It's pretty hard to imagine a circumstance in which I would be reporting a WhatsApp user. This isn't like a public forum. These are one-on-one conversations or group chats with people who were specifically invited. If someone was a problem, I would just block them. Why would you ever report someone? I haven't ever heard of this happening.
Reporting a user to WhatsApp forwards a copy of recent messages from that chat
51–60 of 173 posts
Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat
#52Earlier quoted context omitted.
So it is not only Facebook that has complete access to the message history, but also Google. The funny thing is that I cannot find a way to access that backup myself, is anyone aware of a method to download that backup as a data dump and inspect it?
I don't know if it is included in your Google takeout. 98% of users enable that option. The fact that whatsapp is e2ee is a complete lie. Use Signal for true e2ee, or if you don't like it, Telegram. Telegram stores everything in the cloud tho. (they haven't disclosed any private messages, and are much more trustworthy than Whatsapp). They just wanted to back up messages without giving it to Google/Apple
Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat
#53> WhatsApp can now read your recent messages when you report a user This feature is just an extension of manually making a screenshot and attaching it to the messages. As much as I like E2EE, I don't see where the problem lies? It's you who opts in into getting a third party involved. E2EE doesn't mean that no third party is ever going to see the content, it only means that nobody sees it by default .
The difference is that a screenshot may be fake. If the intermediary is revealing user private messages, it’s a stronger evidence than just making up a photoshopped screenshot.
Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat
#54As if they couldn't read everything anyway. Obviously, I have no evidence for making such a claim. What I know is 1. Facebook's reputation with regards to privacy. 2. The fact that they paid 20 billion dollars to buy a product without a monetization model. (Which is 20 times more than they paid for Instagram by the way.) 3. Whatsapp's founder left the company after the acquisition due to privacy concerns. It's enough…
While I share your general suspicion I don't think they need to see the messages to get a lot of privacy-violating use out of WhatsApp. When the NSA was talking about metadata collection, they said it was more useful than actual data. Likely because it's already computer consumable, and less dense. If FB gets your contact lists, and sees who you message, how much, and when, that's probably a hugely valuable commodity…
Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat
#55It's pretty hard to imagine a circumstance in which I would be reporting a WhatsApp user. This isn't like a public forum. These are one-on-one conversations or group chats with people who were specifically invited. If someone was a problem, I would just block them. Why would you ever report someone? I haven't ever heard of this happening.
Of course, there's no "reason" field on the report interface, so WatsApp probably won't guess that.
Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat
#56Earlier quoted context omitted.
I don't know if it is included in your Google takeout. 98% of users enable that option. The fact that whatsapp is e2ee is a complete lie. Use Signal for true e2ee, or if you don't like it, Telegram. Telegram stores everything in the cloud tho. (they haven't disclosed any private messages, and are much more trustworthy than Whatsapp). They just wanted to back up messages without giving it to Google/Apple
Shouldn't we prefer Matrix over Signal, since it's federated and doesn't require a phone number / phone to sign up.
Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat
#57Earlier quoted context omitted.
Are you verifying that all your OSS binaries you’re running match a reproducible build hash that’s been validated by multiple trusted sources? If not, you’re already engaging in a level of trust. The real question is how do you establish trust in the code you run and while OSS provides benefits at the margin or something, you can’t really rely on it for anything. For an example to illustrate the fallacious reasoning…
Not GP, but: although I'm not currently doing this consistently (I don't have the resources to set up build servers and there aren't many build servers for my distro yet) the distro I use does make it pretty straightforward to do this: https://guix.gnu.org/manual/en/html_node/Invoking-guix-chall... If I want to do this for any particular package as a one-off, it's two commands.
Again, I’m not saying these aren’t valuable things that make attacks more difficult/expensive but the uncomfortable truth is we haven’t figured out how to truly establish zero-knowledge trust. So on that spectrum, ultimately Guix + OSS is closer to WhatsApp than where we’d like to be.
Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat
#58Earlier quoted context omitted.
Does it mean messages can be read without agreement? Let's imagine "a glitch" where operator sees that user has opt in, but they didn't - can they see messages?
I don't know the implementation on the client, but in theory it can be implemented locally on the client only, and I made the above statements under the assumption that it's how it's implemented. The user issues the report command in the UI and the client takes its local copy and uploads it to the server as part of the report. So it's mainly a convenience feature. The only case where the current E2EE security model i…
Signal achieves non-repudiation by allowing forgery of messages after they have been transferred and verified by the receiver. It is not possible to undo that. You would have to make a special exception at the time the message was transferred which wouldn't be practical in this case.
This all assumes that you believe that establishing forgeability actually achieves non-repudiation in the first place. Facebook might want to pass along the signature information anyway.
Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat
#59> WhatsApp can now read your recent messages when you report a user This feature is just an extension of manually making a screenshot and attaching it to the messages. As much as I like E2EE, I don't see where the problem lies? It's you who opts in into getting a third party involved. E2EE doesn't mean that no third party is ever going to see the content, it only means that nobody sees it by default .
> As much as I like E2EE, I don't see where the problem lies? It's a step along a continuum where the end-to-end encrypted messenger wasn't uploading plaintext before, and now it is. Apple's similar previously end-to-end encrypted iMessage went through a similar evolution: now iOS uploads the complete iMessage plaintext history to Apple (with Apple keys) via iCloud Backup. We now know that Facebook deems it okay to e…
Regarding the iMessage backup thing, I fully agree with you that it's a major problem. But it's a different thing.
Also, again, the feature already exists. You can already make screenshots and share them with facebook, with the world, etc. There are entire subreddits that publicly share IM histories with people. This is nothing that facebook can initiate. If the feature gets changed to something that they can initiate, I would agree that it's bad. But this isn't.
Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat
#60Just FYI, the Google Drive backup of your "E2E encrypted" whatsapp messages is stored in plain text... https://faq.whatsapp.com/android/chats/about-google-drive-ba...
E2EE is a lie, Facebook hold the private encryption keys server-side so they're able to decrypt messages at any time.
This is a pretty bold claim. Do you have a citation for this?