Could you please elaborate why (in detail)?
Why the surprise?
Meta has access to the folder it manages in the user's Google Drive. That's obvious, otherwise they wouldn't be able to write to it.
They have indirect control over the user’s backup folder via the app, but meta would need to distribute a malicious update to everyone that causes the user’s apps to download the backup and send it to meta, at which point they could just skip trying to access the backup and directly upload the chats from the app.
It’s impressive how much misinfo you’re spreading.
Edit: Meta’s actions over the years clearly show that they don’t want to know the contents of your messages. Not knowing their contents means, for example, that they don’t have to run scanners to detect illegal content (but users can report messages). They benefit from making WhatsApp a secure platform, as it allows them to collect everyone’s metadata, which apparently has lots of value to them.
Haha. That's a great proof! Not the closed source, not the proprietary protocol they use to talk with their server, but their FAQ.
> They have indirect control over the user’s backup folder via the app, but meta would need to distribute a malicious update to everyone
Please give us the results of your research when you reverse-engineered Meta's apk to prove your point as this is what you think others should do. Otherwise it is just big talk.
"oh but if that was the case you would get rich reporting it!". More low IQ reasoning. You will get sued to death, I know people that did so and now have to waste time and money with the legal system.
They probably do all kinds of horrible stuff with the metadata. I’m honestly too lazy to read the privacy policy. But I have yet to see critique of their e2ee that’s actually backed up by substance instead of people’s imaginations.
You certainly can “prove” and “disprove” “security” by reverse engineering, to the same extent a source code review can (or even more, since you’re looking at what’s actually running on the device). It can often require a bigger time investment, but even that’s not always the case in my experience, especially if you’re working with a really bad code base.
this is facebook. they're data-mining pictures of your dog for money. I don't think privacy/safety is expectable with meta
WhatsApp uses the Signal protocol[1], so the text is never plaintext on the wire (or servers).
Especially if they do it every day/most days, having the option to see what you wrote "on this day" 2-3 years back is great. Especially when I try to include people's names who I was interacting with (but who are easy to forget 3 years later). It can be a nice reminder to text them and say you were "just randomly", unprompted, thinking about them -- 'How's it going?'
Fantastic that you've set it up for yourself.