Live data from Hacker News

Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

news.ycombinator.com

101–110 of 473 posts

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#101
I had a video call with my mum on signal from her android phone to my macbook. Then I got very specific video recommendation in YouTube about our conversation within the same day. Her android is oppo. Could it be leaking the signal call and then cross match me with the phone numbers to my google account?

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#102
post #57
post #17

Some options: 1. Nobody is reading your WA messages, the same topics can be learned from your browsing activity or other msgs, eg. by reading your sms texts. 2. Meta is reading your messages directly in-transit, server-side. 3. Meta is not reading your messages server-side, but the Meta apps extract keywords from your conversations and request relevant ads from the ad servers. 4. Another non-Meta app is doing the abo…

If 2 is true, then it is not end-to-end encrypted, and I don't think that WhatsApp is lying. They have ways of doing their things without lying, so I don't expect 2 to be true. I think that 1 is the most plausible, however the original post is about "topics they never talk about", so assuming that WhatsApp is the only channel and they don't leak data in other ways (and there are many other ways to leak data), then 1…

Another thing that would make 1 happen even if they think they're not leaking information over different channels, is the software keyboard. GBoard is google's, and likely has some data collection in one way or another. Similarly, there's a lot of google-related services running with root privileges on stock android phones that could easily snoop on data from various apps. This effect is worsened by other android OEMs, like xiaomi or maybe even samsung, who ship their own invasive services on top.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#103
post #5

Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. Meta has control over the app Sue uses. So they could send them to Meta unencrypted in addition to sending them to Joe in an encrypted fashion. Or they just extract the relevant terms: Sue->Joe: "Hello Joe, I'm so excited! We are going to have a baby! Let's call it Dingbert. You're not the father! Ji…

> Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them.

No, that's precisely what End-to-End encryption means.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#104

One explanation I've heard for mysterious "We were talking about it in person but nothing else" ads, is that if you were connecting to the internet from the same Wi-Fi access point or IP address as someone else that did a web search on the topic or visited websites on the topic, it has connected you by way of shared internet connection. Is it possible something like that happened? In general, while anything is possib…

Being on the same network is not even necessary. Meta can still see who talked to whom at what time, and that would be sufficient to correlate the interests of both individuals.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#105
post #5

Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. Meta has control over the app Sue uses. So they could send them to Meta unencrypted in addition to sending them to Joe in an encrypted fashion. Or they just extract the relevant terms: Sue->Joe: "Hello Joe, I'm so excited! We are going to have a baby! Let's call it Dingbert. You're not the father! Ji…

> Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. No, that's precisely what End-to-End encryption means.

Meta own the proprietary code running at either end of the encrypted pipe. Of course they can.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#106
It's a shame this kind of thing is so hard to prove, otherwise it would be all over the media. People will write it off as 'coincidence'. "Perhaps you looked for or discussed it elsewhere".

What happened with Skype before was that Microsoft would ping any links from their servers, so it was really easy to prove it by generating a new web server, publishing it nowhere and then mentioning it in a chat. This caused some publicity and they stopped the practice. Skype didn't guarantee E2EE at that time though.

But perhaps you could do a similar 'clean room' excerise to prove it. I don't think they would break the E2E by the way but perhaps there is something calling home in the app itself.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#107
post #87

Earlier quoted context omitted.

More so, my wife sent me a picture of my daughter working on a puzzle. Less than 24 hours later, her Instagram was showing ads for a store that was selling the same type of puzzle as the one my daughter was playing with. So it's not just terms but images too.

> my wife sent me a picture of my daughter working on a puzzle. > her Instagram was showing ads for a store that was selling the same type of puzzle How did she take the pic ?

I think that's an important question. Did user take the photo within the app, thereby skipping the camera roll, or did they take the photo, then upload to WhatsApp from camera roll. If the latter than as someone else said, could be that Instagram had access to camera roll and decided to serve ads based upon the puzzle.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#108
post #79
post #76

Earlier quoted context omitted.

> Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. I think it does actually no one except them can read them. If someone else can, then by definition it's not end-to-end encryption. From https://www.definitions.net/definition/End-To-End%20Encrypti... > End-to-end encryption (E2EE) is a system of communication where only the communicating users can…

Whatsapp can't read the message on their servers but they can read it at clients, otherwise they cannot display the messages for users. Likewise, Apple/Google can read them too because they have to in order to render the texts.

This is just redefining terms, then.

We know the app decrypts it to display it. But if the app decrypts it to send it to the parent company, then it is by definition not end to end encrypted anymore.

If the app decrypts it, analyzes it and sends information about the message to the parent company, then the same thing is happening. The parent company is reading the message, INSTEAD of E2E encrypting it. It doesn't matter whether that reading happens on device or on the company's servers. E2E means the company is not reading it.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#109
What's scarier than secretly reading messages is the idea that we are being manipulated into believing that we thought of the "random item" all on our own, instead of it being cleverly triggered by a series of manipulative ads or posts from friends.

Or, a similar idea is that ad companies don't really need to know anything about you so long as all your friends are "unprotected".

For example, you may pick "lawn furniture" as your "totally random" item to test WhatsApp. What you don't remember is that a good friend mentioned lawn furniture to you 3 days ago and just did 14 web searches on Google and FB marketplace to find some. They have strong metadata ties to you, so you get served ads on that topic too.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#110
post #99

try an external source of true randomness for choosing your test topics. choices that seem random to you may be totally predictable. i know that's wild, but also often true. humans are bad at randomness. there may be no direct leak at all of your test topics, they might just be guessable based on everything that is known about you, people like you and things you've been presented or looked at.

You also have to factor in confirmation bias-type effects where when you are looking for something everything seems related. If you are seeing dozens of ads a day on Instagram and suddenly you have some "random" topic in your head you will mentally connect them.

Maybe this could be counteracted by something like:

1. Generate multiple random topics and only send one across WhatsApp. Count "related" ads for each.

2. For every other random topic don't send ti across WhatsApp and see if you still find "related" ads.

Post reply on HN