4 ms·
I personally don't use whatsapp because I like it, but because all my contacts in my country are over there. It is officially more used than SMS here. It is not
by jeanlucas 6mo ago
I personally don't use whatsapp because I like it, but because all my contacts in my country are over there. It is officially more used than SMS here. It is not optional in my case :/
- gsich 6mo agoSMS is unsafe anyway.
- baq 6mo agozuck can read your whatsapp messages, at this point I think I'd rather criminals and the government read them instead
- hikarudo 6mo agoWhatsApp is end-to-end encrypted. No one at Meta can read your messages.
- cute_boi 6mo agoHow are we sure that it is really end-to-end encrypted?
- lossyalgo 6mo agoMoxie Marlinspike (founder of Signal) [0]implemented the same E2EE algorithm as Signal (Signal Protocol) into WhatsApp, but that was 10 years ago, so who knows if things have changed since then. [0] https://en.wikipedia.org/wiki/Moxie_Marlinspike https://en.wikipedia.org/wiki/Moxie_Marlinspike
- dTal 6mo agoPractically speaking, it isn't secure; no closed app can be. It receives regular compulsory updates (old versions refuse to work) and there's nothing at all stopping Zuck from sneaking in backdoors targeted at you personally.
- righthand 6mo agoIf I can log into whatsapp on a new device and old messages aren’t encrypted then they have a copy of your key and it is not true e2e encryption.
- Mordisquitos 6mo agoTry logging in on a new device and putting your main device into aeroplane mode as soon as the login succeeds. Loading of old messages on the new device will stop.
- lukebennett 6mo agoYou can't unless you've chosen to back up your WhatsApp messages to iCloud/Google in which case it's Apple/Google responsible for preserving the messages and subject to their encryption standards, nothing to do with Meta.
- 1vuio0pswjnm7 6mo agoSaw this exact claim on a billboard not too long ago It's a strangely worded statement. What about data collection, metadata, other third parties Maybe it's related to the fact that plaintiffs lawyers are now trying to verify what's going on inside Meta with WhatsApp through litigation discovery: https://ia801607.us.archive.org/10/items/gov.uscourts.cand.463150/gov.uscourts.cand.463150.1.0.pdf https://ia801607.us.archive.org/10/items/gov.uscourts.cand.4... Meta's motion to dismiss seemed a little weak. Time will tell https://ia801607.us.archive.org/10/items/gov.uscourts.cand.463150/gov.uscourts.cand.463150.29.0.pdf https://ia801607.us.archive.org/10/items/gov.uscourts.cand.4... Hearing will likely be sometime this summer
- commandersaki 6mo agoWhat about data collection, metadata, other third parties How does any of that result in Meta reading your messages?
- pwillia7 6mo agoyeah who wants marginally regulated oligarchs -- Give me fully unregulated criminals!
- mett36 6mo ago+1
- gsich 6mo agoMaybe, as I don't know if I got a special version that exfiltrates data to somewhere else. But this does not improve SMS security in any way. Another software also potentially being bad has no influence here.
- TeMPOraL 6mo agoNobody gives a damn. What matters is that it works even on a potato. SMS security only became a problem due to 2FA, which is just one of many use cases, and the failure isn't even technical here but organizational. I agree it should've prompted more pressure to secure the system against SIM-swapping; alas this is too close to the Real World, so the tech industry instead responded with alternative that side-steps the problem by offering zero customer support. No humans to talk to = no humans to social engineer = secure. So much win. (I'd also say the 2FA proliferation is itself a problem, but that's an unpopular opinion and for a separate discussion.)
- lxgr 6mo ago> Nobody gives a damn. What matters is that it works even on a potato. It doesn't work on my computer, nor does it work on my phone when I'm traveling (different SIM), so I give a damn. WhatsApp, iMessage, Signal etc. do both. I really wish there was an open, federated standard (and no, RCS is neither), but until then, I'll use what actually works for me. SMS just sucks, and I hate that it's become so ubiquitous an authentication method when it's not even secure.
- bluebarbet 6mo agoYou can rent a virtual mobile number in your home country and consult SMSs on the web or even redirect them to email. I have done this for years, using Twilio for 2€ a month. Can't say the UX is great but it certainly fixes the whole problem. I've never understood why so many people still chain their identities to physical SIM or even eSIMs. It's so fragile.
- lxgr 6mo agoYeah, that's a good workaround. Google Voice can work too. Unfortunately, more and more services are declining to send to VoIP numbers because of seCurItY, so it's a game of cat and mouse. Fortunately SMS is so expensive in parts of Europe and it's not allowable anymore to use SMS by itself for online payment authentication, and both issues combined have slowly been pushing companies to explore alternatives. There unfortunately seems to be no such pressure in the US. Passkeys could solve the issue, but probably increase support request volumes enough for most companies to not bother unless forced.