5 ms·
And I think you can do more about E2E encrypting it. Or at least trying to. At some point, people don't want plaintext journals floating around stored permanent
by loremm 2y ago
And I think you can do more about E2E encrypting it. Or at least trying to. At some point, people don't want plaintext journals floating around stored permanently. Although I know it starts as cleartext on whatsapp's servers
- sangnoir 2y ago> Although I know it starts as cleartext on whatsapp's servers WhatsApp uses the Signal protocol[1], so the text is never plaintext on the wire (or servers). 1. https://signal.org/blog/whatsapp-complete/ https://signal.org/blog/whatsapp-complete/
- meiraleal 2y agoEasy to say, very difficult to implement it right (and implementing it not right is diffcult AND useless). Also, let's be clear here, whatsapp E2EE is a joke.
- ylk 2y ago> whatsapp E2EE is a joke Could you please elaborate why (in detail)?
- deleted 2y ago[deleted]
- grvdrm 2y agoYes - I would love that too. Please back that up?
- jusepal 2y agoMy guess is since its closed source, no one beside them can verify that the supposedly e2e is even true, or exist in current latest binary. Sort of telling everyone that I've got a mountain of gold inside my house but the door is locked, no one beside me could verify my claim. Security and/or privacy via obscurity is moot.
- meiraleal 2y agoThey also handle and store users backup unencrypted by default so they have access to all messages in plaintext in multiple opportunities.
- ylk 2y agoMeta has access to the backups that are stored on each individual’s Google Drive/iCloud? How does that work exactly? Please elaborate.
- meiraleal 2y ago> Meta has access to the backups that are stored on each individual’s Google Drive/iCloud? Why the surprise? Meta has access to the folder it manages in the user's Google Drive. That's obvious, otherwise they wouldn't be able to write to it.
- ylk 2y agoThe app uses the (i)phone OS’s cloud storage APIs to write to the backup folder, meta’s servers don’t have access to any credentials. For Android I currently can’t check, but it’s obvious from their FAQs that they have the app upload to Google‘s servers even if they don’t use the OS APIs there: https://faq.whatsapp.com/481135090640375/?cms_platform=android&helpref=platform_switcher https://faq.whatsapp.com/481135090640375/?cms_platform=andro... They have indirect control over the user’s backup folder via the app, but meta would need to distribute a malicious update to everyone that causes the user’s apps to download the backup and send it to meta, at which point they could just skip trying to access the backup and directly upload the chats from the app. It’s impressive how much misinfo you’re spreading. Edit: Meta’s actions over the years clearly show that they don’t want to know the contents of your messages. Not knowing their contents means, for example, that they don’t have to run scanners to detect illegal content (but users can report messages). They benefit from making WhatsApp a secure platform, as it allows them to collect everyone’s metadata, which apparently has lots of value to them.
- compootr 2y ago> people don't want plaintext journals floating around stored permanently this is facebook. they're data-mining pictures of your dog for money. I don't think privacy/safety is expectable with meta