Live data from Hacker News

WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

medium.com

11–20 of 53 posts

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#11
Same for Telegram. A couple of years ago people (Phd kind of people) pushed me into using Telegram because "it is encrypted and secure". I checked, and was like... What? AFAIK just transmission is secure (of course, I mean like what traffic is not secure nowadays), but the message are stored plain text on servers in middle east? And the whole thing is operated by a Russian? Like wtf? And people are like "Telegram is totally secure".

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#13

The article opens with a statement by Telegram co-founder Pavel Durov who claims that WhatsApp shared Messages with third parties while Telegram "never did and never will" do that. Now, Telegram doesn't use End-to-End encryption by default at all, does it? What I mean is: The message is encrypted on the sender's device and can only be decrypted on that and the receiver's device. Telegram uses transport layer encrypti…

> Now, Telegram doesn't use End-to-End encryption by default at all, does it?

Underrated fact.

Also, no one knows who exactly operates Telegram and IIRC they don't even have an office. But we know Russian authorities have intense interest in it so it's hard to imagine FSB wouldn't figure out who it is and knock on their (or their relatives still in Russia) door. We know that Russian authorities previously banned Telegram, demanded encryption keys and then a bit later unbanned it saying "Pavel Durov was prepared to cooperate in combating terrorism and extremism on the platform".

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#15
post #5

I’ve been saying this for years — when people derided me on HN — that we need decentralization and open-source backends, because we are relying on pinky-promises. We need attestation that we can trust. I have been building it, piece by piece. Some pieces have been recently featured (last week) in trusted security publications: Safecloud: https://www.helpnetsecurity.com/2026/06/19/safecloud-browser... Safebox and Safe…

We just need open source clients though right?

What does attestation have to do with this? Attestation means not giving me root to my own device. No thanks.

We need something universal, like email, but better engineered.

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#17
> this isn’t a political fight. It’s not a he-said, she-said between tech billionaires. It’s a technical question.

> In transit. Between two online devices. With no cloud backup. With no business accounts. With no Meta AI features. With no linked devices. With no law enforcement warrant for metadata.

> Under every other condition — which is how most people actually use WhatsApp — the story changes dramatically.

Smells a lot like slop so I'll pass, no thanks.

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#18
Almost exactly the same (or worse) can be said about Google's E2EE RCS, but somehow Apple decided to publicly back the initiative. Most people would much more benefit from 1) a faster and broader rollout 2) every other feature in recent versions of the spec, rather than getting a false sense of privacy, yet we're getting a barely compliant RCS client stuck in 2019, plus performative E2EE.

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#20
post #15
post #5

I’ve been saying this for years — when people derided me on HN — that we need decentralization and open-source backends, because we are relying on pinky-promises. We need attestation that we can trust. I have been building it, piece by piece. Some pieces have been recently featured (last week) in trusted security publications: Safecloud: https://www.helpnetsecurity.com/2026/06/19/safecloud-browser... Safebox and Safe…

We just need open source clients though right? What does attestation have to do with this? Attestation means not giving me root to my own device. No thanks. We need something universal, like email, but better engineered.

I mean attestation of what’s running on the server. Did you click and read?

As for the client — the app store on iOS doesn’t allow reproducible builds.

Telegram tried something close for years, which is how I know they care: https://core.telegram.org/reproducible-builds

But it doesn’t matter because the metadata is equally important and useful to get you. And anyway, end-to-end encryption can be banned, or compromised by a new app update, or secretly removed via a backdoor for some, if you pressure one guy (eg @durov in France, or his team every time they pass through an airport). Read this article — it was my response to Moxie Marlinspike (of Signal fame) years ago when he was skeptical of decentralization:

https://community.intercoin.app/t/web3-moxie-signal-telegram...

Post reply on HN