4 ms·
With regards to your edit, yes, you are wrong. And I don't mean that in a harsh way, just answering your question. From WhatsApp themselves [0]: "WhatsApp end-
by doctorsher 8y ago
With regards to your edit, yes, you are wrong. And I don't mean that in a harsh way, just answering your question.
From WhatsApp themselves [0]: "WhatsApp end-to-end encryption ensures only you and the person you're communicating with can read what's sent, and nobody in between, not even WhatsApp. Your messages are secured with locks, and only the recipient and you have the special keys needed to unlock and read your messages."
[0] https://faq.whatsapp.com/en/general/28030015 https://faq.whatsapp.com/en/general/28030015
- lyzan 8y agoThat is end to end from your phone to their phone, and they are talking about 3rd parties outside the app. As your physically typing the the information into the chat message box, and before you send it, the app itself should have access to the plain text coming from the keyboard, which it then encrypts before it leaves your phone. Similarly it needs decrypted on the other side and displayed to the other user, at which time the app again has accesd to clear text versions. I don't believe there's any way to encrypt the message before the app sends the message / while it is displaying to the recipient
- doctorsher 8y agoOf course, there must be plaintext at some point... I don't understand this line of reasoning. WhatsApp tells their users and more importantly the US Gov they do not have any access to the message content itself. For this attack surface to be an issue, that would mean WhatsApp is telling a bold faced lie, secretly exfiltrating the plaintext to a 3rd party, and doing so without getting caught by any black-box auditing.