Live data from Hacker News

Ex-WhatsApp cybersecurity head says Meta endangered billions of users

theguardian.com

171–180 of 192 posts

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#171
post #108

Earlier quoted context omitted.

Whatever Meta says publicly about this topic, and whatever its internal policies may be, directly contradicts its behavior. So any attempt to excuse this is nothing but virtue signalling and marketing. The privacy violations and complete disregard for user data are too numerous to mention. There's a Wikipedia article that summarizes the ones we publicly know about. Based on incentives alone, when the company's primar…

There’s a meaningful difference in a company wanting to exploit user data to enrich itself and allowing employees to engage in voyeurism. The latter doesn’t make the company money, and therefore can be penalised at no cost. Your comment talks about incentives, but you haven’t actually made a rational argument tying actual incentives to behaviour.

There is actually no difference, only a difference in intent.

The problem is similar to that of government efforts to ban encryption: if you have a backdoor, everyone has a backdoor.

If Meta is collecting huge amount of user info like candy (they are) and using it for business purposes (they are), then necessarily those employees implementing those business purposes can do that, too.

You can make them pinky promise not to. That doesn't do anything.

Meta has a similar problem with stalking via Ring camera. You allow and store live feeds of every Ring camera? News flash: your employees can, too! They're gonna use that to violate your customers!

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#172
post #112

Earlier quoted context omitted.

> For instance, if someone shared something incriminating in a group chat and got arrested, and that info was only shared in the group chat, they'd have to silence everyone in that group chat to ensure that the channel still seemed secure. Corrupt investigators can use parallel construction to pretend that the key breakthrough in the case was actually something legal.

See the sibling comment. The odds of nobody noticing still don't make any sense.

PRISM went undetected for a long, long time and it's essentially a wiretapping of the entire internet.

Clearly, you are underestimating the intelligence and capabilities of the US government. They have a lot of money. Like... A lot of money.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#173

Given how WhatsApp is the de-facto way to communicate outside of the West and China, these security/data-handling "weaknesses" are most likely a feature, not a bug. An absolute bonanza for the certain intelligence services. Remember, kids: End to end encryption is useless if the "ends" are fully controlled by an (untrustworthy) third party.

From the article:

> According to the 115-page complaint, Baig discovered through

> internal security testing that WhatsApp engineers could “move

> or steal user data” including contact information, IP addresses

> and profile photos “without detection or audit trail”.

That isn't really the breach you're making it out to be. Profile photos, unless made private/contacts only, are already publicly visible, and so is "contact information".

Of course these are useful to intelligence services, but this doesn't mean that Baig found they don't have true end-to-end encryption.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#174
post #6
post #4

So much for that e2e encryption that HN claimed was so good and that META couldn’t possibly use what’s app messages to do advertising from.

Messages are e2e and WA doesn't have access to them. We're talking about the metadata here. From the article: > including contact information, IP addresses and profile photos I can confirm this, I used to work at WhatsApp.

> Messages are e2e and WA doesn't have access to them. We're talking about the metadata here.

You're still just blindly trusting this is the case. You can't verify the encryption or any of the code.

It would be trivial to actually encrypt the message and send it out and then store an unecrypted version locally and quietly exfiltrate it later.

They have to already be storing an unecrypted version locally, because you can see the messages. So unless your analyzing packets on the scale of months or years, you cannot possibly know that it isn't being exfiltrate at some point.

Take it a step further: put the extiltration behind a flag, and then when the NSA asks, turn on the flag for that person. Security researchers will never find it.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#175
post #104

> Attaullah Baig, who served as head of security for WhatsApp from 2021 to 2025, claims that approximately 1,500 engineers had unrestricted access to user data without proper oversight, potentially violating a US government order that imposed a $5bn penalty on the company in 2020. If it results in a new billion-dollar penalty, maybe it would've saved money to move him quietly to a cushy rest-and-vest advisory positio…

Now that penalty is a weapon for the president to use when he's mad at Zuckerberg.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#177
post #153
post #145

Earlier quoted context omitted.

Pretty sure this is wrong, at least in the case of WhatsApp. If an app sends the message content in clear through the notifications, then it is badly designed, period.

Agreed. As I recall the way notifications work on Signal/WhatsApp is the app receives some silent notification that wakes it up, then the app does its crypto thing, and then it locally triggers the notification with the decrypted content you see. In iOS land your app needs a special entitlement to work this way. It also means if you're on very heavy group chats your battery will drain faster. If WhatsApp central serv…

Fair point. For E2EE messaging apps, metadata often includes encrypted message content. As others have stated, the unencrypted metadata (eg. message recipient) can be potentially be damning enough on its own.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#178
If a company can become a mega company by having billions of users, small violations must be treated as larger. At some point impacting millions/hundreds of millions of human years a year by your practices rises above the 'it's a small inconvenience to a single person'.

You are costing society/humanity millions/hundred of millions of human years. That is not a 'small inconvenience' at this scale.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#179

If a company can become a mega company by having billions of users, small violations must be treated as larger. At some point impacting millions/hundreds of millions of human years a year by your practices rises above the 'it's a small inconvenience to a single person'. You are costing society/humanity millions/hundred of millions of human years. That is not a 'small inconvenience' at this scale.

[dead]

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#180

Earlier quoted context omitted.

> outside of the West you probably mean outside of the USA, it's huge in Europe/UK (which doesn't contradict your main point)

I would have thought he meant "inside of the West". Outside of the West you have other channels. Russia: Telegram Taiwan: Line Japan: Line By contrast, WhatsApp is best known to me for being used in Europe, Australia, and India.

Central Asia is Telegram as well.
Post reply on HN