All Meta guys develop a conscience after leaving Meta.
Ex-WhatsApp cybersecurity head says Meta endangered billions of users
161–170 of 192 posts
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#162Earlier quoted context omitted.
I'm in the UK, I don't even know what 'the blue bubble alternative' is (Signal? Telegram?), everyone's on WhatsApp.
I guess that it’s the iPhone’s messenger app? I heard that in that app, fellow iOS users have blue bubble messages and Android / other users have green bubble messages, and all the teens in the US /maybe Canada think it’s lame if you don’t have blue bubbles.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#163Earlier quoted context omitted.
Would love a link to this story if you find it.
It might be related to this [2015] but that was a hoax. https://news.ycombinator.com/item?id=9374028
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#164Earlier quoted context omitted.
Maybe. I think they'd have a hard time keeping that under wraps—governments aren't typically very careful (and the FBI is about as careful as a bull in a china shop) about not showing their hand when it comes to charging people. If you're strict about keeping certain info on certain channels, smart observers would notice if someone were snooping. For instance, if someone shared something incriminating in a group chat…
> someone shared something incriminating in a group chat and got arrested, and that info was only shared in the group chat “Only” is doing an incredible amount of work there. Unless you concoct something incriminating solely for the purpose of testing this, the something incriminating being discussed in group chat previously happened in the real world. Ripples of information were created there and can be found (paral…
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#165Earlier quoted context omitted.
Maybe. I think they'd have a hard time keeping that under wraps—governments aren't typically very careful (and the FBI is about as careful as a bull in a china shop) about not showing their hand when it comes to charging people. If you're strict about keeping certain info on certain channels, smart observers would notice if someone were snooping. For instance, if someone shared something incriminating in a group chat…
> For instance, if someone shared something incriminating in a group chat and got arrested, and that info was only shared in the group chat, they'd have to silence everyone in that group chat to ensure that the channel still seemed secure. Corrupt investigators can use parallel construction to pretend that the key breakthrough in the case was actually something legal.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#166Earlier quoted context omitted.
It might be related to this [2015] but that was a hoax. https://news.ycombinator.com/item?id=9374028
No, it was something else but I can't find it via HN search anymore. I think it was in 2013-2014, which is timeframe when I deleted my FB account (that for some reason kept living for many years as I was told).
Onavo Protect, the VPN client from the data-security app maker acquired by Facebook back in 2013, has now popped up in the Facebook iOS app itself, under the banner “Protect” in the navigation menu. Clicking through on “Protect” will redirect Facebook users to the “Onavo Protect – VPN Security” app’s listing on the App Store.
https://techcrunch.com/2018/02/12/facebook-starts-pushing-it...
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#167Earlier quoted context omitted.
> someone shared something incriminating in a group chat and got arrested, and that info was only shared in the group chat “Only” is doing an incredible amount of work there. Unless you concoct something incriminating solely for the purpose of testing this, the something incriminating being discussed in group chat previously happened in the real world. Ripples of information were created there and can be found (paral…
Right, but parallel construction only works if opsec fails. Good luck with repeating that feat forever. You clearly have far more faith in the FBI than I do. Now repeat this feat for every dumbass in intelligence in every country.
If they fail in parallel construction, they always have the option to continue. For the vast majority of cases where opsec isn't 100% foolproof, we hear about them. For the few cases where it was foolproof, we just don't hear about them.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#168If you haven't already: Signal is the strongest independent e2e encrypted consumer app that is driven by a non-profit organisation using a zero knowledge approach.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#169Earlier quoted context omitted.
But the crucial bit to know here would be if that data was readable in anyway in case it was accessed? Personally it doesn't matter if there are auditing systems in place, if the data is readable in any way, shape or form.
is that really true? I haven’t touched a lot of these cyber security parts of industry: especially policies for awhile… … but I do recall that auditing was a stronger motivator than preventing. There were policies around checking the audit logs, not being able to alter audit logs and ensuring that nobody really knew exactly what was audited. (Except for a handful of individuals of course.) I could be wrong, but “obse…
No amount of internal auditing, externally verified and stamped with approval for following ISO standards theater will change the fact that as a company it has firebombed each and every bridge that was ever available to it, in my book.
If the data has the potential to be misused, that is enough for me to equate it as not secure for use.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#170That's rather surprising about the accessing user data bit. When I was at Meta, the quickest way to get fired as an engineer was to access user data/accounts without permission or business reason. Everything was logged/audited down to the database level. Can't imagine that changing and the rules are taught very early on in the onboarding/bootcamp process.