https://en.wikipedia.org/wiki/WhatsApp#FBI
https://en.wikipedia.org/wiki/Reception_and_criticism_of_Wha...
you should use Signal.
https://en.wikipedia.org/wiki/WhatsApp#FBI
https://en.wikipedia.org/wiki/Reception_and_criticism_of_Wha...
you should use Signal.
It's super frustrating that every single time WhatsApp is mentioned on Hacker News, someone boldly makes a claim that it's not encrypted based on hearsay or hunches.
1- https://faq.whatsapp.com/791574747982248/?locale=en_US 2 - https://www.whatsapp.com/privacy
Without going into too much detail, I can tell you a huge challenge with encrypted backups is compliance - many people simply do not opt-in to using encrypted backups. It's a difficult line to walk because ultimately you don't want to pester users too much about using encrypted backups either. In case it's not clear, the reason it requires opt-in is because you (i.e., the user) control the encryption keys and therefore you must take some action to write down a key or passphrase. As you may imagine, the average messaging app user is not as tech savvy as the average Hacker News user and many simply don't want to go through this extra step. Even worse, if they opt-in to encrypted backups and lose their keys, they will end up blaming Meta for not giving them a way to restore their message history when their phone gets lost (it's not easy to explain that it's your responsibility as the user to keep your keys safely stored).
Signal on the other hand sides on the side of security so much that it makes the app purposefully less useable, e.g. with their pin feature. But it doesn't have this backup problem. It's not a situation that has an easy solution atm.
But I think it's important to note that the belief of many users is wrong that end-to-end encryption implies that message content is unavailable to governments unless they get unlocked access to devices of communication partners.
You only address OP's first "bold" claim. You've sidestepped the rest. I wonder why.
> I've worked at Meta...
Ah, I see. Super frustrating, indeed.
The frustrating part is people making claims about issues where they don't actually have datapoints to back it up. I try to avoid doing that.
When it comes to security, the default assumption is always to assume any system is not secure unless it can be proven that it is with a reasonable level of certainty. In the case of Whatsapp, that level of proof is not there. We have to assume it is insecure. If Whatsapp released their client's code, that problem would go away.
I'm just humbly asking people to be clear about what they know vs what they assume.
If it was open source that still wouldn’t prove much, see e.g. https://mobile.twitter.com/taviso/status/1263957627077226498 for a discussion on reproducible builds.
The recent OpenSSL vulnerabilities were in there for over a year before they were discovered. Theoretically Signal or an open source version of WhatsApp could have a bugdoor, which would not be found for as long or longer.
Sure, it’s way nicer when stuff is open source, but I’m not sure it’d change much in this regard.
(IMO there are many good reasons to dislike WhatsApp/meta. I just think your argument is flawed.)
or out of date. read the terms of use for business accounts, which are everywhere now. it clearly says that metabook have access to any message exchanged with a business account on whatsbook.
...and I'm not sure about groups. there are data leaks for media in groups that were dismissed as features a while ago, not just metadata. well, i think they called media ids that identify content as metadata or something. not following whatsbook closely lately.
For someone who is "not following whatsbook closely lately" that is again a bold claim to make.
But anyway, business messages are also encrypted. Businesses are allowed to designate other accounts to receive messages, in which case those other accounts are sent copies of those messages using a different key. It's similar to sending messages to multiple devices. This is disclosed [1] and needed to support things like auto responders.
Group chats are also encrypted using a shared sender key and this is described in the whitepaper starting page 10 [2]
1 - https://faq.whatsapp.com/567302067179554/?locale=en_US 2 - https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...
Whatsapp/Meta claim so, but have no proof. As with your comment, without proof we can't be convinced.
> The other tech giant that can be compelled by law enforcement to hand over potentially large amounts of sensitive messaging data is Apple. iMessage, Apple’s text-message service, comes loaded on the iPhone and is used by 1.3 billion people worldwide. According to the FBI’s “Lawful Access” guide, if served with a court order or a search warrant, Apple must hand over basic subscriber information as well as 25 days’ worth of data about queries made in iMessage, such as what a targeted user looked up in iMessage and also which other people searched for that targeted user in the app. That doesn’t include actual message content or whether messages were exchanged between different users.
That doesn't sound like the police have real time access to Apple Messages at all. I believe they still have access to unencrypted backups, which is not real-time.
[1]: https://www.rollingstone.com/politics/politics-features/what...
Didn't they work with the Signal team for their e2e encryption of messages and calls? Are you saying that they've removed that despite showing the opposite at the beginning of of every new conversation?
https://www.rollingstone.com/politics/politics-features/what...
It’s whitewashed surveillance via automated loopholes
Although nothing indicates that Facebook currently collects user messages without manual intervention by the recipient, it's worth pointing out that there is no technical reason it could not do so. [...] An "end-to-end" encrypted messaging platform could choose to, for example, perform automated AI-based content scanning of all messages on a device, then forward automatically flagged messages to the platform's cloud for further action.
https://signal.org/bigbrother/central-california-grand-jury/
The subpoena asks for "all correspondence with [these] users". I am not a lawyer, so I don't know if that gave enough wiggle room for Signal to not provide metadata, or if they don't store it in the first place.
The reality is, sending information is a multi-layered thing. There's the message contents, the message metadata, and the network that the message is sent on. All of which are subjected to different levels of privacy. Each of those things can be used to spy on you, to abuse your rights, and to generally invade your life in ways that most would consider to be inappropriate. Which leads to the obvious conclusion that e2e encryption of the messages is only a portion of the issue. By using WhatsApp, you're trusting Meta corp as arbiter of all of these pieces and their implementations. Which is obviously, given everything the Zuck has ever leaked from his mouth piece, is not a great choice.
Mind enlightening the rest of us?
As someone whose threat model does not yet involve law enforcement, I'll stick to my own preferred platforms, thank you very much.
some other people mention flaggging when sender or recipient send message for moderation, which has absolutely nothing to do with encryption or safety, obviously if YOU have access to message then you can forward it to whoever you want
Sounds as legit as when Facebook asked people to upload nudes of themselves so they would know what to block :-$
absolute and utter nonsense. WhatsApp literally uses Signal's encryption protocol and messages leave your device encrypted. The only thing WhatsApp has access to is metadata.
if you're going to make an accusation like this I suggest you back it up.
I also think it was in the news a few months back and I even think it was discussed here.
Edit: note, I am not saying messages aren’t always sent E2E-encrypted between users today, only that in some cases they are also sent in a side channel to Facebook simultaneously.
Edit 2:
You can try this search: https://duckduckgo.com/?q=does+whatsapp+sometimes+send+messa...
Or read this article: https://nypost.com/2021/09/07/facebook-reads-and-shares-what...
Edit 3: this is of course on top of the fact that they uploaded the backups (from everyone who enabled backups) unencrypted to Google under terms that let Google sift through it.
> A WhatsApp spokeswoman told The Post: “WhatsApp provides a way for people to report spam or abuse, which includes sharing the most recent messages in a chat. This feature is important for preventing the worst abuse on the internet. We strongly disagree with the notion that accepting reports a user chooses to send us is incompatible with end-to-end encryption.”
Are you somehow expecting e2e encryption to mean "incapable of being copied"? Once the user receives a message if they think "OMG this message is horrible!" of course they can send a copy of that message to WhatsApp... it's their data to send!! Technology not only can't it shouldn't attempt to prevent what that user can do with their data once it is on their phone, and while I'd prefer more localized block mechanisms be put into place it doesn't violate security to implement some weird "if the user you spoke with is an asshole and wants to send a copy of your message to Facebook, they should get to do so" feature.
(Also, your third edit is just silly: the user enabled backups and backups don't even automatically enable. The way backups work was always disclosed, and if you didn't want to enable backups DON'T ENABLE BACKUPS. But, the thing to appreciate is that these are YOUR MESSAGES: if you think it makes sense to have a backup copy on Google's server you should 100% get to do that, just as you should get to screenshot them and upload them to Twitter. Would it have been better to build an encrypted backup feature? Sure... and they eventually did! Would you have simply preferred them to not implement a backup mechanism at all?! Just because someone hasn't gotten around to something doesn't mean they are evil. Technology should not prevent users from doing whatever they want with their data.)
We need e2ee so that companies cannot profile entire populations using the content of their messages (they can still do a lot with metadata, admittedly).
That did sound like saying "it would be better to make encryption the standard", didn't it?
If I'm wrong (very possible!) please explain exactly what I have wrong here.
As for Signal, I have an account and use it with a few people. But until the day comes when my other several hundred contacts switch to Signal, I don't have much of an option.
Message metadata is available to Meta. All I can say is.. if your threat model has to account for metadata like this than you have a whole lot more to account for than just WhatsApp or Signal.