A 10-month Commerce Department probe concluded Meta could view all WhatsApp messages in unencrypted form

you are viewing a single comment's thread
view the rest of the comments
[–] 33 points 5 months ago (12 children)

I never assumed that this presumed "end to end encryption" was secure in any way. The key exchange either runs over Meta servers, and they just log them, or the client software simply surrenders the key (maybe always, maybe on demand) together with the data stream that still runs over Meta servers.

  • source
  • hideshow 12 child comments
  • [–] 3 points 5 months ago

    I also never assumed it was fully secure either. Like sure it could be secure to hackers since they would still need the keys, but if anyone ever thought Meta was somehow not going to allow themselves access is just crazy and I am shocked anyone thought differently. On top of this they absolutely share all data with the government, im just not sure if it's by request or full access anytime.

    Sadly, everyone i know still uses it so im kind of forced to but at the same time the chats are all dumb anyway so whatever and enjoy reading them Meta employees.

  • source
  • parent
  • [–] -3 points 5 months ago (10 children)

    They can log anything they want and have nothing useful, if the encryption protocol is sound.
    Have a look at how TLS is designed, if you want to know more.

  • source
  • parent
  • hideshow 10 child comments
  • [–] 16 points 5 months ago (8 children)

    You can have the soundest encryption in the world but if they have access to the keys it doesn’t matter, they can see everything.

  • source
  • parent
  • hideshow 8 child comments
  • [–] 6 points 5 months ago (7 children)

    But the key exchange is not the issue then.
    Access to private keys is.
    If the host system, on which the key exchange runs, is compromised, you're toast.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 7 points 5 months ago (6 children)

    Where's the private key? I can get a new phone, log with WhatsApp and download all the historical messages without intruducing any additional password or key.

    I assume they have all the required data too.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 2 points 5 months ago

    @Railcar8095 @zergtoshi actually is not my exlerience with whatsapp, since I have the backups disable, everytime I change phones I lost all my conversations. But since whatsapp is closed source, the app can indeed use encryption to comunicate p2p, but I will allways assume that the key is logged by meta, "just in case"

  • source
  • parent
  • [–] 1 point 5 months ago (4 children)

    Sounds like a compromised phone in the sense that it doesn't protect (and instead transmit) the private key.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 5 points 5 months ago (3 children)

    That's not the phones fault, but how WhatsApp works

  • source
  • parent
  • hideshow 3 child comments
  • [–] -2 points 5 months ago (2 children)

    How is a phone not compromised if it hosts apps that play into the hands of evil actors?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 11 points 5 months ago

    I know my way around cryptography, therefor I am skeptical. If push comes to shove, they can simply command the Whatsapp App to silently surrender the keys. Nobody would know, it is a closed source app and protocol, and they can hide what they are doing inside the (probably) TLS encrypted stream.

  • source
  • parent