Live data from Hacker News

Reporting a user to WhatsApp forwards a copy of recent messages from that chat

wabetainfo.com

111–120 of 173 posts

Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat

#111
post #103

Earlier quoted context omitted.

(Edit, for context: the original submission title was “WhatsApp can now read your recent messages when you report a user”) By selecting a specific part of the article to highlight in the title, you introduce your own bias before people even begin reading. Stick to the Submissions Guidelines [1], and use the original title. “WhatsApp beta for Android 2.20.206.3” [1] https://news.ycombinator.com/newsguidelines.html > P…

> “WhatsApp beta for Android 2.20.206.3” Sorry but there is zero information in that title. I'm not going to use that. The intention of my post is to make more people aware of this new 'feature'. If some other user had posted this article with that title, I wouldn't have clicked it and I wouldn't have know of this new change.

> I wouldn't have clicked it

That’s exactly the point. The current title is clickbait. If you think the original title is boring, it’s because this is a boring piece of news.

I wouldn’t be worried about “warning” people, since WhatsApp already warns people when they click the report button:

> Most recent messages from this user will be forwarded to WhatsApp

Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat

#112
post #45

Have they fixed the flaw of sabotaging people's accounts by having their numbers reported by many people? https://m.facebook.com/OfficialRishie/posts/4606731886034882

How else would they take down a bad person's account? They say they don't know anything he/she sends.

Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat

#113
post #102

Earlier quoted context omitted.

> I imagine that the API-based uploads of the recent decrypts from the user being reported can also be faked, so I'm not sure that this is a very important distinction. That assumes that the decrypted messages aren't signed (e.g. via HMAC), no?

I somehow don't think FB's world class engineers would fall for the cryptographic doom principle, so this would imply MAC-then-Encrypt-then-MAC, no? :D

While there is certainly a MAC using a key shared between sender and receiver using either an integrated authenticated encryption algorithm or encrypt-then-MAC this key will be known to the recipient and is thus useless for proving authenticity to a third party. But facebook could add an additional MAC using a key only known to them over the already authenticated ciphertext.

Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat

#114
post #95
post #60

Earlier quoted context omitted.

> E2EE is a lie, Facebook hold the private encryption keys server-side so they're able to decrypt messages at any time. This is a pretty bold claim. Do you have a citation for this?

It is a bold claim, indeed. What about WhatsApp Web though? I wonder how that works. I guess it connects to the device via a 3rd party (Facebook's) to send the data over HTTPS? Does it use public-key authentication where the key is only known to the WhatsApp Web client? Either way, it is a compromise on E2EE.

>I wonder how that works. I guess [...] Either way, it is a compromise on E2EE.

How about instead of guessing and concluding it must be compromised (argument from ignorance), you do a cursory search and get an actual response?

https://security.stackexchange.com/questions/148321/how-does...

Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat

#115
post #104
post #94

Earlier quoted context omitted.

You send them the messages, by opt-in, your version seems to suggest something else. Simplest thing is to just stick to the guidelines and use the original title, then add the thing you want to highlight in a comment. The other way ends up taking a non-clickbait title and making it clickbait.

This is not opt-in. You can either report or not report. There is no way to report but not send the messages. The reporting is opt in. The sending of messages tied to the reporting is not

You're now quibbling over my characterization of your characterization of the clickbaity title, which is fun but not really the point. The point is 'don't editorialize/rewrite titles into clickbait, please'.

Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat

#116
post #70

Earlier quoted context omitted.

Shouldn't we prefer Matrix over Signal, since it's federated and doesn't require a phone number / phone to sign up.

It's just something about Matrix. I don't know what it is. I've never opened the app after logging in. It has a good UX which is rare for open source apps. It seems to be based around a decent community. But I don't know why I don't use it.

Network effects?

Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat

#117
post #78

There have been several unofficial reports of Facebook unifying the backend messaging among Instagram, WhatsApp and FB Messenger. If and when that happens, E2EE on WhatsApp will finally be completely gone. Anyone knows how far along (or canceled) that plan is?

[dead]

Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat

#119
post #4

> WhatsApp can now read your recent messages when you report a user This feature is just an extension of manually making a screenshot and attaching it to the messages. As much as I like E2EE, I don't see where the problem lies? It's you who opts in into getting a third party involved. E2EE doesn't mean that no third party is ever going to see the content, it only means that nobody sees it by default .

> I don't see where the problem lies?

There is no problem. I'm just informing people reading HN of this change. Your messages will now be sent when you report a person/group.

Re: Reporting a user to WhatsApp forwards a copy of recent messages from that chat

#120
With (popular) messaging apps now subject to draconian measures to introduce a backdoor, I am now skeptical of these messenger apps, since all an intel agency has to do is push a backdoored binary down the wire to a device, and the user is (usually) unaware that their messages are tapped by the agency. Even with reverse engineering of the app, it could be difficult to determine if it's compromised or no longer 'privacy aware'.
Post reply on HN