Live data from Hacker News

US has investigated claims WhatsApp chats aren't private

bloomberg.com

31–40 of 387 posts

Re: US has investigated claims WhatsApp chats aren't private

#31

Both things cannot be true at the same time - WhatsApp encryption is broken - EU's and UK's Chat Control spooks demand Meta to insert backdoor because they cannot break the encryption The Guardian has its own editorial flavour on tech news, so expect them to use any excuse to bash the subject.

They’re just not sharing the back door with the EU?

Re: US has investigated claims WhatsApp chats aren't private

#32
> “We look forward to moving forward with those claims and note WhatsApp’s denials have all been carefully worded in a way that stops short of denying the central allegation in the complaint – that Meta has the ability to read WhatsApp messages, regardless of its claims about end-to-end encryption.”

My money is on the chats being end to end encrypted and separately uploaded to Facebook.

Re: US has investigated claims WhatsApp chats aren't private

#35

Earlier quoted context omitted.

e2e means unreadable by a middleman. That is a small inconvenience if you can readily compromise an endpoint.

People keep talking about e2ee as if it was some brain-to-brain encoding that truly allowed only the recipient person to decrypt the message

because it used to be that the ends and the middlemen were different entities.

In the universe where they are the same entity (walled-gardens) there is only the middleman.

In such cases you either trust them or you don’t, anything more is not required because they can compromise their own endpoints in a way you can not detect.

Re: US has investigated claims WhatsApp chats aren't private

#36

Both things cannot be true at the same time - WhatsApp encryption is broken - EU's and UK's Chat Control spooks demand Meta to insert backdoor because they cannot break the encryption The Guardian has its own editorial flavour on tech news, so expect them to use any excuse to bash the subject.

Just because Adam has a back door doesn’t mean Eve also has a back door.

Re: US has investigated claims WhatsApp chats aren't private

#37
post #4

I wonder how these investigations go? Are they just asking them if it is true? Are they working with IT specialist to technically analyze the apps? Are they requesting the source code that can be demonstrated to be the same one that runs on the user devices and then analyze that code?

That will be step 1. Fear of being caught lying to the government is such that that is usually enough. Presumably at least a handful of people would have to know about it, and nobody likes their job at Facebook enough to go to jail over it. But you never know.

Companies lie to governments and the public all the time. I doubt that even if something were found and the case were lost, it would lead to prison or any truly severe punishment. No money was stolen and no lives were put at risk. At worst, it would likely end in a fine, and then it would be forgotten, especially given Meta’s repeated violations of user trust.

The reality is that most users do not seem to care. For many, WhatsApp is simply “free SMS,” tied to a phone number, so it feels familiar and easy to understand, and the broader implications are ignored.

Re: US has investigated claims WhatsApp chats aren't private

#38
post #5

Who do they expect to fall for the claims that a Facebook owned messenger couldn't read your "encrypted" messages? It's truly funny. Any large scale provider with headquarters in the USA will be subject to backdoors and information sharing with the government when they want to read or know what you are doing.

I have reached the point that I think even the chat control discussion might be a distraction because essentially they can already get anything. Yeah government needs to fill in a form to request, but that’s mostly automated I believe

Re: US has investigated claims WhatsApp chats aren't private

#39
post #12

I want whatsapp to decrypt the messages in a secure enclave and render the message content to the screen with a secure rendering pipeline, as is done with DRM'ed video. Compromise of the client side application or OS shouldn't break the security model. This should be possible with current API's, since each message could if needed simply be a single frame DRM'ed video if no better approach exists (or until a better ap…

Signal uses the DRM APIs to mitigate threats like Microsoft Recall, but it doesn't stop the app itself from reading its own data. I don't really see how it's possible to mitigate client compromise. You can decrypt stuff on a secure enclave but at some point the client has to pull it out and render it.

> I don't really see how it's possible to mitigate client compromise

Easy: pass laws requiring chat providers to implement interoperability standards so that users can bring their own trusted clients. You're still at risk if your recipient is using a compromised client, but that's a problem that you have the power to solve, and it's much easier to convince someone to switch a secure client if they don't have to worry about losing their contacts.

Re: US has investigated claims WhatsApp chats aren't private

#40
I always assumed Meta has backdoor that at least allows them to compromise key individuals if men in black ask, but law firm representing NSO courageously defending the people? Come the fuck on.

> Our colleagues’ defence of NSO on appeal has nothing to do with the facts disclosed to us and which form the basis of the lawsuit we brought for worldwide WhatsApp users.

Post reply on HN