Live data from Hacker News

US has investigated claims WhatsApp chats aren't private

bloomberg.com

21–30 of 387 posts

Re: US has investigated claims WhatsApp chats aren't private

#22
post #18

Earlier quoted context omitted.

By avoiding untrustworthy clients. All Windows devices should be considered compromised after last year.

That's not mitigating client compromise, that's a whole other thing - trying to construct an uncompromiseable client. You don't build defense-in-depth by assuming something can't be compromised.

Clients can always be compromised. I'm not talking about a client that can't be compromised, but simply a client that is not compromised out-of-the-box.

Re: US has investigated claims WhatsApp chats aren't private

#23
post #4

I wonder how these investigations go? Are they just asking them if it is true? Are they working with IT specialist to technically analyze the apps? Are they requesting the source code that can be demonstrated to be the same one that runs on the user devices and then analyze that code?

Multiple governments will already know as they have analyzed and reverse engineered it.

Re: US has investigated claims WhatsApp chats aren't private

#24
post #18

Earlier quoted context omitted.

That's not mitigating client compromise, that's a whole other thing - trying to construct an uncompromiseable client. You don't build defense-in-depth by assuming something can't be compromised.

Clients can always be compromised. I'm not talking about a client that can't be compromised, but simply a client that is not compromised out-of-the-box.

That seems orthogonal to the subject of this discussion, i.e. "Compromise of the client side application or OS shouldn't break the security model."

Re: US has investigated claims WhatsApp chats aren't private

#25
post #12

I want whatsapp to decrypt the messages in a secure enclave and render the message content to the screen with a secure rendering pipeline, as is done with DRM'ed video. Compromise of the client side application or OS shouldn't break the security model. This should be possible with current API's, since each message could if needed simply be a single frame DRM'ed video if no better approach exists (or until a better ap…

Signal uses the DRM APIs to mitigate threats like Microsoft Recall, but it doesn't stop the app itself from reading its own data. I don't really see how it's possible to mitigate client compromise. You can decrypt stuff on a secure enclave but at some point the client has to pull it out and render it.

This. The gap in E2E is the point at which I type in clear text and the point at which I read clear text. Those can be exploited.

Re: US has investigated claims WhatsApp chats aren't private

#26
Both things cannot be true at the same time

- WhatsApp encryption is broken

- EU's and UK's Chat Control spooks demand Meta to insert backdoor because they cannot break the encryption

The Guardian has its own editorial flavour on tech news, so expect them to use any excuse to bash the subject.

Re: US has investigated claims WhatsApp chats aren't private

#27

Earlier quoted context omitted.

This is what a layman would assume happens from Meta’s WhatsApp advertising. They show the e2e process, and have the message entirely unreadable by anyone but the phone owner.

e2e means unreadable by a middleman. That is a small inconvenience if you can readily compromise an endpoint.

People keep talking about e2ee as if it was some brain-to-brain encoding that truly allowed only the recipient person to decrypt the message

Re: US has investigated claims WhatsApp chats aren't private

#28
post #5

Who do they expect to fall for the claims that a Facebook owned messenger couldn't read your "encrypted" messages? It's truly funny. Any large scale provider with headquarters in the USA will be subject to backdoors and information sharing with the government when they want to read or know what you are doing.

They're only concerned someone at meta, they don't already control, could read their personal messages.

Re: US has investigated claims WhatsApp chats aren't private

#29

Earlier quoted context omitted.

By avoiding untrustworthy clients. All Windows devices should be considered compromised after last year.

Why last year?

Windows recall, intrusive addition of AI features (is there even a pinky promise that they're not training on user data?), more builtin ads, and less user control (most notably the removal of using the OS without an account - something that makes sense in the context of undisclosed theft of private information).

This was 2025. I'm excited for what 2026 will bring. Things are moving fast indeed.

Re: US has investigated claims WhatsApp chats aren't private

#30
post #12

Earlier quoted context omitted.

Signal uses the DRM APIs to mitigate threats like Microsoft Recall, but it doesn't stop the app itself from reading its own data. I don't really see how it's possible to mitigate client compromise. You can decrypt stuff on a secure enclave but at some point the client has to pull it out and render it.

By avoiding untrustworthy clients. All Windows devices should be considered compromised after last year.

Windows has been sending usage history back to their servers for longer than just last year
Post reply on HN