Another idea: test a null hypothesis. Block with your pi-hole or a proxy all the facebook traffic so the messages won't work. Then reproduce with the same exact behavior with your wife (it would be better if you both could get a clean identity and then repeat the exact same conversations and topics, but getting a clean identity is not that easy) so all the external factors are the same except the facebook connection…
Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
111–120 of 473 posts
Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
#112Some options: 1. Nobody is reading your WA messages, the same topics can be learned from your browsing activity or other msgs, eg. by reading your sms texts. 2. Meta is reading your messages directly in-transit, server-side. 3. Meta is not reading your messages server-side, but the Meta apps extract keywords from your conversations and request relevant ads from the ad servers. 4. Another non-Meta app is doing the abo…
If 2 is true, then it is not end-to-end encrypted, and I don't think that WhatsApp is lying. They have ways of doing their things without lying, so I don't expect 2 to be true. I think that 1 is the most plausible, however the original post is about "topics they never talk about", so assuming that WhatsApp is the only channel and they don't leak data in other ways (and there are many other ways to leak data), then 1…
I agree, I'm pretty sure 2. is not the case; I just listed it as a theoretical possibility. Despite all the bad press and problems, FB has very (very) high integrity and standards, at least the parts I saw.
Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
#113Earlier quoted context omitted.
Is this something that actually happens (= can anyone prove this by disassembling the app or MITMing the network traffic), or is it just unfounded paranoia?
Considering how easy it is to implement these things without anyone noticing since it's closed source, you have to assume it is happening in any scenario where you need any decent opsec. Even in scenarios where you don't, there's been enough cases of similar things happening with well-known apps and services to be wary.
I see you’ve never heard of Jane Manchun Wong...
Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
#114Some options: 1. Nobody is reading your WA messages, the same topics can be learned from your browsing activity or other msgs, eg. by reading your sms texts. 2. Meta is reading your messages directly in-transit, server-side. 3. Meta is not reading your messages server-side, but the Meta apps extract keywords from your conversations and request relevant ads from the ad servers. 4. Another non-Meta app is doing the abo…
Another option would be that META created a small model that could be run client-side and picked the right selection of ads to show elsewhere without even exfiltrating keywords.
Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
#115Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
#116It's a shame this kind of thing is so hard to prove, otherwise it would be all over the media. People will write it off as 'coincidence'. "Perhaps you looked for or discussed it elsewhere". What happened with Skype before was that Microsoft would ping any links from their servers, so it was really easy to prove it by generating a new web server, publishing it nowhere and then mentioning it in a chat. This caused some…
If 200 people send preselected product communique over brand new devices and are 800% more likely to be targeted by ads for those or related products by the control group of the same size then we have enough for a legal case and discovery.
Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
#117Earlier quoted context omitted.
> Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. No, that's precisely what End-to-End encryption means.
Meta own the proprietary code running at either end of the encrypted pipe. Of course they can.
Signal might be the only app unable to read, but even that, I would not trust.
Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
#118Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. Meta has control over the app Sue uses. So they could send them to Meta unencrypted in addition to sending them to Joe in an encrypted fashion. Or they just extract the relevant terms: Sue->Joe: "Hello Joe, I'm so excited! We are going to have a baby! Let's call it Dingbert. You're not the father! Ji…
> Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. No, that's precisely what End-to-End encryption means.
It's illustrated in their example below that they if you say you're having a baby, meta can send some type of distilled ad-keywords to its servers (eg `[mother, baby]` if it knows the user is a woman based on their name/profile, but probably more sophisticated than that). The message you sent is still technically end-to-end encrypted, though,
Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
#119Another idea: test a null hypothesis. Block with your pi-hole or a proxy all the facebook traffic so the messages won't work. Then reproduce with the same exact behavior with your wife (it would be better if you both could get a clean identity and then repeat the exact same conversations and topics, but getting a clean identity is not that easy) so all the external factors are the same except the facebook connection…
just pointing out - pihole can't block web traffic, only the DNS lookups. If server IP addresses are hard-coded, there's nothing pihole can do.
Of course, if it does not work, use a proxy.
Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
#120- systematically record how often this happens, in contrast to other ads, and for each of the reason topics
- record for each random topic if you have also mentioned it anywhere else, e.g. in a Google search it some other digital media
- make the choice of random topics more random, ie. not depending on current moods (which might be biased through subtle, external nudges
-...
These are of course just pointers, and by no means a proper experimental setup.
I'm aware that this might take the fun out of your playful approach. However, you might be surprised by the results, in whatever direction. Also, it would give you a much more grounded fundament for further discussion. Of course you can just keep doing it the current, less tedious way. I'm only suggesting it because you seem to be interested in the topic and it might be more satisfying for yourselves to turn this into a little citizen science project.