Live data from Hacker News

Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

news.ycombinator.com

231–240 of 473 posts

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#231
post #132
post #85

Earlier quoted context omitted.

The application processing the message for the purpose of displaying it is clear. But if the message is copied, read, analyzed and sent further on behalf of a third party before encryption, then that puts that third party in the middle between the sender and the recipient. A man in the middle directly undermines e2ee: "no one else reads your message". It doesn't matter if the third party made the messaging app or not…

E2EE doesn't prevent the app itself from analyzing messages locally, and sending updated interest profiles to meta... which can be a vector of weights or whatever thing they might be using to know what ads to show. If the logic is in the app, the message doesn't leave the app and E2EE is preserved. This said, analyzing messages for the purpose of ad display is creepy, whatever the way it is done.

E2EE most certainly does exclude analyzing messages anywhere for a third party.

Notice that "ends" in "end-to-end" are users, not applications. When an application forwards things to an entity, then that entity becomes an "end" of the conversation. When it displays a message to the user, the way the user wants, then the user is the end. When it processes the message and delivers results to Facebook, the way Facebook wants it, then the application makes Facebook the "third end".

In such scenario, Facebook had intercepted the message, just chose to forward only some extracted information (which may or may not be enough to reconstruct the original). This does not match the definition of "end-to-end encryption".

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#232
post #97

Earlier quoted context omitted.

Is this something that actually happens (= can anyone prove this by disassembling the app or MITMing the network traffic), or is it just unfounded paranoia?

Considering how easy it is to implement these things without anyone noticing since it's closed source, you have to assume it is happening in any scenario where you need any decent opsec. Even in scenarios where you don't, there's been enough cases of similar things happening with well-known apps and services to be wary.

> Considering how easy it is to implement these things without anyone noticing since it's closed source

You can reverse engineer those things and analyze your network traffic. You can’t have a client in a device controlled by the user, in this case an app, send anything to a server without anyone noticing it.

And frankly, they don’t even need it. Just with your contacts they can link you to your friends and common interests without even you having a facebook account, all you need is friends with a fb/ig account who have linked their accounts to their phones and use whatsapp.

The contacts are known to be sent to the server, they are known to be linked to facebook except in the european union where there is a different app from WhatsApp Ireland and a different privacy policy that specifically states (in the version outside of EU) that it shares your contacts with facebook and they are much more valuable and much less risky than reading your messages.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#234
Recently I was booking a trip to Finland, so my booking app showed me suggested destinations to other nearby countries like Estonia. That's normal.

Then, my friend asked me where do I want to go the most if I am to go scuba diving. I answered "Phillipines". My friend then said "Maldives is also great". We never searched for anything, just casual conversation. A few minutes later I look at my booking app, guess what were the top suggestions - Maldives, followed by Phillipines. Must be coincidence.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#235
post #158

Earlier quoted context omitted.

This is facebook. They've been caught recording people and selling that for advertising, they deny it because technically your audio is transcripted not recorded and they can send only some keywords back so whole conversations aren't sent back to them.

Source?

Ah yes, a bunch of anecdotes in reply.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#236

I am 99% sure Meta/Facebook have secretly broken WhatsApp e2e encryption by adding a second key to all users. I have security code change notifications enabled, and around November 4, 2021 a large number of my unrelated contacts suddenly had security code changes. There wasn’t any media reporting at the time, but I remember some others mentioning it on Reddit[0] (would love if anyone here can scroll back in their mes…

"Also note that both iMessage and WhatsApp strongly encourage you to enable iCloud backups, which are not e2e encrypted and readable by Apple" -> That's not completely true (at least for WhatsApp): It is possible to enable a e2e encrypted backup right in the chat-backup menu.

You are right, I should have said they WhatsApp messages are “not e2e encrypted by default”.

However, I still believe Facebook holds a second decryption key for all messages, which they rolled out along with their web access product as described above. So they are not e2e encrypted by any reasonable interpretation of the phrase.

I am not aware of any way to e2e encrypt iCloud backups, so the vast majority of “e2e encrypted” iMessage messages are readable by Apple.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#237
Well, yeah. Of course lots of companies are targeting us for ads based on data that we lightheartedly assumed was private. It's even possible that they could do this without violating their ever-changing privacy policies. For example, they could say that the programs that review your messages don't retain any personally identifiable information. It might even be true. (Although there's no auditing of this and little or no accountability.)

Online ads ... if you've ever paid for one you know they are desperately in need of targeting. We consumers provide our info directly to folks who sell ads, under terms and conditions that we don't understand. Of course they're making use of this free resource. They'd have to be idiots not to.

So ... with respect, the wave of denial in the comments here ... 10 years ago, that would have seemed "naive but understandable." Today it's just weird. Almost like some kind of absurdist comedy. It's totally disconnected from the world we actually live in.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#238

I’m convinced WhatsApp’s e2e is BS. Because multiple times I’ve mentioned something I’ve never even googled and then had Facebook ads for those things show up minutes later. The most notable one being renting an apartment. I viewed an apartment then sent a message to the agent requesting window grills or latches and then had adverts for that stuff straight away. When ever I mention this on HN I get downvoted with lam…

I mean the WhatsApp founders literally quit with millions left on the table over "disagreements with facebook senior leadership" and then promptly made a huge donation to Signal. If that wasn't them saying "HEY THEY ARE REMOVING E2E" without violating NDA I don't know what it was.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#239
post #186

I think Meta is reading your messages locally on your device and showing you personalized ads from the messages that are actually on your device. It's not uploaded on Meta's servers and not in anyway breaking the e2ee, because your device is one of the 2 ends. If you don't use Facebook or Instagram on your phone then no personalized ads is shown. Everything above is supposition from something I vaguely remember but n…

Whatsapp isn't open source. How do you know that the messages are actually e2e encrypted?

Decompilation. Reverse engineering. Network monitoring. Third-party attestations like https://research.nccgroup.com/wp-content/uploads/2021/10/NCC.... The lack of whistleblowers from within Meta itself. There are are hundreds of employees working on this product.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#240

Earlier quoted context omitted.

Quoted post unavailable.

This isn’t evidence. Even if Facebook was not listening to your conversations, there would be some rate in which you would just randomly be served an ad related to a topic you were discussing. There needs to be evidence that it is happening at a rate too high to be attributable to chance.

Sounds like a good way to engineer it... anything to improve the bottom line even if insanely-targeted ads only trickle out to users. How about limiting who sees this feature to also limit the risk of being detected? Maybe just do it once a year to everyone, or never to specific "tech-savvy" users that they have completely profiled.
Post reply on HN