Live data from Hacker News

Ex-WhatsApp cybersecurity head says Meta endangered billions of users

theguardian.com

141–150 of 192 posts

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#141
post #122
post #48

Didn't Hacker News feature an article on their home page at some point (10 years ago?) that at that time Facebook misconfigured something and users could observe their data being fed directly to some Israeli intelligence company? That was the day I deleted my FB account and never looked at anything they offer anymore.

Are you thinking of Cambridge Analytica? That was a British company, not Israeli.

No, CA was later. This incident was earlier in FB's lifecycle.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#142
post #46

Full text of the lawsuit: https://www.bloomberglaw.com/public/desktop/document/BaigvMe...

Here is 115 pages: https://storage.courtlistener.com/recap/gov.uscourts.cand.45...

from here: https://www.courtlistener.com/docket/71293063/baig-v-meta-pl...

    This further surprised Mr. Baig, as WhatsApp, which is known for its strong security brand externally, had such a small security team of just 6 engineers, and they were all only working on this tiny aspect of application security. All the other teams in WhatsApp were well staffed. The engineering team had about 1200 engineers. In addition, there were about 100 product managers, about 100 product designers, nearly 200 data scientists, etc. WhatsApp overall had about 3000 employees.

    “Are we going to be in the same situation as Mudge at Twitter?”

WhatsApp is way beyond just texting and calling, it is basically global infrastructure now, used daily by governments, NGOs, and billions. This is not a startup screw-up, it's a public utility gone seriously messed up. Heads need to roll. Stop playing god. Secure the platform or step aside.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#143
post #119
post #104

> Attaullah Baig, who served as head of security for WhatsApp from 2021 to 2025, claims that approximately 1,500 engineers had unrestricted access to user data without proper oversight, potentially violating a US government order that imposed a $5bn penalty on the company in 2020. If it results in a new billion-dollar penalty, maybe it would've saved money to move him quietly to a cushy rest-and-vest advisory positio…

> I don't understand the "reinstatement" part. Does he actually want to go back, and think that it wouldn't be a toxic dynamic? Maybe he's just laying a foundation for an upcoming legal dispute?

It means he would prefer to be paid to not be reinstated.

But until he is paid, his position is that he wants to be reinstated.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#144
post #42

I hate Meta as much as the next person, but it feels like "endangering billions of users" is exagerating here. The complaint is pretty much that WhatsApp engineers can access metadata ( NOT the content of the messages). This said, WhatsApp is not open source, so it's impossible for users to verify how the encryption works, so users have to trust that it's properly end-to-end encrypted. If you care about privacy (and…

The metadata of someone's communications can be almost as damning as the content. I would guess that if the FBI could merely have a list of who their suspect contacted over an app, and when, they'd have 90% of what they wanted.

> I would guess that if the FBI could merely have a list of who their suspect contacted over an app, and when

Well with WhatsApp they most definitely can, but it has never been a secret. WhatsApp always had access to the metadata (whereas Signal makes a lot of effort to reduce the metadata they have access to). In ~2016 WhatsApp integrated the Signal protocol to add end-to-end encryption, but did nothing about the metadata.

Again: if you care about privacy, use Signal.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#145
post #42

I hate Meta as much as the next person, but it feels like "endangering billions of users" is exagerating here. The complaint is pretty much that WhatsApp engineers can access metadata ( NOT the content of the messages). This said, WhatsApp is not open source, so it's impossible for users to verify how the encryption works, so users have to trust that it's properly end-to-end encrypted. If you care about privacy (and…

Metadata includes notifications, which often include the text of the message.

Pretty sure this is wrong, at least in the case of WhatsApp.

If an app sends the message content in clear through the notifications, then it is badly designed, period.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#146

> In his whistleblower complaint, Baig is requesting reinstatement, back pay and compensatory damages, along with potential regulatory enforcement action against the company. If the company is so bad (it is), why does he want back?! 'Just pay me the salaries I "missed", and keep them coming.' The regulatory action is just "potential". I have no sympathy for Meta, but this guy...

He got fired unjustly. For trying to do something good. (His position.)

Any full remedy would require his position is reinstated.

If he wins the right to be reinstated, he will be happy to negotiate a payment instead. He is made whole.

What about any of that lacks sensible motives?

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#148
post #11
post #7

> A Meta spokesperson, Andy Stone, wrote on Threads, the company’s text-based social network: “Sadly this is a familiar playbook in which a former employee is dismissed for poor performance and then goes public with distorted claims that misrepresent the ongoing hard work of our team.” Skeletons keep piling up while PR try to dismiss them

That quote is brilliant. Corporate communications has playbook damage control responses, and this quote seems to be suggesting that the quoted response is one of them (it's "familiar"). Whether "former employees" are sketchily operating from playbooks, who knows. Because PR playbook-sounding statements don't have a lot of credibility.

Innocent until proven guilty.

Or the PR team undermines their own credibility with a stock and specious fact-free non-response.

I think the point of these is to dodge the even guiltier look of “no comment”. And signal there won’t be any potentially costly cooperative engagement from their side to their shareholders.

They don’t expect to be believed.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#149
post #32

Earlier quoted context omitted.

I can't tell if I'm being paranoid or just realistic, when I suspect that FBI/Apple fights over decrypting/unlocking iPhones or iMessage are just part of Apple's security theater. If I were Evil-Tim-Cook, I'd have a deal with the FBI (and other agencies) where I'd hand over some user's data, in return for them keeping that secret and occasionally very publicly taking Apple to court demanding they expose a specific us…

Maybe. I think they'd have a hard time keeping that under wraps—governments aren't typically very careful (and the FBI is about as careful as a bull in a china shop) about not showing their hand when it comes to charging people. If you're strict about keeping certain info on certain channels, smart observers would notice if someone were snooping. For instance, if someone shared something incriminating in a group chat…

> someone shared something incriminating in a group chat and got arrested, and that info was only shared in the group chat

“Only” is doing an incredible amount of work there.

Unless you concoct something incriminating solely for the purpose of testing this, the something incriminating being discussed in group chat previously happened in the real world. Ripples of information were created there and can be found (parallel construction).

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#150
post #128

Earlier quoted context omitted.

is that really true? I haven’t touched a lot of these cyber security parts of industry: especially policies for awhile… … but I do recall that auditing was a stronger motivator than preventing. There were policies around checking the audit logs, not being able to alter audit logs and ensuring that nobody really knew exactly what was audited. (Except for a handful of individuals of course.) I could be wrong, but “obse…

As a customer I'm angry that businesses get to use "hope and pray" as their primary data protection measure without being forced to disclose it. "Motivators" only work on people who value their job more than the data they can access and I don't believe there's any organization on this planet where this is true for 100% of the employees, 100% of the time. That strategy doesn't help a victim who's being stalked by an e…

This really isn’t fair. It is not simply hope and pray: it is a clearly stated/enforced deterrent that anyone who violates the policy will be terminated. You lose your income and seriously harm your future career prospects. This is more or less the same policy that governments hold to bad actors (crime happens but perpetrators will be punished). I get that it is best to avoid the possibility of such incidents but it is not always practical and a strong punishment mechanism is a reasonable policy in these cases.
Post reply on HN