Live data from Hacker News

US has investigated claims WhatsApp chats aren't private

bloomberg.com

131–140 of 387 posts

Re: US has investigated claims WhatsApp chats aren't private

#131
post #79

> “We look forward to moving forward with those claims and note WhatsApp’s denials have all been carefully worded in a way that stops short of denying the central allegation in the complaint – that Meta has the ability to read WhatsApp messages, regardless of its claims about end-to-end encryption.” My money is on the chats being end to end encrypted and separately uploaded to Facebook.

If this was happening en-masse, wouldn't this be discovered by the many people reverse engineering WhatsApp? Reverse engineering is hard sophisticated work, but given how popular WhatsApp is plenty of independent security researchers are doing it. I'm quite skeptical Meta could hide some malicious code in WhatsApp that's breaking the E2EE without it being discovered.

Before that, Meta employees would know about it. Pretty convinced that someone would leak it.

Re: US has investigated claims WhatsApp chats aren't private

#132
post #84

> “We look forward to moving forward with those claims and note WhatsApp’s denials have all been carefully worded in a way that stops short of denying the central allegation in the complaint – that Meta has the ability to read WhatsApp messages, regardless of its claims about end-to-end encryption.” My money is on the chats being end to end encrypted and separately uploaded to Facebook.

>being end to end encrypted and separately uploaded to Facebook That's a cute loophole you thought up, but whatsapp's marketing is pretty unequivocal that they can't read your messages. >With end-to-end encryption on WhatsApp, your personal messages and calls are secured with a lock. Only you and the person you're talking to can read or listen to them, and no one else, not even WhatsApp https://www.whatsapp.com/ That…

The thing is, if they were uploading your messages, then they'd want to do something with the data.

And humans aren't great at keeping secrets.

So, if the claim is that there's a bunch of data, but everyone who is using it to great gain is completely and totally mum about it, and no one else has ever thought to question where certain inferences were coming from, and no employee ever questioned any API calls or database usage or traffic graph.

Well, that's just about the best damn kept secret in town and I hope my messages are as safe!

And I'm no fan of Meta...

Re: US has investigated claims WhatsApp chats aren't private

#133
post #39
post #12

Earlier quoted context omitted.

Signal uses the DRM APIs to mitigate threats like Microsoft Recall, but it doesn't stop the app itself from reading its own data. I don't really see how it's possible to mitigate client compromise. You can decrypt stuff on a secure enclave but at some point the client has to pull it out and render it.

> I don't really see how it's possible to mitigate client compromise Easy: pass laws requiring chat providers to implement interoperability standards so that users can bring their own trusted clients. You're still at risk if your recipient is using a compromised client, but that's a problem that you have the power to solve, and it's much easier to convince someone to switch a secure client if they don't have to worry…

> Easy: pass laws requiring chat providers to implement interoperability standards so that users can bring their own trusted clients.

In Europe that's called the Digital Markets Act.

Re: US has investigated claims WhatsApp chats aren't private

#134

WhatsApp's end-to-end encryption has been independently investigated: https://kclpure.kcl.ac.uk/ws/files/324396471/whatsapp.pdf Full version here: https://eprint.iacr.org/2025/794.pdf We didn't review the entire source code, only the cryptographic core. That said, the main issue we found was that the WhatsApp servers ultimately decide who is and isn't in a particular chat. Dan Goodin wrote about it here: https://arst…

Thank you for actually evaluating the technology as implemented instead of speculating wildly about what Facebook can do based on vibes.

Re: US has investigated claims WhatsApp chats aren't private

#135
Matthew Green's take from 3 days ago:

> There’s a lawsuit against WhatsApp making the rounds today, claiming that Meta has access to plaintext. I see nothing in there that’s compelling; the whole thing sounds like a fishing expedition.

https://bsky.app/profile/matthewdgreen.bsky.social/post/3mdg...

Re: US has investigated claims WhatsApp chats aren't private

#136
post #73

Earlier quoted context omitted.

Although now I think about it more, you could have APIs for "decrypt this [text/image] with key $id, and render it as a secure overlay at coordinates ($x, $y)"

Exactly. Thats how DRM video works, and I don't see why you couldn't do the same for text.

Actual DRM uses symmetric keys though, figuring out how to do the crypto in an E2EE-comaptible way would be challenging.

Re: US has investigated claims WhatsApp chats aren't private

#137
post #124

Earlier quoted context omitted.

The PIN is used when you're too lazy to set an alphanumeric pin or offload the backup to Apple/Google. Now sure, this is most people, but such are the foibles of E2EE - getting E2EE "right" (eg supporting account recovery) requires people to memorize a complex password. The PIN interface is also an HSM on the backend. The HSM performs the rate limiting. So they'd need a backdoor'd HSM.

That might be a different pin? Messenger requires a pin to be able to access encrypted chat. Every time you sign in to the web interface or resign into the app you enter it. I don’t remember an option for an alphanumeric pin or to offload it to a third party.

Oh my bad! I was talking about WhatsApp.

The Messenger PIN is rate limited by an HSM, you merely enter it through the web interface.

Of course, the HSM could be backdoored or the client could exfil the secret but the latter would be easy to discover.

Harder to do any better here without making the user memorize a master password, which tends to fail miserably in real life.

Re: US has investigated claims WhatsApp chats aren't private

#138

Earlier quoted context omitted.

If you claim REing a flagship FAANG application is "extra easy", either they need to be laughed out of the room or you do.

Reverse engineering is easy when the source code is available. :) The difference between source code in a high-level language, and AArch64 machine language, is surmountable. The effort is made easier if you can focus on calls to the crypto and networking libraries.

The source is available?

Understanding program flow is very different from understanding the composition of data passing though the program.

Re: US has investigated claims WhatsApp chats aren't private

#139

Earlier quoted context omitted.

They likely wouldn’t rate limit themselves, rate limiting only applies when you access through their cute little enter your pin UI.

The PIN is used when you're too lazy to set an alphanumeric pin or offload the backup to Apple/Google. Now sure, this is most people, but such are the foibles of E2EE - getting E2EE "right" (eg supporting account recovery) requires people to memorize a complex password. The PIN interface is also an HSM on the backend. The HSM performs the rate limiting. So they'd need a backdoor'd HSM.

That added some context I didn’t have yet thanks. I’m not seeing yet how Meta if it was a bad actor wouldn’t be able to brute force the pin of a particular user. Of this was a black box user terminal site, Meta owns the stack here though, seems plausible that you could inject yourself easily somewhere.
Post reply on HN