Live data from Hacker News

US has investigated claims WhatsApp chats aren't private

bloomberg.com

321–330 of 387 posts

Re: US has investigated claims WhatsApp chats aren't private

#321
post #285

Earlier quoted context omitted.

We probably can't make it free for all, but for something like a messaging app, we also need to recognize that it isn't optional to function in society. It should be regulated more like a utility: - Facebook can still control the identity, but there needs to be a legal recourse for getting banned, and their policies can't discriminate against viewpoints, for example - The client specs should be open so that an altern…

> but there needs to be a legal recourse for getting banned Agreed. > The client specs should be open so that an alternate client can be implemented An example that comes to mind is Signal, where they don't want that. They get a lot of criticism for it of course, but I think it the reasoning actually makes sense: in terms of security, allowing third-party clients is a security risk. If your threat model is "people wh…

I was intending that the alternate client should exist to function as an escape hatch. I fully expect most people will still use the default one, just like how people used the official reddit/telegram client when third party ones were available. The existence of an alternative constrains how much Facebook can enshittify the experience.

E2EE is about secure transport between the endpoints. What happens to the message after the endpoint is not something an app can feasibly enforce. Having control of the clients can at most do things like enforcing deletes, which IMO is not a good idea anyway.

> every second client was pretty much a spyware

Very few people will actually use one since the official app won't be outwardly too hostile, and those who do should be sufficiently discerning.

Re: US has investigated claims WhatsApp chats aren't private

#322
post #274
post #256

Earlier quoted context omitted.

Can they control private keys and do replay attacks?

Signal protocol prevents replay attacks as every message is encrypted with new key. Either it's next hash ratchet key, or next future secret key with new entropy mixed via next DH shared key. Private keys, probably not. WhatsApp is E2EE meaning your device generates the private key with OS's CSPRNG. (Like I also said above), exfiltration of signing keys might allow MITM but that's still possible to detect e.g. if you…

Wouldn't ratchet keys prevent MITM too? In other words if MITM has your keys and decrypts your message, then your keys are out of sync from now on. Or do I misunderstand that?

Re: US has investigated claims WhatsApp chats aren't private

#323

Ex-WhatsApp engineer here. WhatsApp team makes so much effort to make this end to end encrypted messages possible. From the time I worked I know for sure it is not possible to read the encrypted messages. From business standpoint they don’t have to read these messages, since WhatsApp business API provide the necessary funding for the org as a whole.

The backups are either unencrypted by default or have keys held by Meta / your backup provider. I think this means three-letter agencies can see your chats, just with a slight delay.

Another comment above mentions that you can recover conversation histories with just your phone number--if that's true then yup. The E2EE is all smoke and mirrors.

Re: US has investigated claims WhatsApp chats aren't private

#324

Just to throw in a couple of possibly outlandish theories: 1. as others have said, they could be collecting the encrypted messages and then tried to decrypt them using quantum computing, the Chinese have been reportedly trying to do this for many years now. 2. with metadata and all the information from other sources, they could infer what the conversation is about without the need to decrypt it: if I visit a page (Fa…

It's the backups. The backups aren't encrypted such that only the end-user has the key.

Re: US has investigated claims WhatsApp chats aren't private

#325
post #164
post #128

Earlier quoted context omitted.

> There's the conspiracy theory about mentioning a product near a the phone and then getting ads for it (which I don't believe) Well you sure as hell should. Both Google and Apple are making class action settlement payments right now for this very thing. https://www.bbc.com/news/articles/c4g38jv8zzwo https://www.nbcchicago.com/news/local/payments-begin-in-95m-... https://www.404media.co/heres-the-pitch-deck-for-activ…

> https://www.bbc.com/news/articles/c4g38jv8zzwo > https://www.nbcchicago.com/news/local/payments-begin-in-95m- ... Both are for voice assistants that inadvertently got activated. Extending it to imply that they're intentionally deceiving their users is a stretch. > https://www.404media.co/heres-the-pitch-deck-for-active-list ... It's a pitch deck. For how skeptical HN is about AI startups or whatever, it seems prett…

> Extending it to imply that they're intentionally deceiving their users is a stretch.

If you say so. They directly profited from it.

Re: US has investigated claims WhatsApp chats aren't private

#326

Earlier quoted context omitted.

They also decide what public key is associated with a phone number, right? Unless you verify in person.

That's protected cryptographically with key transparency. Anyone can check what the current published keys for a user are, and be sure they get the same value as any other user. Specifically, your wa client checks that these keys are the right key.

Even if your client is asking other clients to verify, what if everyone has the same wrong key for a particular user Whatsapp has chosen to spoof?

Re: US has investigated claims WhatsApp chats aren't private

#327

Earlier quoted context omitted.

It sounds like your salary has depended on believing things like a partial audit is worthwhile in the case that a client is the actual adversary.

Except Meta is not an adversary. They are aligned with people who want private messaging.

Brutal sarcasm.

Re: US has investigated claims WhatsApp chats aren't private

#328
post #314

Earlier quoted context omitted.

Or they could even take out the backdoor code and then put it back in after review.

This is why signal supports reproducible builds.

In this day and age, in a world with Docker and dev containers and such, it's kind of shocking that reproducible builds aren't table stakes.

Re: US has investigated claims WhatsApp chats aren't private

#329
post #325
post #164

Earlier quoted context omitted.

> https://www.bbc.com/news/articles/c4g38jv8zzwo > https://www.nbcchicago.com/news/local/payments-begin-in-95m- ... Both are for voice assistants that inadvertently got activated. Extending it to imply that they're intentionally deceiving their users is a stretch. > https://www.404media.co/heres-the-pitch-deck-for-active-list ... It's a pitch deck. For how skeptical HN is about AI startups or whatever, it seems prett…

> Extending it to imply that they're intentionally deceiving their users is a stretch. If you say so. They directly profited from it.

So? You "directly profit" from picking up a bundle of cash robbers dropped as well doing the actual robbery. That doesn't mean someone who does the former is going to do the latter.

Re: US has investigated claims WhatsApp chats aren't private

#330
post #221

Earlier quoted context omitted.

>If you have to do a thing that obscures your act it doesn’t change the fact that there are rules for me and not them. We know for a fact they did it. Did their ISP threaten them? Did they get their internet service shut off? Is there any indication they didn't use a VPN? If they did use a VPN, how is it "there are rules for me and not them", given that anyone can also use VPN to pirate with impunity?

I don’t understand what you’re doing here. They were caught. We know they did it. There are several articles about it. They have been sued over it because it happened. I don’t think anything will come of it, but they clearly did it. It is public knowledge.

You claim there's some two tier legal system for Meta compared to the average torrenter, by virtue of their internet not getting cut off. However that's a false premise. You only get your internet cut off if you fail to use a VPN. If Meta used a VPN (like most pirates do), then their internet staying up isn't evidence of any special treatment.

If there's some two tier treatment of Meta, it's that they're being sued more aggressively than the average pirate. If you pirated Stranger Things, you can blab all you want about your copyright infringement escapades, and you'll unlikely never face any legal consequences. OTOH once word got out that Meta torrenting books, every copyright lawyer out there is going after them.

Post reply on HN