5 ms·
Message contents are end-to-end encrypted (but not all metadata is). And no, they are not sent through an unencrypted side channel to Meta. I've worked at Meta
by xerxesaa 4y ago
Message contents are end-to-end encrypted (but not all metadata is). And no, they are not sent through an unencrypted side channel to Meta. I've worked at Meta on a team that does end-to-end encryption. The company is also very clear about this publicly [1][2]
It's super frustrating that every single time WhatsApp is mentioned on Hacker News, someone boldly makes a claim that it's not encrypted based on hearsay or hunches.
1- https://faq.whatsapp.com/791574747982248/?locale=en_US https://faq.whatsapp.com/791574747982248/?locale=en_US
2 - https://www.whatsapp.com/privacy https://www.whatsapp.com/privacy
- est31 4y agoIt's fair to criticize the end to end encrypted claim though because for a long time, WhatsApp was storing unencrypted backups. Now that has been improved, but I doubt that most people opt into that. If 10% of users has turned off backups, and 5% has put a password on their backups, you have 85% of people being vulnerable. If some authority wants to know what has been discussed on WhatsApp, they won't ask Meta, they will ask Google or Apple. With the above (imaginary) numbers, if there is a group with 5 random Signal users and a group with 5 random WhatsApp users, the WhatsApp content is going to be available most likely to authorities that Google and Apple deliver content to, while the content of the Signal group is most likely not available. For iCloud, Apple claims end to end encryption but they keep a backup key around so it's mostly just marketing. There might be a small benefit from this through protection from employees side stepping company policies.
- xerxesaa 4y agoSure, that's a fair point. Backups were initially not encrypted, but as you mentioned, this option is now available. Without going into too much detail, I can tell you a huge challenge with encrypted backups is compliance - many people simply do not opt-in to using encrypted backups. It's a difficult line to walk because ultimately you don't want to pester users too much about using encrypted backups either. In case it's not clear, the reason it requires opt-in is because you (i.e., the user) control the encryption keys and therefore you must take some action to write down a key or passphrase. As you may imagine, the average messaging app user is not as tech savvy as the average Hacker News user and many simply don't want to go through this extra step. Even worse, if they opt-in to encrypted backups and lose their keys, they will end up blaming Meta for not giving them a way to restore their message history when their phone gets lost (it's not easy to explain that it's your responsibility as the user to keep your keys safely stored).
- est31 4y agoDefinitely, this is a hard tradeoff to make. Users very often care more about having access to their messages than them being not accessible to authorities/advertisers/etc, and they are very often not very savvy. As you say they also probably don't choose the most secure passwords. Signal on the other hand sides on the side of security so much that it makes the app purposefully less useable, e.g. with their pin feature. But it doesn't have this backup problem. It's not a situation that has an easy solution atm. But I think it's important to note that the belief of many users is wrong that end-to-end encryption implies that message content is unavailable to governments unless they get unlocked access to devices of communication partners.
- xerxesaa 4y agoAll fair points.
- mi_lk 4y agothe takeaway for me is that it tells you how bad the Meta's reputation has become. Quite obvious at this point but still
- xerxesaa 4y ago100% agree.
- ignoramous 4y ago> It's super frustrating that every single time WhatsApp is mentioned on Hacker News, someone boldly makes a claim that it's not encrypted based on hearsay or hunches. You only address OP's first "bold" claim. You've sidestepped the rest. I wonder why. > I've worked at Meta... Ah, I see. Super frustrating, indeed.
- xerxesaa 4y agoI worked in tech, not legal. I have no idea about what is or isn't shared with law enforcement or anyone else. That's why I didn't address that part. The frustrating part is people making claims about issues where they don't actually have datapoints to back it up. I try to avoid doing that.
- axlee 4y ago> The frustrating part is people making claims about issues where they don't actually have datapoints to back it up. I try to avoid doing that. When it comes to security, the default assumption is always to assume any system is not secure unless it can be proven that it is with a reasonable level of certainty. In the case of Whatsapp, that level of proof is not there. We have to assume it is insecure. If Whatsapp released their client's code, that problem would go away.
- xerxesaa 4y agoThat's fine, but it's one thing to say "I don't know, and therefore I assume it's insecure" vs saying "it's not end-to-end encrypted" I'm just humbly asking people to be clear about what they know vs what they assume.
- ylk 4y agoIt’d make for a really great story if someone were able to prove that WhatsApp isn’t e2ee and instead sends copies of all message contents to meta. You could just go ahead and decompile the app to do that, then write it up and get #1 on HN. If it was open source that still wouldn’t prove much, see e.g. https://mobile.twitter.com/taviso/status/1263957627077226498 https://mobile.twitter.com/taviso/status/1263957627077226498 for a discussion on reproducible builds. The recent OpenSSL vulnerabilities were in there for over a year before they were discovered. Theoretically Signal or an open source version of WhatsApp could have a bugdoor, which would not be found for as long or longer. Sure, it’s way nicer when stuff is open source, but I’m not sure it’d change much in this regard. (IMO there are many good reasons to dislike WhatsApp/meta. I just think your argument is flawed.)
- gdidhskwhei73 4y agowell, you are wrong. or out of date. read the terms of use for business accounts, which are everywhere now. it clearly says that metabook have access to any message exchanged with a business account on whatsbook. ...and I'm not sure about groups. there are data leaks for media in groups that were dismissed as features a while ago, not just metadata. well, i think they called media ids that identify content as metadata or something. not following whatsbook closely lately.
- xerxesaa 4y ago> well, you are wrong. For someone who is "not following whatsbook closely lately" that is again a bold claim to make. But anyway, business messages are also encrypted. Businesses are allowed to designate other accounts to receive messages, in which case those other accounts are sent copies of those messages using a different key. It's similar to sending messages to multiple devices. This is disclosed [1] and needed to support things like auto responders. Group chats are also encrypted using a shared sender key and this is described in the whitepaper starting page 10 [2] 1 - https://faq.whatsapp.com/567302067179554/?locale=en_US https://faq.whatsapp.com/567302067179554/?locale=en_US 2 - https://www.whatsapp.com/security/WhatsApp-Security-Whitepaper.pdf https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...
- manbash 4y agoSignal offers more to the table to prove it's secure and respects users privacy. Whatsapp/Meta claim so, but have no proof. As with your comment, without proof we can't be convinced.
- xerxesaa 4y agoThat's fair. Signal is open source and that certainly helps.
- annadane 4y agoThe thing is, I wouldn't want to use Whatsapp considering how Facebook got it: spy on people with Onavo and then basically pressure the original founders out of the company, and then do stuff like https://news.ycombinator.com/item?id=25662215 https://news.ycombinator.com/item?id=25662215... that doesn't sound like stewards I'd trust