The frustrating part is people making claims about issues where they don't actually have datapoints to back it up. I try to avoid doing that.
The frustrating part is people making claims about issues where they don't actually have datapoints to back it up. I try to avoid doing that.
When it comes to security, the default assumption is always to assume any system is not secure unless it can be proven that it is with a reasonable level of certainty. In the case of Whatsapp, that level of proof is not there. We have to assume it is insecure. If Whatsapp released their client's code, that problem would go away.
I'm just humbly asking people to be clear about what they know vs what they assume.
If it was open source that still wouldn’t prove much, see e.g. https://mobile.twitter.com/taviso/status/1263957627077226498 for a discussion on reproducible builds.
The recent OpenSSL vulnerabilities were in there for over a year before they were discovered. Theoretically Signal or an open source version of WhatsApp could have a bugdoor, which would not be found for as long or longer.
Sure, it’s way nicer when stuff is open source, but I’m not sure it’d change much in this regard.
(IMO there are many good reasons to dislike WhatsApp/meta. I just think your argument is flawed.)