an attacker has a far greater reach.
To use a few examples:
- When sharing your location with a contact. This feature is provided by sending your location to Meta, not directly to the contact through E2EE. Even when not sharing your location Meta will approximate your location from your IP address and other available information such as the phone number area codes. For both of these scenarios Meta feed this information back into their system for other uses.
- Your contacts, and all metadata are taken by Meta for their usual purposes.
- Any kind of status update is immediately provided to Meta. Whatsapp's E2EE applies to only a specific subset of the app's functions.
- There are a range of automatically collected pieces of information that the app provides whatsapp, anecdotal evidence also indicates that whatsapp reports back conversation keywords. Such reporting usually presents unseen security risks to users.
Meta have been attempting to dilute the conversation about privacy and security by providing sly talking points for how their products are "private" and "secure". For example: They have stated that facebook is private because their servers are well maintained against hackers. They're currently heavily advertising whatsapp as secure because it offers E2EE messaging - neither of these statements address the underlying issue with Meta: it's an advertising company based on invasive data collection. Meta build profiles on users which are unacceptably detailed, we wouldn't trust our own elected representatives with such detailed profile building.
As with all jokes though, I think there's an element of truth to it. May not be independent fact checkers, but discussion in this thread covers the iMessage comparison and I wouldn't say it's as clear cut as Zuckerberg would like to make out.
I see problems with this setup. The central server is responsible for relaying communication since there is no directly link between those trying to communicate. It is also responsible for handing out public keys. It is literally a man in the middle. What is stopping the central server from lying about the public keys? What is stopping the server from decrypting everything?
Hopefully my understanding of this is wrong. It is certainly incomplete.
But of course, this is why I use Signal instead. If I'm going to use a 3rd party app, why not use one that is actually secure.
So I guess when Zuck talks about security that doesn't include privacy.
(I know we should have more substantive comments, but honestly, anything Mark says, I assume is false on its face)
Founding the fastest $1 trillion dollar company in the 21st century sounds like what a product visionary would make and Zuckerberg is undisputed over that claim, while many have told him the Instagram purchase was a mistake, after finding another billion users again.
The proclaimed death of Meta Platforms. Inc has been greatly exaggerated (again).
Everday I ask this question to myself. Will the world a better place without Facebook and Instagram?
Eh?
https://www.statista.com/statistics/264810/number-of-monthly...