33 ms·
"This means the privacy of your end-to-end encrypted group chat is only guaranteed if you actually trust the WhatsApp server." "This undermines the entire purp
by aplorbust 9y ago
"This means the privacy of your end-to-end encrypted group chat is only guaranteed if you actually trust the WhatsApp server."
"This undermines the entire purpose of end-to-end encryption."
"And yet, the entire point of end-to-end encryption is to remove the server from the trusted computing base."
"The challenge here is that since WhatsApp itself determines who the administrators are, this isn't quite so simple."
Not only does this system require trusting a third party, that party is none other than Facebook. Its business is built on learning about the lives of users and selling ads, not serving as a naive broker of "secure messages".
- yuliyp 9y agoHyperbolic much? This is a weakness that not only requires WhatsApp to be malicious but to not care about the trivial visibility of an exploit (the client would still display the extra person being added to the group chat).
- rickycook 9y agonot malicious per se, just with non obvious ulterior motives
- whyever 9y agoThey have a feature where you can invite people to the group with a link that requires the server being able to add people. Isn't that a fairly obvious motive?
- fulafel 9y agoMalicious can happen through server compromise, too.