Earlier quoted context omitted.
If you want secure your top choices, in my opinion, are Signal and Wire -- and I like Wire better because I can sign up with a burner account or seemingly random alias on my ProtonMail account. But don't just take my word for it -- here's a good place to start your own research: https://www.securemessagingapps.com/
Why is Wechat missing on that list?
NSO hacked WhatsApp to spy on top government officials at U.S. allies
281–290 of 321 posts
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#282Earlier quoted context omitted.
You have it correct. Nearly every major US provider maintains some sort of online interface for law enforcement to submit requests. The level of information provided via these means varies, but they are obligated to respond to legitimate requests with wharever data they have on hand. Dont like it? Go with a security-minded service like signal. Or, better yet, something totally severless and open source.
I don't use WhatsApp. But if they have an official backdoor, then it's not really e2e encrypted. Until now I thought, at least the official statement was, WhatsApp is truly e2e encrypted. Just that.
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#283Earlier quoted context omitted.
Even of they implement the Signal protocol, they have additional modifications to support ads, which increases the attack surface.
Does WhatsApp have ads?
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#284What's the deal with the end-to-end encryption here, I don't understand. If you get control over the server, you can circumvent it with WhatsApp? How did the attackers get hold of the private keys?
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#285Earlier quoted context omitted.
You have it correct. Nearly every major US provider maintains some sort of online interface for law enforcement to submit requests. The level of information provided via these means varies, but they are obligated to respond to legitimate requests with wharever data they have on hand. Dont like it? Go with a security-minded service like signal. Or, better yet, something totally severless and open source.
I don't use WhatsApp. But if they have an official backdoor, then it's not really e2e encrypted. Until now I thought, at least the official statement was, WhatsApp is truly e2e encrypted. Just that.
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#286Earlier quoted context omitted.
> Unfortunately people often don't have the luxury of doing the latter. What? Just don't install the Facebook or other social apps. I do have Telegram, but no other social media apps on my phone. If you need to communicate, then SMS / MMS / telephone is fine. What can be done with Facebook that cannot be done with normal SMS or MMS or phone calls or video calls?
I also don't have any facebook apps on my phone - but from what I understand there are countries where whatsapp is how a lot of business is done. If you can't afford the time and opportunity cost of avoiding those businesses you have to install it.
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#287"Prior to notifying victims, WhatsApp checked the target list against existing law enforcement requests for information relating to criminal investigations, such as terrorism or child exploitation cases. But the company found no overlap, said a person familiar with the matter. Governments can submit such requests for information to WhatsApp through an online portal the company maintains." There is already an official…
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#288"Prior to notifying victims, WhatsApp checked the target list against existing law enforcement requests for information relating to criminal investigations, such as terrorism or child exploitation cases. But the company found no overlap, said a person familiar with the matter. Governments can submit such requests for information to WhatsApp through an online portal the company maintains." There is already an official…
You have it correct. Nearly every major US provider maintains some sort of online interface for law enforcement to submit requests. The level of information provided via these means varies, but they are obligated to respond to legitimate requests with wharever data they have on hand. Dont like it? Go with a security-minded service like signal. Or, better yet, something totally severless and open source.
There's no security-minded service which use Google services.
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#289Use Matrix (Riot.im is a great client) Or Signal, but without the phone number signup
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#290Earlier quoted context omitted.
>Given that Android exploits are far more common than iOS, I would expect they had one of those too. The Pixel was the only device that was not pwned in the 2017 Mobile Pwn2Own competition - the iPhone, running iOS 11.1, was exploited 4 times via both WiFi and Safari. I'd be incredinly surprised if NSO were able to compromise an up to date Pixel phone.
That’s great for the Pixel. But what percent of Android phones are the Pixel, and not one of the hundreds of other varieties with varying patch schedules? (That’s not entirely snark. I do wonder how high risk individuals are choosing which devices they use for communication.)