Earlier quoted context omitted.
Right, but parallel construction only works if opsec fails. Good luck with repeating that feat forever. You clearly have far more faith in the FBI than I do. Now repeat this feat for every dumbass in intelligence in every country.
My position doesn’t require a lot of faith in the FBI. If they fail in parallel construction, they always have the option to continue . For the vast majority of cases where opsec isn't 100% foolproof, we hear about them. For the few cases where it was foolproof, we just don't hear about them.
Ex-WhatsApp cybersecurity head says Meta endangered billions of users
181–190 of 192 posts
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#182Earlier quoted context omitted.
See the sibling comment. The odds of nobody noticing still don't make any sense.
PRISM went undetected for a long, long time and it's essentially a wiretapping of the entire internet. Clearly, you are underestimating the intelligence and capabilities of the US government. They have a lot of money. Like... A lot of money.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#183Earlier quoted context omitted.
It is huge in Latin America. USA is special because it is the (only?) country where iPhone has more users than Android.
Yeah, huge in Latin America in the sense that a lot (most?) business only have a number that they use with Whatsapp (you can't call or even text them). Is it the same in Europe? Since I am from Latin America I never know if people from other continents use Whatsapp as much as we do, and if when I ask them to use Whatsapp I am imposing a new app or it's what they regularly use.
If you give someone your number, they’ll text you on WhatsApp.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#184Earlier quoted context omitted.
Ok, what do you suggest instead?
I think Signal is the safest choice. If you want to be absolutely sure, host your own service, and hope you know how to make it have airtight security.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#185Earlier quoted context omitted.
Everything is logged, but no one really cares, and the "business reasons" are many and extremely generic. That being said, maybe I'm dumb but I guess I don't see the huge risk here? I could certainly believe that 1500 employees had basically complete access with little oversight (logging and not caring isn't oversight imo). But how is that a safety risk to users? User information is often very important in the day to…
You really don't see the safety risk? If you have a sister,imagine her being stalked by an employee? If you have crypto, imagine an employee selling your information to a third party?
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#186Earlier quoted context omitted.
We don't really know that messages really are end-to-end encrypted though, do we? Is there a way to actually check that the messages in transit are encrypted in a way that only the other end can decrypt them? If not, we have to take Meta's word for it, which frankly doesn't carry much weight.
Not trivially. But with painstaking reverse engineering you could prove this. And people have, so you're not exclusively just taking Meta's word. The fact that Pegasus malware relied on remote code execution vuln to run malware on your phone to extract WhatsApp messages, really suggests that the E2EE works. If it wasn't E2EE, then the makers of Pegasus could have just intercepted traffic to get your messages. Academi…
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#187Earlier quoted context omitted.
Not trivially. But with painstaking reverse engineering you could prove this. And people have, so you're not exclusively just taking Meta's word. The fact that Pegasus malware relied on remote code execution vuln to run malware on your phone to extract WhatsApp messages, really suggests that the E2EE works. If it wasn't E2EE, then the makers of Pegasus could have just intercepted traffic to get your messages. Academi…
This does not prove that Meta does not have the ability to decrypt the messages.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#188Full text of the lawsuit: https://www.bloomberglaw.com/public/desktop/document/BaigvMe...
Here is 115 pages: https://storage.courtlistener.com/recap/gov.uscourts.cand.45... from here: https://www.courtlistener.com/docket/71293063/baig-v-meta-pl... This further surprised Mr. Baig, as WhatsApp, which is known for its strong security brand externally, had such a small security team of just 6 engineers, and they were all only working on this tiny aspect of application security. All the other teams in WhatsApp…
≥ Company refused to allocate more than around 10 engineers to the Security team at any point
If true, this tells the story here with security culture at WhatsApp. Assuming a backlog of known weaknesses (as any established code base will have), and the velocity that 100 PMs and 1200 SWEs implies, how would you do anything as a security team besides stick your fingers in the figurative holes in the dike? The ensuing conflict between Baig and his superiors about not fixing stuff is surely going to result in an assessment of "poor performance" but is likely just Baig giving a f** about user data.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#189Earlier quoted context omitted.
He got fired unjustly. For trying to do something good. (His position.) Any full remedy would require his position is reinstated. If he wins the right to be reinstated, he will be happy to negotiate a payment instead. He is made whole. What about any of that lacks sensible motives?
Nothing, but there's something in your comment that was not in the article: > he will be happy to negotiate a payment instead . This, indeed, sounds way more normal than wanting to keep working for the evil company, and in a toxic environment. It hasn't occurred to me that one can change their mind and choose a different compensation after the court decision like that.
You don't negotiate with what you don't have yet. But the idea that he or they would actually want to resume working together is beyond unlikely. They will be happy to pay for him to go away, if that's the only way they can legally get rid of him.
Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users
#190Earlier quoted context omitted.
There’s a meaningful difference in a company wanting to exploit user data to enrich itself and allowing employees to engage in voyeurism. The latter doesn’t make the company money, and therefore can be penalised at no cost. Your comment talks about incentives, but you haven’t actually made a rational argument tying actual incentives to behaviour.
My point is that it would be naive to believe that a company whose revenue depends on exploiting user data has internal measures in place to ensure the safe handling of that data. In fact, their actions over the years effectively prove that to not be the case. So whatever they claim publicly, and probably to their low-level employees, is just marketing to cover their asses and minimize the impact to their bottom line…
You claim it’s all talk, but it’s not much more effort to walk the walk. It doesn’t hurt profits to do it.