Live data from Hacker News

WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

medium.com

21–30 of 53 posts

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#21

The article opens with a statement by Telegram co-founder Pavel Durov who claims that WhatsApp shared Messages with third parties while Telegram "never did and never will" do that. Now, Telegram doesn't use End-to-End encryption by default at all, does it? What I mean is: The message is encrypted on the sender's device and can only be decrypted on that and the receiver's device. Telegram uses transport layer encrypti…

Yes, the article lost a significant amount of credibility right from the start by bringing up Durov and his well-known, ongoing rivalry with WhatsApp.

Telegram is a much worse messenger when it comes to E2E encryption and default settings.

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#22
Feels AI generated ("linkedin-style" short sentences, blob of malformated text towards the bottom), so I'll give myself the permission to skim and take shortcuts.

The most interesting claim is the weakness of groups (the article claims the server controls who is a group member, without cryptographically secured authorization by an existing member).

The other key points are correct to my knowledge but unsurprising to anyone knowledgeable and partially apply to Signal too (backups are a weak point, you securing/disabling them properly doesn't protect you, metadata is unprotected and sensitive, participants in the conversation might upload the chat to Meta's AI, endpoints are attackable either through WhatsApp or other apps, the general trust issue - which isn't really resolved by being open source unless someone actually checks the reproducible builds AND someone reviews the code).

I thought that claim about the backup password hash was wrong, but https://www.nccgroup.com/media/fzwdxklh/_ncc_group_whatsapp_... suggests that Meta thought that 100k iterations of PBKDF2 are a reasonable choice for the key derivation, so it might actually be accurate.

AFAIK WhatsApp backups are, by default, encrypted with a key escrowed to WhatsApp (which means that an attacker using warrants now has to subpoena both the cloud provider and whatsapp - probably the best you can get while keeping backups usable for the 99% of people who can't be expected to write down a passphrase and still have it when asked).

But IMO the reality is that WhatsApp is the most secure messenger that you can expect normal people to actually use (mostly due to market share/network effect), and the only secure-ish messenger aside from Signal, so I'd be careful with the messaging towards "normies": "Signal is a much better choice, but out of the other options, Whatsapp is by far the least bad".

Otherwise, you end up with people picking something like Telegram because "it's all bad anyways" or "I've heard Telegram is secure".

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#23
This is just bad. The writing is more horrible Claude garbage. It also begins with this quote from Durov:

> Despite its claims, it reads users’ messages and shares them with third parties.

Note this claim. When it goes into its first smoking gun,

> WhatsApp [...] automatically backs up your entire chat history to iCloud or Google Drive

> This is what Durov meant. This is why he said ~95% of messages end up in plain text on Apple/Google servers.

This is the closest the article ever comes to proving the claim at the front. Note that nothing in this claim implies that Meta can or is reading your messages, only that it is "sharing" them with a third party, so we still haven't actually successfully justified this quote.

It then rambles over just about every security controversy WhatsApp has ever had: bugs, design flaws, etc.

Okay. Then it mentions that sometimes when you're talking to a business it's actually Meta servers on the other end of the encryption, I guess. This again seems like it doesn't really prove anything.

I am not saying none of these issues are problems, but this literal dump of AI output into Medium can't even justify its primary claim. It just keeps throwing more shit at you and hopes you've forgotten what the bold claim at the front of the article actually said was, since it isn't really true.

I do not believe Matrix is a scam, but it has almost all of these problems in some form aside from the stupid Cloud Backups issue, only its a bit more complicated. It has CVEs, generates tons of metadata and several places where homeservers could attempt to attack your privacy.

Durov's platform, meanwhile, offers very little in the way of end-to-end encryption and of course generates a ton of unencrypted metadata, so I am not sure who he's fooling. It seems like they continuously brag about Telegram not being able to solve the E2EE key management problem by pointing out that other solutions are imperfect, whereas Telegram just doesn't have one. Congratulations?

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#24
post #4

Absolutely, it can be encrypted all they want and it's totally irrelevant given all the plaintext chats get stored straight in Google Drive (if you didn't, your conversation partners did!). Then for some reason WhatsApp has far more critical no-click or 1-click exploits than Telegram, which has 30 global employees? Huh? There's several thousand working on WhatsApp. Telegram has more features, too. WhatsApp has less s…

Maybe it's just a matter of how much effort people put into finding exploits on the two apps. If WhatsApp has many more (actual) users than Telegram, researching exploits on WhatsApp is more worth researching on WhatsApp than Telegram

A bit like how there's much more malware for Windows than there is for Linux

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#25
For anyone wondering what the actual purported security weaknesses are in this article (I used the slop machine to reduce the slop):

- Cloud backups — by default, backups to iCloud/Google Drive contain plaintext messages, and E2EE backup is opt-in. Even if you enable it, a weak password collapses the effective security, and any other person in the chat with an unencrypted backup exposes the conversation.

- Metadata — who you talk to, when, how often, IP, contact graph, etc. This is the "reading your life without reading your messages" argument, and it's the part that's genuinely well-established.

- Pen register / FBI — the claim that WhatsApp uniquely delivers near-real-time metadata (~every 15 min) to law enforcement.

- Group chat membership integrity — a server-level adversary can inject a member into a group; messages stay encrypted but get delivered to the injected party. Endpoint compromise (Pegasus / CVE-2019-3568) — encryption is irrelevant if the device is owned.

- Closed source, Meta AI, business accounts — content can leave the E2EE envelope in those flows.

Nothing really new here, and as everyone else is pointing out Telegram might be worse.

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#26

The article opens with a statement by Telegram co-founder Pavel Durov who claims that WhatsApp shared Messages with third parties while Telegram "never did and never will" do that. Now, Telegram doesn't use End-to-End encryption by default at all, does it? What I mean is: The message is encrypted on the sender's device and can only be decrypted on that and the receiver's device. Telegram uses transport layer encrypti…

> Now, Telegram doesn't use End-to-End encryption by default at all, does it? Underrated fact. Also, no one knows who exactly operates Telegram and IIRC they don't even have an office. But we know Russian authorities have intense interest in it so it's hard to imagine FSB wouldn't figure out who it is and knock on their (or their relatives still in Russia) door. We know that Russian authorities previously banned Tele…

AFAIK, the FSB knocked on Durov’s previous company’s door, VKontakte, a Russian Facebook knock-off.

They asked for info on some of their users, were told “no” and… they told Durov that “it would be a good idea if you sold this thing to someone else”.

Which he did, for decent money but probably a lot less than it was worth. He then used that money to start Telegram, at first from Berlin and later on from Dubai, from 2017 I think.

VKontakte (VK) eventually created Max, a newish IM service that the tiger-fighting shortie at the Kremlin is pushing onto Russians, while trying to limit their use of Telegram, that is or at least was the standard in Russia.

https://www.theatlantic.com/international/archive/2025/10/ru...

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#27
post #4

Absolutely, it can be encrypted all they want and it's totally irrelevant given all the plaintext chats get stored straight in Google Drive (if you didn't, your conversation partners did!). Then for some reason WhatsApp has far more critical no-click or 1-click exploits than Telegram, which has 30 global employees? Huh? There's several thousand working on WhatsApp. Telegram has more features, too. WhatsApp has less s…

Several thousand employees means several thousand chances per working day to create a security breach.

I suspect that smaller teams are, on average, more likely than larger ones to write secure software.

Re: WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History

#29
post #21

The article opens with a statement by Telegram co-founder Pavel Durov who claims that WhatsApp shared Messages with third parties while Telegram "never did and never will" do that. Now, Telegram doesn't use End-to-End encryption by default at all, does it? What I mean is: The message is encrypted on the sender's device and can only be decrypted on that and the receiver's device. Telegram uses transport layer encrypti…

Yes, the article lost a significant amount of credibility right from the start by bringing up Durov and his well-known, ongoing rivalry with WhatsApp. Telegram is a much worse messenger when it comes to E2E encryption and default settings.

depends, at least he didn't claim that telegram is encrypted. the problem is that whatsapp encryption gives you a false sense of security, which arguably is worse than knowing your messages are not encrypted.
Post reply on HN