Live data from Hacker News

US has investigated claims WhatsApp chats aren't private

bloomberg.com

371–380 of 387 posts

Re: US has investigated claims WhatsApp chats aren't private

#371
post #347
post #308

Earlier quoted context omitted.

Currently, the Russian government is trying to squeeze people out of Telegram and move them over to MAX: https://caspianpost.com/regions/russia-tightens-telegram-res... WhatsApp also operates in Russia, despite Instagram and Facebook being banned. So I wouldn't count on its E2EE either. Signal still requires a phone number and proprietary Google blobs on mobile. Many third-party Telegram clients exist - Signal allows…

The real story is, MAX is there to scare people into Telegram. Durov isn't your friend, neither is Putin who doesn't bother blocking connections to the server. >So I wouldn't count on its E2EE either. This is the worst way to assses E2EE deployment. 5D-chess. >Signal still requires a phone number and proprietary Google blobs on mobile. Telegram also requires a phone number. If you didn't have double standards, I bet…

>This is the worst way to assses E2EE deployment. 5D-chess.

How would you explain the fact that WhatsApp remains unblocked in Russia, when all other major messengers except Telegram and Meta's own products all got banned there?

>Telegram also requires a phone number. If you didn't have double standards, I bet you'd have no standards.

Not my point. I'm pointing out a flaw that both messengers share.

>TG has no idea how to make seamless E2EE like Signal.

Because it's never seamless. Loading your messages on Signal can take quite a while. Also if you receive a message over 2 weeks ago without checking your phone in the meantime, you may as well have never received it.

>You ignoring that Signal is both open source and always E2EE and complaining about it's "proprieatry blobs" yet looking past TG's atrocious E2EE speaks volumes.

Why are you ignoring the fact Signal actively prohibits third-party clients? Why the air quotes on proprieatry blobs? Yes, Telegram is far from perfect, and inferior to Signal when it comes to E2EE. But what makes you reject the proprieatry blob claim when it's true? Because your favorite messenger is being attacked?

Re: US has investigated claims WhatsApp chats aren't private

#372

WhatsApp's end-to-end encryption has been independently investigated: https://kclpure.kcl.ac.uk/ws/files/324396471/whatsapp.pdf Full version here: https://eprint.iacr.org/2025/794.pdf We didn't review the entire source code, only the cryptographic core. That said, the main issue we found was that the WhatsApp servers ultimately decide who is and isn't in a particular chat. Dan Goodin wrote about it here: https://arst…

"We didn't review the entire source code, ..."

Why not

"Our work is based primarily on the WhatsApp web client, archived on 3rd May 2023, and version 6 of the WhatsApp security whitepaper [46]."

Did not even look at the continously changing mobile app, only looked at part of the minified Javascript in the web client

Not sure what this accomplishes. Are the encryption protocols used sound, is the implementation correct. Maybe, but the app is closed source and constantly changing

But users who care want to know about what connections the software makes, what is sent over those connections, to whom it is sent and why. There is no implicit trust as to Meta, only questions. The source code is hidden from public scrutiny

For example, the app tries to connect to {c,e8,e10,g}.whatsapp.net over TCP on port 80

The app has also tried to connect over UDP using port 3478/STUN

These connections can be blocked and the user will still be able to send and receive texts and make and receive calls

Meta forces users to install new mobile app, i.e., untrusted, unaudited code, multiple times per year. This install grows in size by over 100%

For example, there were at least four different apps (subsequent versions) forced on users in 2023, five in 2024 and four in 2025

In 2023 the first was 54.06MB. In 2026, it is now 126MB

Re: US has investigated claims WhatsApp chats aren't private

#373

Earlier quoted context omitted.

https://www.gnu.org/philosophy/free-sw.html Whether the original comment knows it or not, Stallman greatly influenced the very definition of Source Code, and the claim being made here is very close to Stallman's freedom to study. >"You don't actually need code to evaluate security, you can analyze a binary" Correct >"just as well" No, of course analyzing source code is easier and analyzing binaries is harder. But it'…

Binaries absolutely don't map one-to-one with source code. Compilers optimize out dead code, elide entire subroutines to single instructions, perform loop unrolling and auto-vectorization, and many many more optimizations and transformations that break exact mapping.

That is true, but I don't think I ever said that binaries map one-to-one with source code.

I was referring to source code to binary maps, these are files that map binary locations to source code locations. In C (gcc/gdb) these are debug objects, they are also used in gdb style debuggers like Python's pdb, Java's jdb. They also exist in js/ts when using minifiers or react, so that you are able to debug in production.

Re: US has investigated claims WhatsApp chats aren't private

#374

Ex-WhatsApp engineer here. WhatsApp team makes so much effort to make this end to end encrypted messages possible. From the time I worked I know for sure it is not possible to read the encrypted messages. From business standpoint they don’t have to read these messages, since WhatsApp business API provide the necessary funding for the org as a whole.

> Ex-WhatsApp engineer here. WhatsApp team makes so much effort to make this end to end encrypted messages possible. From the time I worked I know for sure it is not possible to read the encrypted messages. None of this makes the point you want to make. Being a former engineer. The team making "so much effort". You "knowing for sure". Like many in security, a single hole is all it takes for your privacy to pour out o…

[dead]

Re: US has investigated claims WhatsApp chats aren't private

#375
post #345
post #315

Earlier quoted context omitted.

Telegram has private chats. I don't pay attention to his words, indeed. Way before the Ukrainian war, Russia had a massive campaign trying to block Telegram and they failed on a technical level. This has never happened with WhatsApp.

Yeah it's really hard to block tally count of five IPs. https://telegramplayground.github.io/pyrogram/faq/what-are-t... No wonder the great Russian firewall is struggling to keep TG at bay. Wake up.

>Yeah it's really hard to block tally count of five IPs.

They blocked 16m IPs, to the extent that it started affecting the entire Russian's internet stability, and Telegram was still available there: https://www.theguardian.com/world/2018/apr/17/russia-blocks-...

>Wake up

Is that a demand? A slogan? I wonder how much your own wokeness affects your ability to absorb facts.

Re: US has investigated claims WhatsApp chats aren't private

#376
post #364

WhatsApp's end-to-end encryption has been independently investigated: https://kclpure.kcl.ac.uk/ws/files/324396471/whatsapp.pdf Full version here: https://eprint.iacr.org/2025/794.pdf We didn't review the entire source code, only the cryptographic core. That said, the main issue we found was that the WhatsApp servers ultimately decide who is and isn't in a particular chat. Dan Goodin wrote about it here: https://arst…

Of particular note here is that while compromised WhatsApp servers could add arbitrary members to a group, each member's client would show the new member's presence and would not share prior messages, only future messages. Now, of course, this assumes the client hasn't been simultaneously compromised to hide that. But it's defense in depth at the very least. It is worth noting that this may be eroding as we speak: ht…

"People you send messages to have access to those messages. (And could therefore potentially share them with others.)" doesn't seem like a particularly scary security threat to me.

Re: US has investigated claims WhatsApp chats aren't private

#377

No closed-source E2EE client can be truly secure because the ends of e2e are opaque. Detecting backdoors is only truly feasible with open source software and even then it can difficult. A backdoor can be a subtle remote code execution "vulnerability" that can only be exploited by the server. If used carefully and it exfiltrates data in expected client-server communications it can be all but impossible to detect. This…

With all due respect to Stallman, you can actually study binaries. The claim Stallman would make (after punishing you for using Open Source instead of Free Software for an hour) is that Closed Software (Proprietary Software) is unjust. but in the context of security, the claim would be limited to Free Software being capable of being secure too. You may be able to argue that Open Source reduces risk in threat models w…

I think "manufacturer is the attacker" is precisely the threat people are most worried about.

And yes you can analyze binary blobs for backdoors and other security vulnerabilities, but it's a lot easier with the source code.

Re: US has investigated claims WhatsApp chats aren't private

#378
post #364

Earlier quoted context omitted.

Of particular note here is that while compromised WhatsApp servers could add arbitrary members to a group, each member's client would show the new member's presence and would not share prior messages, only future messages. Now, of course, this assumes the client hasn't been simultaneously compromised to hide that. But it's defense in depth at the very least. It is worth noting that this may be eroding as we speak: ht…

"People you send messages to have access to those messages. (And could therefore potentially share them with others.)" doesn't seem like a particularly scary security threat to me.

The threat here is that the ability of an attacker to add themselves to a thread, stacked with a new ability to either socially-engineer or otherwise attack an existing member to click a single share-history button, could result in disclosure of history without explicit intent to share.

Re: US has investigated claims WhatsApp chats aren't private

#379

Earlier quoted context omitted.

They can also tell your client it has the correct key. Yours and the other clients are all talking to their mitm in this scenario. There's fundamentally no way to solve this without users verifying keys out-of-band.

> They can also tell your client it has the correct key. No they can't. Key transparency cryptographically makes sure everyone gets the same result.

Key transparency is a public list of keys, like what CAs do. That still trusts an authority. Of course a third party could archive/republish the key list and you could trust them instead of Whatsapp, but that's what I call an out of band key verification.

These are all good measures though. It's much harder for Whatsapp to mass attack users this way.

Re: US has investigated claims WhatsApp chats aren't private

#380
post #195

Earlier quoted context omitted.

> We didn't review the entire source code And, you don't see the issue with that? Facebook was bypassing security measures for mobile by sending data to itself on localhost using websockets and webrtc. https://cybersecuritynews.com/track-android-users-covertly/ An audit of 'they can't read it cryptographically' but the app can read it, and the app sends data in all directions. Push notifications can be used to read m…

> Push notifications can be used to read messages. Are you trying to imply that WhatsApp is bypassing e2e messaging through Push notifications? Unless something has changed, this table highlights that both Signal and WhatsApp are using a "Push-to-Sync" technique to notify about new messages. https://crysp.petsymposium.org/popets/2024/popets-2024-0151....

No, I'm saying Meta can't be trusted.
Post reply on HN