A TD:DR; for people. The "WhatsApp Encryption Overview" technical whitepaper [1] had the following text removed between revisions: "At no time does the WhatsApp server have access to any of the client's private keys." [1] https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857...
WhatsApp whitepaper removed sentence about never having access to private keys
11–20 of 111 posts
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#12They are talking about public keys though. They just removed the part about not having access to private keys. Omission of the line doesn't actually mean that they now have access to private keys as well.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#13I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#14They are talking about public keys though. They just removed the part about not having access to private keys. Omission of the line doesn't actually mean that they now have access to private keys as well.
It doesn't mean they don't either. It's the removal of the previous claim that's worrying. But honestly, it doesn't matter anyway since Whatsapp is somehow able to backup all your data on Google Drive and restore it on separate phones. How are they able to do that without backing up the private key? https://faq.whatsapp.com/android/chats/how-to-restore-your-c...
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#15Probably because: All chats use the same Signal protocol outlined in this whitepaper, regardless of their end-to-end encryption status. The WhatsApp server has no access to the client’s private keys, though if a business user delegates operation of their Business API client to a vendor, that vendor will have access to their private keys - including if that vendor is Facebook. ( https://scontent.whatsapp.net/v/t39.856…
> However, these private keys will still not be stored on the WhatsApp chat server.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#16They are talking about public keys though. They just removed the part about not having access to private keys. Omission of the line doesn't actually mean that they now have access to private keys as well.
I'm not sure they deserve the benefit of the doubt. Facebook has shown themselves to be dodgy as hell when it comes to our privacy.
I would prefer them to explicitly state that they don't have access to the private keys.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#17A a side-note I'm interested in the PDF diffing tool the author is using, seems pretty well made
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#18After Facebook bought what’s app, I’ve never for a moment believed it was secure. I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.
Re: WhatsApp whitepaper removed sentence about never having access to private keys
#19A a side-note I'm interested in the PDF diffing tool the author is using, seems pretty well made
sudo apt-get install diffpdf
https://www.linuxlinks.com/diffpdf-compare-two-pdf-files/Re: WhatsApp whitepaper removed sentence about never having access to private keys
#20After Facebook bought what’s app, I’ve never for a moment believed it was secure. I’ve mentioned on here before about a conversation i had on what’s app and was presented with ads for the topic in Facebook right after. I’ve heard people have had similar stories. What’s app isn’t secure.