US has investigated claims WhatsApp chats aren't private
21–30 of 387 posts
Re: US has investigated claims WhatsApp chats aren't private
#22Earlier quoted context omitted.
By avoiding untrustworthy clients. All Windows devices should be considered compromised after last year.
That's not mitigating client compromise, that's a whole other thing - trying to construct an uncompromiseable client. You don't build defense-in-depth by assuming something can't be compromised.
Re: US has investigated claims WhatsApp chats aren't private
#23I wonder how these investigations go? Are they just asking them if it is true? Are they working with IT specialist to technically analyze the apps? Are they requesting the source code that can be demonstrated to be the same one that runs on the user devices and then analyze that code?
Re: US has investigated claims WhatsApp chats aren't private
#24Earlier quoted context omitted.
That's not mitigating client compromise, that's a whole other thing - trying to construct an uncompromiseable client. You don't build defense-in-depth by assuming something can't be compromised.
Clients can always be compromised. I'm not talking about a client that can't be compromised, but simply a client that is not compromised out-of-the-box.
Re: US has investigated claims WhatsApp chats aren't private
#25I want whatsapp to decrypt the messages in a secure enclave and render the message content to the screen with a secure rendering pipeline, as is done with DRM'ed video. Compromise of the client side application or OS shouldn't break the security model. This should be possible with current API's, since each message could if needed simply be a single frame DRM'ed video if no better approach exists (or until a better ap…
Signal uses the DRM APIs to mitigate threats like Microsoft Recall, but it doesn't stop the app itself from reading its own data. I don't really see how it's possible to mitigate client compromise. You can decrypt stuff on a secure enclave but at some point the client has to pull it out and render it.
Re: US has investigated claims WhatsApp chats aren't private
#26- WhatsApp encryption is broken
- EU's and UK's Chat Control spooks demand Meta to insert backdoor because they cannot break the encryption
The Guardian has its own editorial flavour on tech news, so expect them to use any excuse to bash the subject.
Re: US has investigated claims WhatsApp chats aren't private
#27Earlier quoted context omitted.
This is what a layman would assume happens from Meta’s WhatsApp advertising. They show the e2e process, and have the message entirely unreadable by anyone but the phone owner.
e2e means unreadable by a middleman. That is a small inconvenience if you can readily compromise an endpoint.
Re: US has investigated claims WhatsApp chats aren't private
#28Who do they expect to fall for the claims that a Facebook owned messenger couldn't read your "encrypted" messages? It's truly funny. Any large scale provider with headquarters in the USA will be subject to backdoors and information sharing with the government when they want to read or know what you are doing.
Re: US has investigated claims WhatsApp chats aren't private
#29Earlier quoted context omitted.
By avoiding untrustworthy clients. All Windows devices should be considered compromised after last year.
Why last year?
This was 2025. I'm excited for what 2026 will bring. Things are moving fast indeed.
Re: US has investigated claims WhatsApp chats aren't private
#30Earlier quoted context omitted.
Signal uses the DRM APIs to mitigate threats like Microsoft Recall, but it doesn't stop the app itself from reading its own data. I don't really see how it's possible to mitigate client compromise. You can decrypt stuff on a secure enclave but at some point the client has to pull it out and render it.
By avoiding untrustworthy clients. All Windows devices should be considered compromised after last year.