3 ms·
I worked in tech, not legal. I have no idea about what is or isn't shared with law enforcement or anyone else. That's why I didn't address that part. The frust
by xerxesaa 4y ago
I worked in tech, not legal. I have no idea about what is or isn't shared with law enforcement or anyone else. That's why I didn't address that part.
The frustrating part is people making claims about issues where they don't actually have datapoints to back it up. I try to avoid doing that.
- axlee 4y ago> The frustrating part is people making claims about issues where they don't actually have datapoints to back it up. I try to avoid doing that. When it comes to security, the default assumption is always to assume any system is not secure unless it can be proven that it is with a reasonable level of certainty. In the case of Whatsapp, that level of proof is not there. We have to assume it is insecure. If Whatsapp released their client's code, that problem would go away.
- xerxesaa 4y agoThat's fine, but it's one thing to say "I don't know, and therefore I assume it's insecure" vs saying "it's not end-to-end encrypted" I'm just humbly asking people to be clear about what they know vs what they assume.
- ylk 4y agoIt’d make for a really great story if someone were able to prove that WhatsApp isn’t e2ee and instead sends copies of all message contents to meta. You could just go ahead and decompile the app to do that, then write it up and get #1 on HN. If it was open source that still wouldn’t prove much, see e.g. https://mobile.twitter.com/taviso/status/1263957627077226498 https://mobile.twitter.com/taviso/status/1263957627077226498 for a discussion on reproducible builds. The recent OpenSSL vulnerabilities were in there for over a year before they were discovered. Theoretically Signal or an open source version of WhatsApp could have a bugdoor, which would not be found for as long or longer. Sure, it’s way nicer when stuff is open source, but I’m not sure it’d change much in this regard. (IMO there are many good reasons to dislike WhatsApp/meta. I just think your argument is flawed.)