Live data from Hacker News

Iran asks its people to delete WhatsApp from their devices

apnews.com

221–230 of 560 posts

Re: Iran asks its people to delete WhatsApp from their devices

#221
post #182
post #172

Earlier quoted context omitted.

> like Microsoft did with PRISM or AT&T did with 641A, most likely no one would find out People did find out.

Only because a select few people had the balls to blow the whistle. Imagine if Snowden decided to just do his work and move on? How much longer would it have taken for these facts to be revealed to the public?

Even after we found out, nobody cared...

Re: Iran asks its people to delete WhatsApp from their devices

#222
post #129

Earlier quoted context omitted.

They usually just do a mea culpa: Camera: https://www.bitdefender.com/en-us/blog/hotforsecurity/facebo... Audio: https://news.ycombinator.com/item?id=41424016 Conversations: https://www.vice.com/en/article/facebook-said-it-wasnt-liste... Mass surveillance: https://thehill.com/video/facebook-spying-on-users-new-repor... Across the web: https://www.wired.com/story/ways-facebook-tracks-you-limit-i... Beacon: https://www…

I will never understand how anyone in their right mind can use any product owned by Meta…

Because super vast majority of the population doesn't care. You can just look at the leaks from the last decade and its outcomes. Every company that deals with socials also know that people only care about their privacy within their own small circle. As in, they only care about privacy within their own small bubbles.

Re: Iran asks its people to delete WhatsApp from their devices

#223
Lots of largely baseless speculation here about WhatsApp MITMing end-to-end encrypted chats and other hypotheticals, when the most likely government access path is right there in the open:

WhatsApp heavily nudges users into backing up their chats to iCloud or Google Drive. These backups are, by default, unencrypted (or at least encrypted using a key known to Meta). And most users just use the defaults.

It's exactly the same story with iMessage: If "iCloud Backup" and "iMessage in the cloud" are activated (again, Apple nudges users into these by default), all received messages get uploaded to Apple using a key available to Apple, unless "Advanced Data Protection" is also enabled (decidedly not the default).

Users can deviate from these defaults (and both parties to a conversation need to, for the conversation to actually be private!), but they can already also just use Signal if sufficiently motivated.

Re: Iran asks its people to delete WhatsApp from their devices

#224
post #13

Earlier quoted context omitted.

Why are we toppling all these foreign governments and creating instability that breads terrorism in places that otherwise have nothing to do with us? This seems so exceptionally counter productive.

Because 1) America won’t allow nations near Israel to be successful, it’s too much of a threat to our greatest ally and 2) war is incredibly profitable.

> nations near Israel to be successful,

I'm guessing that doesn't include Turkey or the rich oil arab states.

Re: Iran asks its people to delete WhatsApp from their devices

#225
post #194
post #186

Earlier quoted context omitted.

That's not responsive, though. The point is there are actual human beings in a war zone under a repressive regime making decisions about software. And they aren't interested in your abstract idea about "corpos" being "pressured". They want not to be snatched by the secret police. Please.

How is this "abstract"? Corporations being pressured can directly lead to being snatched by the secret police.

Can you cite the specific instance of Meta (or whoever) receiving pressure that led to an extrajudicial arrest (or whatever)? Or at least the specifics of the sharing that would enable it? Because if you're not talking about specifics your point is "abstract" by definition.

Repression in Iran is real, not abstract. It happens, the state wants to monitor internet use to enable it, and the linked article is very specific about them wanting to disallow Meta's product.

Re: Iran asks its people to delete WhatsApp from their devices

#226
post #7

I find the wordsmithery on Meta's statement the most interesting: “We do not track your *PRECISE* location, we don’t keep logs of who everyone is messaging and we do not track the *PERSONAL* messages people are sending one another," it added. “We do not provide *BULK* information to any government.”

This is just a lie. I personally know somebody who worked at meta and they had a whole set of teams dedicated to building tools for governments to mass-export data based on their queries Now I don't know the exact details of which governments had which access (was it just for warrants, which nations, what was the line between actual terrorist versus persecuting journalists), but there was absolutely bulk export and t…

Remember Snowden outlined the GoogleUS government interface:

The US agency would type in the gmail address of the subject (ie the primary key/identifier) and somewhere between the agency and Google a decision would be automatically made as to whether the owner of the account was a US person* or not.

If yes - FISA warrant was required

If no - the US agency user would have immediate access to the entire google account (think Google Take Out).

In other words, if you were not a US person there was no duty to protect data.

* = US Person is either a US citizen located anywhere in the world or anyone of any nationality who is physically in the US (current interpretation includes visa holders, visitors and even undocumented but that's shifting)

Re: Iran asks its people to delete WhatsApp from their devices

#227
post #81

Earlier quoted context omitted.

I have no idea but I sure hope so.

in discussion next door (got flagged) people are claiming that Iran is peace seeking nation that has amazing relationship with it's neighbors and that it amazingly geopolitically positioned and that USA should team up with current Iranian regime and dump Israel. What's your take on it ?

[deleted]

Re: Iran asks its people to delete WhatsApp from their devices

#228

Earlier quoted context omitted.

Will this result in bloody civil war like in Iraq and minimal dysfunctional central government after?

What’s the alternative? Live under the delusional islamic theocratic dictatorship forever? If you think the islamic republic can be replaced through peaceful protests you have another thing coming, they have already killed thousands of protestors and they have no problem killing because they actually believe they are doing god’s work and the protestors are infidels that deserve to die. I take my chances for a probabl…

I didn't know we were short of examples of what happens when regime-change operations are conducted or when governments get toppled.

You don't need to guess as to what happens; there are examples.

Re: Iran asks its people to delete WhatsApp from their devices

#229
I mean, from a security point of view, those related to the government should use something they control. This goes for all countries.

For the population in general though and in special those who don't like the people in charge of the country, WhatsApp is a great tool. I have to worry about WhatsApp and Meta as I'm in the "west", but there's no chance in hell Meta's going to provide data on any user to the Iranian government... it's a good option for Iranians.

Re: Iran asks its people to delete WhatsApp from their devices

#230

> WhatsApp uses end-to-end encryption, meaning a service provider in the middle can’t read a message. I wish this meme that "whatsapp is secure because it uses e2e encryption" would die. Why does it matter if the messages are e2e encrypted if the messages are managed on the two ends of the channel by a closed source binary that does who-knows-what. The whatsapp app itself sees the clear text message. What it does wit…

Considering how popular WhatsApp is, it's very hard to believe that there are no security researchers reverse-engineering its crypto code. Because WhatsApp uses end-to-end encryption, any backdoor must necessarily be on the client side, and all client-side code can ultimately be reverse-engineered. This makes such backdoors very tricky to implement. With that said, while I think a "general backdoor" (one that weakens…

> any backdoor must necessarily be on the client side

True, but it might be a part of an update that only hits a white-list of users, so you won't find the actual code that steals your private keys if you're on that list.

Post reply on HN