this post was submitted on 09 Oct 2023
0 points (NaN% liked)

Privacy

31803 readers
351 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

For open source messengers, you can check whether they actually encrypt your messages and whether the server has access to your encryption keys but what about WhatsApp? Since it's not open source, you can't be sure that the encryption keys aren't sent to the server, right? Has there been a case where a government was able to access WhatsApp chats without reading them from the phone itself?

all 9 comments
sorted by: hot top controversial new old
[–] crispy_kilt@feddit.de 0 points 1 year ago (1 children)

They don't have to attack the encryption, there are far easier ways. Compromising your phone then reading the notification contents for example. If a smallish company can do this (pegasus) imagine what the resources of the US intelligence complex can do.

[–] Fisch@lemmy.ml 0 points 1 year ago (1 children)

Shouldn't the phone disk be encrypted too?

[–] crispy_kilt@feddit.de 0 points 1 year ago

Doesn't matter if the phone is compromised while turned on.

[–] Pantherina@feddit.de 0 points 1 year ago

Ask Meta. Its not Open source, its all "trust me bro its encrypted with some encryption"

[–] megopie@lemmy.blahaj.zone 0 points 1 year ago (1 children)

Facebook owns what’s app and they can read any message on the service, they’ve also been known to give logs and messages to law enforcement agencies at request without warrants.

[–] Frogodendron@beehaw.org 0 points 1 year ago (1 children)

Why is it legal for them to advertise it as end-to-end encrypted then? I thought the main danger lies in WhatsApp insistence on backing up non-encrypted history to Google Drive/iCloud.

Of course, the existence of backdoors is usually not disclosed (duh), but can they actually read any message?

[–] cjf@feddit.uk 0 points 1 year ago (1 children)

I believe this is down to what they define as being end to end encrypted.

It’s no secret that WhatsApp adopted Signal’s encryption protocol just before Meta acquired them, but since it’s all closed source we don’t know if they’ve changed anything since the announcement in 2016 that all forms of communications on WhatsApp are now encrypted and rolled out.

Within WhatsApp’s privacy policy, it’s important to note that they only mention end to end encryption when it comes to your messages. Everything else is apparently “fair game” for collection. Of note, the Usage and Log information point details all the metadata they collect on you automatically, including how you use the service; how long you use the service; your profile info; the groups you’re in; whether you’re online; and the last time you were online, to name a few things.

I guess what I’m trying to say is that technically they are end to end encrypted by definition, and whilst they’ve gone ahead and implemented things such as encrypted backups (that you must enable) to make it harder for them to read your message contents, they can still collect a lot of metadata on every user.

[–] cmeerw@programming.dev 0 points 1 year ago

It’s no secret that WhatsApp adopted Signal’s encryption protocol just before Meta acquired them, but since it’s all closed source we don’t know if they’ve changed anything since the announcement in 2016 that all forms of communications on WhatsApp are now encrypted and rolled out.

There is an Open Source implementation of the WhatsApp protocol: yowsup