Live data from Hacker News

Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

news.ycombinator.com

361–370 of 473 posts

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#361

Earlier quoted context omitted.

Quoted post unavailable.

> This way too I can troll people on the internet when they suspect this is happening and I can say "bUt ThE bAtTeRy LiFe!" to defend Meta: my corporate overlord business daddy. Please, stop with the sarcasm. Okey, let’s say they manage to record us without a huge impact on our battery life. Now, how do you send these recordings or even the extracted keywords from a popular app, a client installed on devices controll…

Great question! I'd love a peek at their source code to figure out these answers too!

I swear that comment is sarcasm free.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#363
post #216

Earlier quoted context omitted.

A simpler protocol to realize that the Baader-Meinhof phenomenon is probably what's happening: - pick said topic, something you never cared about before, talk about it but don't write any messages containing it; - for 1 month record every ad you see about it; - send a message about the topic; - for another month, record every ad you see about it Comparing the number of occurrences will tell you what is happening.

It also has to be a topic that advertisers would pay to target you with. You can't talk about something super obscure that advertisers don't care about - like steam engines.

Thanks for this!! Now my email is full of offers to buy historical steam engines, steam engine parts, and engineer hats. Amazon is even advertising a subscription for coal deliveries!

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#364

(wrt some comments in this thread) Is it so hard to believe that Meta is snooping on WhatsApp conversations? Meta, a company of unprecedented size that was built over monetizing your private data? A company who's been caught in plenty of scandals (like Cambridge Analytic) about this exact sort of thing (violating their users' privacy)? Someone from this community, which generally means educated, tech-literate and sen…

The most plausible explanation is that people are just easy to predict. Might be tough to admit, but that’s actually a much simpler explanation than Facebook having a back door into our messages, which are end-to-end encrypted. As others above me have thoroughly explained, there are numerous ways Facebook could figure out what you’re reading about/listening to/viewing on the internet, which ultimately drives what you…

[deleted]

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#365

As someone who has actually worked on end to end encryption at Meta, I can tell you I am not aware of anything where the company reads your WhatsApp messages - either in transit or device. The company takes fairly serious measures to ensure it cannot even accidentally infer such contents. I don't know what is happening in this specific case. Perhaps the ads came from some other similar search queries. Perhaps they ca…

Thanks for your explanation.

I didn't have in mind the scenario of a keyboard logging user inputs besides the normal functionality of WhatsApp. I find this theory to be very plausible. Not at all happy with Meta's privacy policy, but I agree that it is worth considering other threats.

From using a VPN that logs all incoming and outgoing traffic (NetGuard) on an Android One device, I've noticied that the default Google keyboard gets in touch way too many times with some distant servers. Whereas, an open source keyboard from F-Droid, FlorisBoard, does no snooping and gets updated solely through the app store.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#366
post #97

Earlier quoted context omitted.

Considering how easy it is to implement these things without anyone noticing since it's closed source, you have to assume it is happening in any scenario where you need any decent opsec. Even in scenarios where you don't, there's been enough cases of similar things happening with well-known apps and services to be wary.

> Considering how easy it is to implement these things without anyone noticing since it's closed source You can reverse engineer those things and analyze your network traffic. You can’t have a client in a device controlled by the user, in this case an app, send anything to a server without anyone noticing it. And frankly, they don’t even need it. Just with your contacts they can link you to your friends and common in…

> You can reverse engineer those things and analyze your network traffic.

I frankly don't think people realize how much obfuscation of both app code and network traffic goes on under the hood. "analyzing network traffic" isn't a sustainable option when things are encrypted and behind dozens of layers of protobuf, websockets and other fancy protocols, and get updated and change around all the time. Far from everything is introspectable http, javascript and json these days, and that applies espeically to big apps like these. It's not hard to send privacy-sensitive data along with "legitimate" data like analytics at unexpected times and evade scrutiny.

Yes there's people that dedicate themselves to reverse engineering apps like this, but they're few and far between, and most of them focus on either the easy fish, or security vulns. Considering nobody's building public documentation on the protocols of these apps I'll have to assume it's hard enough and changes often enough to be worth the time of people without special monetary interests.

I agree with the rest of your assessment, there's way less "obviously malicious" ways to exfiltrate data about users than literally uploading users' pictures, since for example whatsapp stored unencrypted backups on google drive until very recently, among other things. I'm just trying to shed a light on the fact that apps like this have a lot of ways to accomplish this without raising too many eyebrows.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#367

(wrt some comments in this thread) Is it so hard to believe that Meta is snooping on WhatsApp conversations? Meta, a company of unprecedented size that was built over monetizing your private data? A company who's been caught in plenty of scandals (like Cambridge Analytic) about this exact sort of thing (violating their users' privacy)? Someone from this community, which generally means educated, tech-literate and sen…

The most plausible explanation is that people are just easy to predict. Might be tough to admit, but that’s actually a much simpler explanation than Facebook having a back door into our messages, which are end-to-end encrypted. As others above me have thoroughly explained, there are numerous ways Facebook could figure out what you’re reading about/listening to/viewing on the internet, which ultimately drives what you…

Seriously? Facebook knows their internal thoughts well enough to guess what topics they would choose when trying to pick something they "never talk about"?

If FB could do that, then FB would realize that these topics are not actually products they are interested in, so they wouldn't be showing ads.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#368
post #5

Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. Meta has control over the app Sue uses. So they could send them to Meta unencrypted in addition to sending them to Joe in an encrypted fashion. Or they just extract the relevant terms: Sue->Joe: "Hello Joe, I'm so excited! We are going to have a baby! Let's call it Dingbert. You're not the father! Ji…

But the problem arises, I think, is when they say they can't read them: "WhatsApp's end-to-end encryption is used when you chat with another person using WhatsApp Messenger. End-to-end encryption ensures only you and the person you're communicating with can read or listen to what is sent, and nobody in between, not even WhatsApp." https://faq.whatsapp.com/general/security-and-privacy/end-to...

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#369
post #359

Earlier quoted context omitted.

That's still Facebook's problem, no excuses. Facebook absolutely has the power and resources to lobby google and congress. Security teams at both companies will unequivocally agree that keylogging presents an extremely grave security risk that consumers are unlikely to understand the consequences of and therefore need to be protected from. Imagine a hapless military professional/politician downloading one. The proble…

That 3rd-party keyboard would also be able to log your Signal messages, so I don't get your point.

If the original post is true and Facebook is leaking message based data into systems that produce ads (3rd party or 1st party), they have a responsibility to diagnose and resolve the issue. Despite their responsibility to do so, they are not aligned with doing so.

Excuses like "the user did something bad" aren't productive.

A warning that the users expectations (secure communications) do not match reality (3rd party keylogged communications) seems like the minimum level of responsibility:

https://maheshikapiumi.medium.com/allowance-of-third-party-k...

If WhatsApp derived information is being seen in advertisements, it is Facebook's responsibility. It is in Facebooks best (next quarters profits based) interests to not be responsible.

Re: Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?

#370

As someone who has actually worked on end to end encryption at Meta, I can tell you I am not aware of anything where the company reads your WhatsApp messages - either in transit or device. The company takes fairly serious measures to ensure it cannot even accidentally infer such contents. I don't know what is happening in this specific case. Perhaps the ads came from some other similar search queries. Perhaps they ca…

Meta has repeatedly demonstrated they will do whatever it takes to capture user data. Kid VPNs, in app browsers, etc. Is it any surprise that people are deeply suspicious of any coincidences that arise from using a supposedly private channel.?

Given evidence at hand, it is hard to view Meta as anything but a bad actor.

Post reply on HN