“We do not track your *PRECISE* location, we don’t keep logs of who everyone is messaging and we do not track the *PERSONAL* messages people are sending one another," it added. “We do not provide *BULK* information to any government.”
“We do not track your *PRECISE* location, we don’t keep logs of who everyone is messaging and we do not track the *PERSONAL* messages people are sending one another," it added. “We do not provide *BULK* information to any government.”
There's also supposedly a key transparency service deployed (similar to Certificate Transparency), but I haven't looked into that in detail.
Would you even know if you got a special copy of Whatsapp (still signed by Meta and valid) that has this explicit code?
Absolutely for archiving: https://androidapks.com/whatsapp-messenger/com-whatsapp/old/
Reverse engineering to some extent as well – it's an extremely popular app, and as such attracts both security researchers and bloggers that just want to get scoops on new features behind feature flags etc.
> Would you even know if you got a special copy of Whatsapp (still signed by Meta and valid) that has this explicit code?
Given the above, it's feasible – at least on Android, it's fairly easy to hash the .apk you've received and compare it to publicly know versions.
The threat of somebody finding unusual code on their phone will probably not deter targeted deploys by sophisticated/state level actors to specific users, but it goes some way towards making it implausible that everybody is running a backdoored version, potentially backdoored by Meta themselves, which is arguably the goal.
The shit app has 60 MiB compressed. I was not even able to find where in the code it works with the damn secrets it uses for TOTP.
Now do WhatsApp with its zillion features.
If you mean that it's hard to explain away for the devs themselves, then people do much worse things in this world, and are able explain it to themselves just fine as something good, even.
https://transparency.meta.com/reports/government-data-reques...
They can't see your messages but then can give ips or accounts that can be inferred to be related given the info meta has access to
The backdoor in Lotus Notes (differential cryptography) wasn't a secret. It was public information. Ray Ozzie used it as a way to circumvent US encryption export laws. Today companies have to be more discrete.
[1] http://www.cypherspace.org/adam/hacks/lotus-nsa-key.html
Camera: https://www.bitdefender.com/en-us/blog/hotforsecurity/facebo...
Audio: https://news.ycombinator.com/item?id=41424016
Conversations: https://www.vice.com/en/article/facebook-said-it-wasnt-liste...
Mass surveillance: https://thehill.com/video/facebook-spying-on-users-new-repor...
Across the web: https://www.wired.com/story/ways-facebook-tracks-you-limit-i...
Beacon: https://www.wired.com/2007/12/facebook-ceo-apologizes-lets-u...
Apps: https://www.theguardian.com/news/2018/mar/17/cambridge-analy...
People who aren't even on facebook: https://www.vox.com/2018/4/20/17254312/facebook-shadow-profi...
Others do it too, e.g. Amazon: https://www.bloomberg.com/news/articles/2019-04-10/is-anyone...
But Facebook has always been on a whole other level
https://www.theguardian.com/technology/2018/apr/17/facebook-...
The alternatives are also probably up to the same sketchy shit, so your choices are to be a hermit, or accept that your services will spy on you.
If you want to participate in society, you have to either trust a very large list of untrustworthy people... Or acknowledge that they are untrustworthy, and mitigate accordingly. Part of that mitigation is accepting the possibility that if the Mossad want to murder you by blowing up your toaster, nobody's going to stop them.
There's social media use and there's social media use. Hacker News, Reddit, Facebook, Instagram, Whatsapp, EMail, and my phone's SMS systems all serve dramatically different purposes, and all of them are a varied mix of pros and cons and risks.
---
[1] Any Arcanist worth his salt knows that copper has no name, and thus cannot be turned against you.
I do, however, believe that you aren't engaging with what I'm saying, or recognizing some very obvious logical holes in your arguments. Your argument seems to be one of dogma, not one of reason.
Sure, I can also avoid putting chemicals on my body by washing my hair with apple cider vinegar and baking soda, and I can also churn my own butter by hand…
There are a lot more of them, and they are kind of integral to its meaning.
jokes aside, I did read your entire post and I don’t disagree with a single word you wrote. I still don’t understand why anyone in their right mind would install a Meta-owned application on their PHONE. Lots of people overall and number on this thread go with “hey, the GOVERNMENT is already spying on you so why don’t I also let one of the most evil corporations in the history of mankind access to all my everything too… I don’t expect privacy in general, it is 2025 after all and we are talking on HN but these silly “plate reader excuses” are really too much… like saying “well the government can obviously break into my home whenever they want (in 2025 without a warrant as well) so why don’t I leave the door wide open, if government can enter why would I care if someone else does :)
> I have been off social media for years now and my life and health and relationships and career and … have improved so much I cannot put it in words.
It sounds like you personally had a problem. Congratulations I suppose on solving it. However, I have no such issues. My life, health and relationships are all already where I want them to be, and are not impacted by occasional interaction with others through technology as luckily, I have had no such struggles with self control or moderation.
My relationships would be impacted on the other hand if I was to throw a big toddler tantrum about using whatsapp for two weeks whilst i'm overseas with my employer and twenty other people. So i'm probably not going to do that.
People are not accepting that possibility, they are assuming it will not happen to them and that they are not a target of interest.
Change that assumption and attitudes toward privacy also change.
Imagine that times a billion.
That ends with them mostly not communicating with me, not with them switching apps.
If you think that your phone provider isn't spying on you, I would like to cut you into an incredible, once-in-a-lifetime investment opportunity in some Louisiana waterfront property.
All I need is your phone number, mother's maiden name, ...
https://www.nbcnews.com/tech/security/chinese-hackers-stole-...
Nor the inability to add people to groups. sms doesn't have groups; it has pools of numbers. And it works terribly when, eg, one of you is traveling or living outside the US.
You're definitely in a minority. Most people send and receive zero non-MFA related SMS.
Are you going to suggest to me that I should force them onto Signal and a pile of other DIY platforms? I dare you. Look a burned out parent in their bloodshot eyes first.
- tell parents and teachers I can be reached at xxx-xxx-xxxx if they need anything
- absolutely never had meta-requirement to volunteer. if I did I would 100% know my time there is better spent elsewhere
I am not going to suggest you anything except to tell you that you can live a beautiful live outside of the meta-world. it is super easy
Great it is super easy for you, but why do you think your individual experience is valid for other people (who might be thousands of km away in a very different setting)?
I have three kids. Sure it's not easy, buying used local things is basically impossible, but it's not terribly hard. You just work around it
Eventually, I decided to step away. This was partly because I was not willing to engage more deeply just to make the platform work properly, and partly because of personal circumstances, such as having twins. After deleting my account, I noticed a significant reduction in stress.
These days, my children’s kindergarten uses a dedicated app to communicate with parents, and their sports club uses another (Spond, which seems fairly common in Norway). However, when I try to connect more informally with other parents, the conversation almost always leads back to Facebook, Messenger, or "insta". Even when people express understanding or sympathy for my choice to avoid those platforms, exchanging phone numbers or using alternatives rarely leads to real communication. It feels as if, socially, I cease to exist if I am not part of those groups.
So no, I would not suggest trying to push others onto Signal or similar platforms. I relate to your experience completely. Although we may have made different choices, the underlying challenge is the same: wanting to participate meaningfully, but finding that the tools we're expected to use often come with a cost we are not willing to pay.
For the second one in particular, Meta never listened to anyone's mic. I would know, I worked on this stuff there at that time.
Do you consider misrepresentation a lie?
If there's a lawsuit which determines that Meta misrepresented something, do you consider that a lie, even if Meta says it was merely on honest mistake made in good faith?
If the European Commission "fines Facebook €110 million for providing misleading information about WhatsApp takeover" and that "contrary to Facebook's statements in the 2014 merger review process, the technical possibility of automatically matching Facebook and WhatsApp users' identities already existed in 2014, and that Facebook staff were aware of such a possibility" then that statement was not actually a lie, right, because no one at Facebook said they lied, correct?
Can you give an example of any company which has lied, but where the company officials have never agreed with that conclusion?
There is a long history in the US of companies having to pay a fine but never accepting responsibility. https://knowledge.wharton.upenn.edu/article/paying-a-fine-bu...
Large public companies do not lie very often because it's incredibly easily for lies to be discovered, and the penalties are high. There are many examples where the popular narrative is the the company lied, but when you look at details it becomes clear that no lying occurred.
For example, David Rainey probably did not actually lie about the extent of the BP oil spill even though most people still believe he did. He was acquitted by a jury who had access to far more information, and more time to think about it, than anyone else.
They even paid them to do transcribe chats: https://www.bloomberg.com/news/articles/2019-08-13/facebook-...
And this is just the publicly known stuff. So perhaps you weren’t privy to everything?
So Facebook (not Meta at the time) just “forgot” to turn off the camera after they were done with it? Sounds reasonable… except wait, they were actively re-activating it while you were scrolling, and until iOS 14 users were none-the-wiser. If it was an honest mistake, do you think FB testers would have not caught it during the MONTHS between iOS 14 developer preview and release? And yet, for this one I do think it was probably a bug about when to activate the camera.
https://medium.com/macoclock/apples-ios-14-catches-facebook-...
You're confusing the audio calls with secretly listening to microphone, which never happened
People did find out.
Imagine if Snowden decided to just do his work and move on? How much longer would it have taken for these facts to be revealed to the public?
So literally no downside to putting a backdoor and lying about it
Just like lots of people want universal healthcare, a clean environment, an arms embargo on Israel, affordable housing and education, etc.
It can hard to believe these are majority views sometimes, but that's what you get when the entire media landscape is owned by like 10 people.
And you're not even talking about Meta
The bragging wasn't about their lawyers' ability in court, it was about their lawyers' ability to draft Terms and Conditions such that they could not be caught in a lie.
And yes, not Meta in this story, but come on.
The privacy settings also did not obviously do what their wording suggested - accidental over-sharing was their goal, and the wording was carefully crafted to deceive and confuse. Is that lying? It's a technical argument, and not really relevant - they are shady AF and always have been.
They are also uttered on TV, in public talks and to a far lesser extent in court. Court is a formal process. Outside it's not. There's a big difference.
But the statement itself is technically not a lie, they did say “upto”, lol. That is how corporate speak works
The European Commission has found that Facebook provided “misleading information” about its 2014 takeover of WhatsApp following an investigation into the deal.
The commission’s complaint relates specifically to the sharing of user data between Facebook and WhatsApp. In a submission to the EU made in August 2014, Facebook said it would not be possible to create a reliable automated system for matching users. In August 2016, WhatsApp announced that it would be linking WhatsApp user phone numbers with Facebook user identities.
The fact that they successfully got the book removed from sale for a while speaks volumes. They not only lie they are encouraged to.
It is rather shocking seeing how rapidly the US is shifting from all of its historic norms. Trump sees the US as a "store" where he dictates the terms, he directly has control over US Steel after the Nippon Steel "takeover" -- straight out of the communist central control dictums -- and now US major corporations are embedded in the US military.
It is insane. This is stuff people accused China of for time eternal but apparently it was taken as a good lesson to learn from.
But absolutely no one outside the US -- whether enemies or allies -- should trust anything from US corporations now. The country has fallen.
group messages and messages (metadata),
messages to business accounts (these they can read in full as the client send to a meta owned private key),
and who forwards media to who (deduplication and cdn)
and links (thanks to previews)
and it scans and uploads your contact list in full all the time.
The real question is where they draw the line, not if they do it ever.
When you use credit or debit cards your transactions and data related to it is collected and sold. When you apply for mortgages and close on a house all that information you put in there is collected and sold.
When you put your address in for the post office, when you apply for a drivers or fishing license... Your local governments collect that information and sell access to it.
Meta tries to then tie in your online and app/phone activity with your legal/financial identity it can obtain through partner data brokers.
This is Facebook's businesses model.
So, yes, this data is available to pretty much anybody that is willing to pay for it. Which includes governments.
None of this should be surprising to anybody at this point. Apple, Google, Microsoft, etc.. all of these companies will do this to greater or lesser extents nowadays since has worked out so well for Meta's bottom line.
Now I don't know the exact details of which governments had which access (was it just for warrants, which nations, what was the line between actual terrorist versus persecuting journalists), but there was absolutely bulk export and the fact that they are lying about it makes me inclined to presume the worst.
The US agency would type in the gmail address of the subject (ie the primary key/identifier) and somewhere between the agency and Google a decision would be automatically made as to whether the owner of the account was a US person* or not.
If yes - FISA warrant was required
If no - the US agency user would have immediate access to the entire google account (think Google Take Out).
In other words, if you were not a US person there was no duty to protect data.
* = US Person is either a US citizen located anywhere in the world or anyone of any nationality who is physically in the US (current interpretation includes visa holders, visitors and even undocumented but that's shifting)
Microsoft shared data early on with IDF to help target their users (would have to check their ToS to see if there's a clause for that there).
I doubt there's any need to hide anything inside these kinds of companies. Leaders there likely believe they're doing the right thing helping "the good cause" by supporting extrajudicial executions of people. At worst they'll have to kick out employees who'll raise their voices, like they already did many times. No biggie.
While I can totally imagine that governments would mass-export data, and I don’t doubt your friends claim, I can also imagine more innocent interpretation of this work.
I once worked on a large company’s GDPR data-export project. It was a large enough company that it also had a dedicated team to handle legal requests regularly from government(s). GDPR exporting needs to work “at scale” for all accounts, without human-in-the-loop work, and without causing any load issues to running services. The same system also handled legal requests, where the legal team could get an export for a user (almost) identically to the process of a user getting their own data. The legal team had tools set up to work with warrants, subpoenas and similar (internationally) legal data requests from courts and law enforcement. It looks like a “mass export” system, because it was, but it wasn’t used in “bulk requests” from the legal system.
If however they said something more authentic like "We export data in all these cases, in all these countries, and it's never more than .01% of users in a given country, and it never includes freedom-of-speech crimes, and ..." or something then maybe I'd be inclined to consider that.
From https://faq.whatsapp.com/444002211197967/?locale=en_US:
> In the ordinary course of providing our service, WhatsApp does not store messages once they are delivered or transaction logs of such delivered messages. Undelivered messages are deleted from our servers after 30 days. As stated in the WhatsApp Privacy Policy, we may collect, use, preserve, and share user information if we have a good-faith belief that it is reasonably necessary to (a) keep our users safe, (b) detect, investigate, and prevent illegal activity, (c) respond to legal process, or to government requests, (d) enforce our Terms and policies. This may include information about how some users interact with others on our service. We also offer end-to-end encryption for our services, which is always activated. End-to-end encryption means that messages are encrypted to protect against WhatsApp and third parties from reading them. Additional information about WhatsApp's security can be found here.
Note specifically "information about how some users interact with others on our service", which contradicts their claim they don't keep logs of which people are messaging each other.
I'm much more inclined to believe they track everything in high precision and also MITM all the messages. Especially now that they are inserting ads.
I'm no apologist for Facebook, none of whose services I use. But get your facts straight. They are not 'inserting ads' in your chats, as you imply. AFAIK they are adding adds to the never-used 'Updates' tab.
Annoying from an ad perspective, no doubt. Vastly different from a are-they-MITMing-your-messages perspective.
"WE don’t keep logs of who everyone is messaging..."
"We don't KEEP logs of everyone who is messaging..."
"We don't keep logs of EVERYONE who is messaging..."
Etc.
> We do not track your PRECISE location
If they log IP addresses, they can't say they don't log location at all.
> we don’t keep logs of who everyone is messaging
Seems like a pretty strong claim
> we do not track the PERSONAL messages people are sending one another
I don't know much about their business offering, but it seems likely it's not e2e encrypted or has some kind of escrow. Businesses often multiple people to be able to access an account and that is best done without e2e encryption... let alone auditing requirements.
> We do not provide BULK information to any government
Because they are subject to subpoena and search warrants. They are legally required to provided tailored information to governments.
====
All in all it's pretty much what you'd expect for Whatsapp's "e2e but otherwise conventional saas" approach. If you want better, use signal.
> Actualllly you can't prove that it was me who made that search query.
> Actualllly you can't prove that it was me who had that cellphone around that cell tower. Could have been anybody. I could have been hacked.
Judges always allow those evidence and jury always views it as incriminating. What makes more sense, that some unknown hacker hacked into your account and googled something about the thing you're here for, or that you actually just googled it yourself?
On Android, push notifications were always processed by the receiving app, so it can just decrypt a payload directly (or download new messages from the server and decrypt these); on iOS, this isn't as reliable (e.g. swiping the app out of the app switcher used to break it in several iOS versions), but "VoIP notifications" and the newer "message decryption extension" [1] are.
The same principle applies to Web Push – I believe end-to-end encryption is even mandatory there.
[1] https://developer.apple.com/documentation/usernotifications/...
Zuck dribbled and 3D Chessed the Law
META DATA. Literally they did say truthfully they "only" read all the Meta Data, which is actually all data of the company Meta.
Mixed metaphors aside, you can't cheat the law by naming yourself something.
Well, you can try, but the courts take a dim view of it.
> Mixed metaphors aside
Zapp hit that bullseye, causing the rest of the dominoes to fall like a house of cards. Checkmate.
And on top of that if you want make any money with company like X, you need to send your biometrics to some company in Israel. What is this Israel and surveillance capitalism? Or has this always being the case, and I am just now start to realizing it.
Surely they must, how else are the messages… you know… available when you use the app?
just selected people then?
"This may include information about how some users interact with others on our service."