Live data from Hacker News

Ex-WhatsApp cybersecurity head says Meta endangered billions of users

theguardian.com

91–100 of 192 posts

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#91
post #56

Earlier quoted context omitted.

It is huge in Latin America. USA is special because it is the (only?) country where iPhone has more users than Android.

It's crazy how an US company dominates the world's messaging market but not in the US

It's definitely not the world's messaging market. For instance in Japan and many places in SEA, Line is the standard messenger - one many people probably haven't even heard of. Though it does have a nice play on words - are you on Line?

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#92
post #32

Earlier quoted context omitted.

iMessage is end to end encrypted. Although Apple says it secure and the courts and FBI seem to not be able to get it in, it is still closed source.

I can't tell if I'm being paranoid or just realistic, when I suspect that FBI/Apple fights over decrypting/unlocking iPhones or iMessage are just part of Apple's security theater. If I were Evil-Tim-Cook, I'd have a deal with the FBI (and other agencies) where I'd hand over some user's data, in return for them keeping that secret and occasionally very publicly taking Apple to court demanding they expose a specific us…

It's possible for it to be a facade, but also real.

Apple is a part of PRISM so there's approximately a 100% chance that anything you send to Apple via message, cloud, or whatever else, gets sent onto the NSA and consequently any agency that wants it. But the entire mass data collection they are doing is probably unconstitutional and thus illegal. But anytime it gets challenged in courts it gets thrown out on a lack of standing - nobody can prove it was used against them, so they don't have the legal standing to sue.

And the reason this is, is because its usage is never acknowledged in court. Instead there is parallel construction. [1] For instance imagine the NSA finds out somebody is e.g. muling some drugs. They tip off the police and then the police find the car in question and create some reason to pull it over - perhaps it was 'driving recklessly.' They coincidentally find the cache of drugs after doing a search of the car because the driver was 'behaving erratically', and then this 'coincidence' is how the evidence is introduced into court.

----

So getting back to Apple they probably want to have their cake and eat it too. By giving the NSA et al all they want behind the scenes they maintain those positive relations (and compensatory $$$ from the government), but then by genuinely fighting its normalization (which would allow it to be directly introduced) in court, they implicitly lie to their users that they're keeping their data protected. So it's this sort of strange thing where it's a facade, but simultaneously also real.

[1] - https://en.wikipedia.org/wiki/Parallel_construction

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#94
post #53

"He also claimed the company failed to remedy the hacking and takeover of more than 100,000 accounts each day, ignoring his pleas and proposed fixes and choosing instead to prioritize user growth." There is no oversight of these monstrosities of any sort. I doubt anyone would have issues with the thesis that Meta would implement anything that might curb their user numbers unless it was mandated. Why would they? They…

Zuckerberg has a different class of shares

And not every CEO begins life in their company with "if you need any info just ask, they trust me, dumb fucks"

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#95
post #70

Earlier quoted context omitted.

how would you restore if you lost your device?

Backups with Advanced Data Protection also enroll: * Recovery Keys * Recovery Contact (someone who holds your recovery key in key escrow)

right, the ability to recover implies keys exist outside the device. even if they gossip keys to other devices you control, there are lots of people with only a single apple device.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#96
When it comes to e2e encryption it's important for the ends to be static (not web apps) and auditable (open source, reproducible builds) because the software running on the ends can trivially compromise anything going trough either of them. It can be as simple as a script being loaded from the server into a runtime such as Lua (closed source app). Or custom javascript delivered (web app).

When these conditions aren't met, any e2e encryption claim can be dismissed out of hand. This does not mean the service offers no value, it just means it cannot be trusted to keep anything confidential.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#97

That's rather surprising about the accessing user data bit. When I was at Meta, the quickest way to get fired as an engineer was to access user data/accounts without permission or business reason. Everything was logged/audited down to the database level. Can't imagine that changing and the rules are taught very early on in the onboarding/bootcamp process.

That part of the complaint is specifically about 1500 ”WhatsApp engineers”.

Different culture from the blue app, or whatever they call it?

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#98

Given how WhatsApp is the de-facto way to communicate outside of the West and China, these security/data-handling "weaknesses" are most likely a feature, not a bug. An absolute bonanza for the certain intelligence services. Remember, kids: End to end encryption is useless if the "ends" are fully controlled by an (untrustworthy) third party.

> outside of the West you probably mean outside of the USA, it's huge in Europe/UK (which doesn't contradict your main point)

I would have thought he meant "inside of the West". Outside of the West you have other channels.

Russia: Telegram

Taiwan: Line

Japan: Line

By contrast, WhatsApp is best known to me for being used in Europe, Australia, and India.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#99
post #88

That's rather surprising about the accessing user data bit. When I was at Meta, the quickest way to get fired as an engineer was to access user data/accounts without permission or business reason. Everything was logged/audited down to the database level. Can't imagine that changing and the rules are taught very early on in the onboarding/bootcamp process.

Do you have proof?

To the extent a random person's evidence on the Internet amounts to proof:

From people at Facebook circa 2018, I know that end user privacy was addressed at multiple checkpoints -- onboarding, the UI of all systems that could theoretically access PII, war stories about senior people being fired due to them marginally misunderstanding the policy, etc.

Note that these friends did not belong to WhatsApp, which was at that time a rather separate suborg.

Re: Ex-WhatsApp cybersecurity head says Meta endangered billions of users

#100

Earlier quoted context omitted.

Companies are not relationships where once they're your ex they are never worth interacting with ever again. If you are doing good work and then HR pushes you out, then it is reasonable to sue the company to get them to pay you damages and then go back to doing what you were before with the protection that they won't do it again.

The point I tried to make was not that he should be resentful about being kicked out, but that he doesn't really care that Meta is unethical and endangers billions. Even if nothing changes (the regulatory action is optional), he's happy to contribute (he insists, in fact). Even among people who don't want him there.

The points you’re making are personal attacks about the whistleblower. They don’t focus on the substance of the accusations (insecurity). Instead, they focus on your idea of their career motivations and their personality.
Post reply on HN