Live data from Hacker News

Ex-WhatsApp cybersecurity head says Meta endangered billions of users

theguardian.com

151–160 of 192 posts

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#151
post #108

Earlier quoted context omitted.

Whatever Meta says publicly about this topic, and whatever its internal policies may be, directly contradicts its behavior. So any attempt to excuse this is nothing but virtue signalling and marketing. The privacy violations and complete disregard for user data are too numerous to mention. There's a Wikipedia article that summarizes the ones we publicly know about. Based on incentives alone, when the company's primar…

There’s a meaningful difference in a company wanting to exploit user data to enrich itself and allowing employees to engage in voyeurism. The latter doesn’t make the company money, and therefore can be penalised at no cost. Your comment talks about incentives, but you haven’t actually made a rational argument tying actual incentives to behaviour.

My point is that it would be naive to believe that a company whose revenue depends on exploiting user data has internal measures in place to ensure the safe handling of that data. In fact, their actions over the years effectively prove that to not be the case.

So whatever they claim publicly, and probably to their low-level employees, is just marketing to cover their asses and minimize the impact to their bottom line.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#152
post #141
post #122

Earlier quoted context omitted.

Are you thinking of Cambridge Analytica? That was a British company, not Israeli.

No, CA was later. This incident was earlier in FB's lifecycle.

Would love a link to this story if you find it.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#153
post #145

Earlier quoted context omitted.

Metadata includes notifications, which often include the text of the message.

Pretty sure this is wrong, at least in the case of WhatsApp. If an app sends the message content in clear through the notifications, then it is badly designed, period.

Agreed. As I recall the way notifications work on Signal/WhatsApp is the app receives some silent notification that wakes it up, then the app does its crypto thing, and then it locally triggers the notification with the decrypted content you see. In iOS land your app needs a special entitlement to work this way. It also means if you're on very heavy group chats your battery will drain faster.

If WhatsApp central servers could push a notification to your phone that contained your actual message content, it couldn't be E2EE.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#154

Earlier quoted context omitted.

France and UK, from personal experience, whatsapp is big, especially for professional use, or friends/family groups. Blue bubble isn't really a thing ever mentioned in France either, not enough iPhone market share.

> Blue bubble isn't really a thing ever mentioned in France either, not enough iPhone market share. Nobody uses iMessage. People with iPhone use WhatsApp too. The user experience of iMessage used to be subpar and now everyone has WhatsApp installed anyway, the feature set is the same and it works on all phone brands so nobody feels like switching.

Same in the UK. The fact that iMessage only works for iOS devices means it's a complete non-starter. What's the point in using a messaging app if you can't add all your contacts to a group? And if you're using a different app for group chats for this reason, then why not use it for 1-1 messaging, too?

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#155

> In his whistleblower complaint, Baig is requesting reinstatement, back pay and compensatory damages, along with potential regulatory enforcement action against the company. If the company is so bad (it is), why does he want back?! 'Just pay me the salaries I "missed", and keep them coming.' The regulatory action is just "potential". I have no sympathy for Meta, but this guy...

He got fired unjustly. For trying to do something good. (His position.) Any full remedy would require his position is reinstated. If he wins the right to be reinstated, he will be happy to negotiate a payment instead. He is made whole. What about any of that lacks sensible motives?

Nothing, but there's something in your comment that was not in the article:

> he will be happy to negotiate a payment instead.

This, indeed, sounds way more normal than wanting to keep working for the evil company, and in a toxic environment.

It hasn't occurred to me that one can change their mind and choose a different compensation after the court decision like that.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#156
post #6

Earlier quoted context omitted.

Messages are e2e and WA doesn't have access to them. We're talking about the metadata here. From the article: > including contact information, IP addresses and profile photos I can confirm this, I used to work at WhatsApp.

We don't really know that messages really are end-to-end encrypted though, do we? Is there a way to actually check that the messages in transit are encrypted in a way that only the other end can decrypt them? If not, we have to take Meta's word for it, which frankly doesn't carry much weight.

Not trivially. But with painstaking reverse engineering you could prove this. And people have, so you're not exclusively just taking Meta's word. The fact that Pegasus malware relied on remote code execution vuln to run malware on your phone to extract WhatsApp messages, really suggests that the E2EE works. If it wasn't E2EE, then the makers of Pegasus could have just intercepted traffic to get your messages.

Academics have also reverse engineered it as well, and though there are some weakness it's not a lie that WhatsApp is E2EE. Here's some I just found:

- https://eprint.iacr.org/2025/794.pdf

- https://i.blackhat.com/USA-19/Wednesday/us-19-Zaikin-Reverse...

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#157
post #152
post #141

Earlier quoted context omitted.

No, CA was later. This incident was earlier in FB's lifecycle.

Would love a link to this story if you find it.

It might be related to this [2015] but that was a hoax. https://news.ycombinator.com/item?id=9374028

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#158

Earlier quoted context omitted.

As a customer I'm angry that businesses get to use "hope and pray" as their primary data protection measure without being forced to disclose it. "Motivators" only work on people who value their job more than the data they can access and I don't believe there's any organization on this planet where this is true for 100% of the employees, 100% of the time. That strategy doesn't help a victim who's being stalked by an e…

This really isn’t fair. It is not simply hope and pray: it is a clearly stated/enforced deterrent that anyone who violates the policy will be terminated. You lose your income and seriously harm your future career prospects. This is more or less the same policy that governments hold to bad actors (crime happens but perpetrators will be punished). I get that it is best to avoid the possibility of such incidents but it…

You don't think it's fair to expect a trillion-dollar business to implement effective technical measures to stop rogue (or hacked!) employees from accessing personal information about their users?

I'm not talking about small businesses here, but large corporations that have more than enough resources to do better than just auditing.

> crime happens but perpetrators will be punished

Societies can't prevent crime without draconian measures that stifle all of our freedoms to an extreme degree. Corporations can easily put barriers in place that make it much more difficult (or impossible) to gain unauthorized access to customer information. The entire system is under their control.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#159
post #104

> Attaullah Baig, who served as head of security for WhatsApp from 2021 to 2025, claims that approximately 1,500 engineers had unrestricted access to user data without proper oversight, potentially violating a US government order that imposed a $5bn penalty on the company in 2020. If it results in a new billion-dollar penalty, maybe it would've saved money to move him quietly to a cushy rest-and-vest advisory positio…

Dont whistlebowers get a percentage cut of the fine?

> In the United States, whistleblowers typically receive a percentage of the money collected by the government, ranging from 10% to 30% of fines or penalties.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#160
post #75
post #56

Earlier quoted context omitted.

It is huge in Latin America. USA is special because it is the (only?) country where iPhone has more users than Android.

Yeah, huge in Latin America in the sense that a lot (most?) business only have a number that they use with Whatsapp (you can't call or even text them). Is it the same in Europe? Since I am from Latin America I never know if people from other continents use Whatsapp as much as we do, and if when I ask them to use Whatsapp I am imposing a new app or it's what they regularly use.

I think Europe is not homogenous enough for this, but in the Netherlands at least, there are plenty of companies that you can't call, email or text, but they'll have some other options: a chatbot, a web form, maybe a Twitter account, and sometimes via WhatsApp indeed.
Post reply on HN