Communities Now Available
blog.whatsapp.com
blog.whatsapp.com
I'm not sure how I feel about this. I like apps with a singular purpose, that do one thing well. This feels like it's going to intrude on my peace of mind with big, distracting groups that broadcast low quality, high volume information.
> Communities like neighborhoods, parents at a school, and workplaces can now connect multiple groups together under one umbrella to organize group conversations on WhatsApp.
http://www.paulgraham.com/quotes.html?viewfullsite=1#:~:text...
- Option to block/filter/hide people within a group. This way I can mute inconsiderate jerks from groups I can’t leave (work/family);
- alternatively, option to mute and hide groups forever, no I don’t want a red dot to signal there’s new message. I want it completely hidden until I casually remember to check it;
- hide my online status
These three action points would alleviate all my pain points with their platform.
Unfortunately, I’m not confident they will give me this kind of control as this would be anathema to Meta core values: controlling their (product|user) and increasing engagement on their app to the expense of the user mental health.
You can do this by archiving the groups, they will only appear if you go in the archived chats tab and won't notify you.
> - hide my online status
You can already do this in the Privacy options.
> - Option to block/filter/hide people within a group. This way I can mute inconsiderate jerks from groups I can’t leave (work/family);
This is honestly stupid, there's no way you will be able to follow a conversation where some people's messages aren't displayed. Leave your family groups and refuse to use WhatsApp for work.
Whoa, that’s new! Thank the Lord.
No you can't, read again, I *don't* want a red dot signalyzing there's new messages on my archive.
> You can already do this in the Privacy options.
Unless you're in some A-B test I definetely don't have this option on my Privacy setting. Just Triple checked.
> This is honestly stupid, there's no way you will be able to follow a conversation where some people's messages aren't displayed.
The hot take is: I don't need to follow any conversation that includes those individuals. But I need to follow notices, and important information regarding my job.
How about hide behind a notice: "You mutted this person, click here if you want to read the message anyway.". There, some middle ground.
> Leave your family groups and refuse to use WhatsApp for work.
I'm not even sure how to respond to this, if you're privilleged enough to say this, good for you. I'm definetely not.
I had never used the feature a lot so I didn't know what was the behavior.
I just tested, there's no red dot, it just shows you the number of unread messages, which is really not attention catching (I actually had 2 unread messages there for months and had never noticed before).
> Unless you're in some A-B test I definetely don't have this option on my Privacy setting. Just Triple checked.
https://i.imgur.com/GRLMjGh.png
Just took this screenshot. It's also not new, my girlfriend has been using it for years.
> I'm not even sure how to respond to this, if you're privilleged enough to say this, good for you. I'm definetely not.
I can't see any demographic that can't afford to leave a family discussion on WhatsApp, especially one with people that they don't want to talk to.
As for work conversations, unless you work a job where you're not on a computer all day, which is probably less than 1% of the commenters of HN, there is a more work-appropriate tool for communication that your company is already using.
> https://i.imgur.com/GRLMjGh.png
> Just took this screenshot. It's also not new, my girlfriend has been using it for years.
Can confirm this privacy option existed since I installed WhatsApp on my brand new LG G2 back in 2014. I turned it on then right away and never turned it off in all the years and phones I've had since.
The price for people not seeing your "last seen" status, is that you don't see other's people's "last seen" status. Which is fine by me.
Unless new configuration options may appear without an update, it is not "brand new". I just checked and I have that option, and I updated WhatsApp in August 14, when I was forced to do so. My version is 2.22.16.75.
https://www.livemint.com/technology/tech-news/whatsapp-bring...
That is indeed how WhatsApp seem to have been rolling out features recently.
Never seen this before - but I have it as well! It must have been added in the last 6 months or so for me... Thanks for pointing it out :-)
If someone from one of the groups confront you/GP about leaving, you can always say "I was restoring from backup and it looked like something went wrong!"
Do not disturb times (say 7pm to 6am)
Delete all media in a chat/group
Write-protect groups-- to avoid accidentally sending stuff to contacts or groups where you don't usually send anything (involuntary groups for work or family)
Alternatively- permanently disable mic and camera access to groups.
Thats what you would think from a technical point of view, but actually I witnessed some drama with people installing Telegram, because the partner thought it was done only for this "secret chat" option, which seems to be popular for people having affairs. As it leaves no trace on the phone. Most people don't care about the NSA. They care about their partner, or parents spying on them (which says a lot about the integrity of those relationships).
Haha, real secret agents forgot Top Secret documents in the subway or alike.
Normal people absolutely forget to do this.
Telegram has about half a billion monthly active users, I think that qualifies as a decent user base
Even if that were truth I know pretty much nobody who has it, while I think I dunno single person who wouldn't have Whatsapp, so I assume majority of those Telegram users are concentrated in few countries lika Russia, Iran etc. or in some specific social circles, which I am not part of.
Edit: you might also be onto something with the "specific social circles" part of the comment.
It is maybe like Google+: from the outside it looked like a ghost town, while inside it was beautiful.
You may go by Google Play Store installations. With about ~1.5 billion installs that's about a third to a quarter of WhatsApp installations. WhatsApp claims about two billion active users, so that seems about right.
Or is this something new?
Does anyone have any examples or experience with platforms that pulled off that transition space successfully? And what were the key features that made the transition successful?
More importantly Meta owns astounding amounts of undersea cable, which lends credence to the idea they are the new 'cable and wireless'... https://fairinternetreport.com/research/facebook-meta-submar...
> Today (..) we’ve started to roll out Communities (..) globally and this will be available to everyone over the next few months.
https://en.wikipedia.org/wiki/WhatsApp#FBI
https://en.wikipedia.org/wiki/Reception_and_criticism_of_Wha...
you should use Signal.
Didn't they work with the Signal team for their e2e encryption of messages and calls? Are you saying that they've removed that despite showing the opposite at the beginning of of every new conversation?
https://www.rollingstone.com/politics/politics-features/what...
It’s whitewashed surveillance via automated loopholes
Although nothing indicates that Facebook currently collects user messages without manual intervention by the recipient, it's worth pointing out that there is no technical reason it could not do so. [...] An "end-to-end" encrypted messaging platform could choose to, for example, perform automated AI-based content scanning of all messages on a device, then forward automatically flagged messages to the platform's cloud for further action.
https://signal.org/bigbrother/central-california-grand-jury/
The subpoena asks for "all correspondence with [these] users". I am not a lawyer, so I don't know if that gave enough wiggle room for Signal to not provide metadata, or if they don't store it in the first place.
The reality is, sending information is a multi-layered thing. There's the message contents, the message metadata, and the network that the message is sent on. All of which are subjected to different levels of privacy. Each of those things can be used to spy on you, to abuse your rights, and to generally invade your life in ways that most would consider to be inappropriate. Which leads to the obvious conclusion that e2e encryption of the messages is only a portion of the issue. By using WhatsApp, you're trusting Meta corp as arbiter of all of these pieces and their implementations. Which is obviously, given everything the Zuck has ever leaked from his mouth piece, is not a great choice.
Mind enlightening the rest of us?
> The other tech giant that can be compelled by law enforcement to hand over potentially large amounts of sensitive messaging data is Apple. iMessage, Apple’s text-message service, comes loaded on the iPhone and is used by 1.3 billion people worldwide. According to the FBI’s “Lawful Access” guide, if served with a court order or a search warrant, Apple must hand over basic subscriber information as well as 25 days’ worth of data about queries made in iMessage, such as what a targeted user looked up in iMessage and also which other people searched for that targeted user in the app. That doesn’t include actual message content or whether messages were exchanged between different users.
That doesn't sound like the police have real time access to Apple Messages at all. I believe they still have access to unencrypted backups, which is not real-time.
[1]: https://www.rollingstone.com/politics/politics-features/what...
If I'm wrong (very possible!) please explain exactly what I have wrong here.
As for Signal, I have an account and use it with a few people. But until the day comes when my other several hundred contacts switch to Signal, I don't have much of an option.
Message metadata is available to Meta. All I can say is.. if your threat model has to account for metadata like this than you have a whole lot more to account for than just WhatsApp or Signal.
As someone whose threat model does not yet involve law enforcement, I'll stick to my own preferred platforms, thank you very much.
some other people mention flaggging when sender or recipient send message for moderation, which has absolutely nothing to do with encryption or safety, obviously if YOU have access to message then you can forward it to whoever you want
Sounds as legit as when Facebook asked people to upload nudes of themselves so they would know what to block :-$
absolute and utter nonsense. WhatsApp literally uses Signal's encryption protocol and messages leave your device encrypted. The only thing WhatsApp has access to is metadata.
if you're going to make an accusation like this I suggest you back it up.
I also think it was in the news a few months back and I even think it was discussed here.
Edit: note, I am not saying messages aren’t always sent E2E-encrypted between users today, only that in some cases they are also sent in a side channel to Facebook simultaneously.
Edit 2:
You can try this search: https://duckduckgo.com/?q=does+whatsapp+sometimes+send+messa...
Or read this article: https://nypost.com/2021/09/07/facebook-reads-and-shares-what...
Edit 3: this is of course on top of the fact that they uploaded the backups (from everyone who enabled backups) unencrypted to Google under terms that let Google sift through it.
> A WhatsApp spokeswoman told The Post: “WhatsApp provides a way for people to report spam or abuse, which includes sharing the most recent messages in a chat. This feature is important for preventing the worst abuse on the internet. We strongly disagree with the notion that accepting reports a user chooses to send us is incompatible with end-to-end encryption.”
Are you somehow expecting e2e encryption to mean "incapable of being copied"? Once the user receives a message if they think "OMG this message is horrible!" of course they can send a copy of that message to WhatsApp... it's their data to send!! Technology not only can't it shouldn't attempt to prevent what that user can do with their data once it is on their phone, and while I'd prefer more localized block mechanisms be put into place it doesn't violate security to implement some weird "if the user you spoke with is an asshole and wants to send a copy of your message to Facebook, they should get to do so" feature.
(Also, your third edit is just silly: the user enabled backups and backups don't even automatically enable. The way backups work was always disclosed, and if you didn't want to enable backups DON'T ENABLE BACKUPS. But, the thing to appreciate is that these are YOUR MESSAGES: if you think it makes sense to have a backup copy on Google's server you should 100% get to do that, just as you should get to screenshot them and upload them to Twitter. Would it have been better to build an encrypted backup feature? Sure... and they eventually did! Would you have simply preferred them to not implement a backup mechanism at all?! Just because someone hasn't gotten around to something doesn't mean they are evil. Technology should not prevent users from doing whatever they want with their data.)
We need e2ee so that companies cannot profile entire populations using the content of their messages (they can still do a lot with metadata, admittedly).
That did sound like saying "it would be better to make encryption the standard", didn't it?
It's super frustrating that every single time WhatsApp is mentioned on Hacker News, someone boldly makes a claim that it's not encrypted based on hearsay or hunches.
1- https://faq.whatsapp.com/791574747982248/?locale=en_US 2 - https://www.whatsapp.com/privacy
Without going into too much detail, I can tell you a huge challenge with encrypted backups is compliance - many people simply do not opt-in to using encrypted backups. It's a difficult line to walk because ultimately you don't want to pester users too much about using encrypted backups either. In case it's not clear, the reason it requires opt-in is because you (i.e., the user) control the encryption keys and therefore you must take some action to write down a key or passphrase. As you may imagine, the average messaging app user is not as tech savvy as the average Hacker News user and many simply don't want to go through this extra step. Even worse, if they opt-in to encrypted backups and lose their keys, they will end up blaming Meta for not giving them a way to restore their message history when their phone gets lost (it's not easy to explain that it's your responsibility as the user to keep your keys safely stored).
Signal on the other hand sides on the side of security so much that it makes the app purposefully less useable, e.g. with their pin feature. But it doesn't have this backup problem. It's not a situation that has an easy solution atm.
But I think it's important to note that the belief of many users is wrong that end-to-end encryption implies that message content is unavailable to governments unless they get unlocked access to devices of communication partners.
You only address OP's first "bold" claim. You've sidestepped the rest. I wonder why.
> I've worked at Meta...
Ah, I see. Super frustrating, indeed.
The frustrating part is people making claims about issues where they don't actually have datapoints to back it up. I try to avoid doing that.
When it comes to security, the default assumption is always to assume any system is not secure unless it can be proven that it is with a reasonable level of certainty. In the case of Whatsapp, that level of proof is not there. We have to assume it is insecure. If Whatsapp released their client's code, that problem would go away.
I'm just humbly asking people to be clear about what they know vs what they assume.
If it was open source that still wouldn’t prove much, see e.g. https://mobile.twitter.com/taviso/status/1263957627077226498 for a discussion on reproducible builds.
The recent OpenSSL vulnerabilities were in there for over a year before they were discovered. Theoretically Signal or an open source version of WhatsApp could have a bugdoor, which would not be found for as long or longer.
Sure, it’s way nicer when stuff is open source, but I’m not sure it’d change much in this regard.
(IMO there are many good reasons to dislike WhatsApp/meta. I just think your argument is flawed.)
or out of date. read the terms of use for business accounts, which are everywhere now. it clearly says that metabook have access to any message exchanged with a business account on whatsbook.
...and I'm not sure about groups. there are data leaks for media in groups that were dismissed as features a while ago, not just metadata. well, i think they called media ids that identify content as metadata or something. not following whatsbook closely lately.
For someone who is "not following whatsbook closely lately" that is again a bold claim to make.
But anyway, business messages are also encrypted. Businesses are allowed to designate other accounts to receive messages, in which case those other accounts are sent copies of those messages using a different key. It's similar to sending messages to multiple devices. This is disclosed [1] and needed to support things like auto responders.
Group chats are also encrypted using a shared sender key and this is described in the whitepaper starting page 10 [2]
1 - https://faq.whatsapp.com/567302067179554/?locale=en_US 2 - https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...
Whatsapp/Meta claim so, but have no proof. As with your comment, without proof we can't be convinced.
Does anyone else find these soft-launches irritating? Give us a date?
Instead, I think their inspiration has come from alternatives like Discord where multiple chat rooms within a group of people is part of the core app design.
I'd like them to copy the spaces feature, though, because it's quite useful to me personally.