Live data from Hacker News

Ex-WhatsApp cybersecurity head says Meta endangered billions of users

theguardian.com

1–10 of 192 posts

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#3
post #2

Edit: Oof good catch (bad day for Meta)

This is unfortunately entirely seperate from that other article.

FTA:

> Attaullah Baig, who served as head of security for WhatsApp from 2021 to 2025, claims that approximately 1,500 engineers had unrestricted access to user data without proper oversight, potentially violating a US government order that imposed a $5bn penalty on the company in 2020.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#5
Given how WhatsApp is the de-facto way to communicate outside of the West and China, these security/data-handling "weaknesses" are most likely a feature, not a bug. An absolute bonanza for the certain intelligence services.

Remember, kids: End to end encryption is useless if the "ends" are fully controlled by an (untrustworthy) third party.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#6
post #4

So much for that e2e encryption that HN claimed was so good and that META couldn’t possibly use what’s app messages to do advertising from.

Messages are e2e and WA doesn't have access to them. We're talking about the metadata here.

From the article: > including contact information, IP addresses and profile photos

I can confirm this, I used to work at WhatsApp.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#7
> A Meta spokesperson, Andy Stone, wrote on Threads, the company’s text-based social network: “Sadly this is a familiar playbook in which a former employee is dismissed for poor performance and then goes public with distorted claims that misrepresent the ongoing hard work of our team.”

Skeletons keep piling up while PR try to dismiss them

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#8
post #6
post #4

So much for that e2e encryption that HN claimed was so good and that META couldn’t possibly use what’s app messages to do advertising from.

Messages are e2e and WA doesn't have access to them. We're talking about the metadata here. From the article: > including contact information, IP addresses and profile photos I can confirm this, I used to work at WhatsApp.

Meta/WA. Same thing. Might have worked at WhatsApp but FB still advertises based on conversation content.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#9

Given how WhatsApp is the de-facto way to communicate outside of the West and China, these security/data-handling "weaknesses" are most likely a feature, not a bug. An absolute bonanza for the certain intelligence services. Remember, kids: End to end encryption is useless if the "ends" are fully controlled by an (untrustworthy) third party.

Without open source, end to end encryption is useless. It's not hard to hide a piece of code that defeats the encryption in closed source code.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#10
post #8
post #6

Earlier quoted context omitted.

Messages are e2e and WA doesn't have access to them. We're talking about the metadata here. From the article: > including contact information, IP addresses and profile photos I can confirm this, I used to work at WhatsApp.

Meta/WA. Same thing. Might have worked at WhatsApp but FB still advertises based on conversation content.

Not sure this is correct - alaq said the messages are e2e, so not visible at all by anyone other that the participants of the conversation. The meta->data<- however IS visible by them and can and is likely to be used for advertising.
Post reply on HN