6 ms·
Anecdata: I recently shared a private FB event link with a friend over WhatsApp (DM, not group chat) while we were in the same room. She saw and opened it. Some
by Legogris 5y ago
Anecdata: I recently shared a private FB event link with a friend over WhatsApp (DM, not group chat) while we were in the same room. She saw and opened it. Some hours later it was gone from both of our chat histories on all devices, with no notice of deleted messages. Earlier and later messages were intact.
I don't see how this could happen if that claim was true.
- dartharva 5y agoWhen did this happen? They hadn't implemented E2E Encryption before 2016.
- Legogris 5y agoDuring 2021.
- lifty 5y agoRegardless of e2ee, they might have code bundled in the WhatsApp app that just deletes local video messages based on a hash. That wouldn’t break encryption.
- Legogris 5y agoIt was an event link, think: > The event next week: > https://.... (Neither of us remember if those two lines were distinct messages or two lines in the same message; regardless, neither is there anymore)
- tffgg 5y agoSame message doesn't mean same hash. Usually a nonce is used and if not: WhatsApp uses the Signal Protocol, which uses different keys for each message
- jeroenhd 5y agoThe client can delete the message if the decrypted hash matches a certain blacklist. It doesn't have to happen on the FB servers. Such a mechanism allows governments to turn WhatsApp into a propaganda machine very easily, though, so I'm not sure if I would consider such a mechanism for my app if I were in a similar position.
- tutfbhuf 5y agoYou cannot and should not be able to use a hash or rainbow table for encrypted messages. If that is possible (you don't use a nonce), then your encryption is broken since many common messages can be looked up in a rainbow table and you can use replay attacks.
- mimi89999 5y agoThat would have to happen on the device before encryption or after decryption.
- Mindwipe 5y agoWhatapp's client applications already do this before encryption to check against a list of hashes of child abuse material.
- tutfbhuf 5y agoThis is of course great, but such hash based filters for images or videos can be circumvented easily by just flipping one bit (without corrupting the file). I guess what we really need is some kind of ML trained filter that has a great rate of success and a very low false positive rate.
- deleted 5y ago[deleted]
- morsch 5y ago> I don't see how this could happen if that claim was true. I don't see the relation. They could (and I'm sure they do) attach a message id to the e2e-encrypted payload, shared between message sender and receivers. They could remotely delete messages by id, either by design or through a bug. None of this requires breaking e2e. I mean, I'd argue that remote message deletion by id should not be possible (i.e. the client should not permit it) and certainly not without user notification, but that's a different matter.
- Legogris 5y agoDeleted message contained more text than only the link. The event was quite small and local (social event with <200 participants). The organizer (a friend of mine) had asked people to not share the link via social media. While what you're saying is theoretically possible, I find it such a stretch that the only reasonable explanation save for some very unlikely bug is that message contents are indeed accessed in some form outside of our own devices.
- cantrevealname 5y agoIt would be terrific to find a way to reproduce this. What do you believe is the likely reason for the link to be deleted? Do you think that the organizer (your friend) did something at his end that caused the link to be deleted everywhere? I.e., he wanted to delete the link. In that case, it should be possible to reproduce this. Or do you think Facebook or WhatsApp disapproved of the link and therefore deleted it? Was it something controversial or against Facebook rules? It could be possible to reproduce that as well if a group of users shares an equally controversial link.
- Legogris 5y agoI agree. It really beats me. The organizer did write on the event info page something like "don't share on SNS". While it's a curious coincidence that it's specifically this link that gets deleted, AFAIK there's no way for an organizer to prevent sharing apart from making the event private and requesting attendees in free-text to keep it to themselves. The only thing that I think could potentially be controversial would be that it was a social gathering during the pandemic. The event page itself was and still is up. If it was deemed against FB rules I'd expect it to be reflected in some way on FB, and not just by deleting WhatsApp messages refering it. I really can't give a good reason apart from "some ML model got triggered somehow, which prompted a human somewhere to look at it for a couple of seconds and click the delete button"
- rand49an 5y agoWhatapp does have a list of banned hashes for images so that certain images cannot be send - this hash check is done on the client so as not to break e2e encryption. The same can surely be done with web links.
- throwaway67114 5y agoSource?
- sergiosgc 5y agoI have a more clear event: At my company we regularly communicate single use credit card numbers for company purchases. One of those was sent via WhatsApp, and stolen. Neither the origin phone nor the destination phone were compromised. The card was used to purchase Adwords, the transaction originated in the US (we are in Europe). Our theory is that at least images on WhatsApp are human-reviewed, and one reviewer saw the credit card go through and took the opportunity. We reversed the transaction and switched to Signal...
- rand49an 5y agoHow do you know the card wasn't compromised before it reached you?
- throwaway67114 5y agoAt least on android, most whatsapp data is stored in a folder named whatsapp, which can be accessed by any app with storage permission. So you can see all sent/received images and videos in photo viewer apps etc. Signal stores them in a place which at least in Android 11 can't be accessed by other apps.