An international group of plaintiffs is suing Meta, alleging that WhatsApp’s end-to-end encryption isn’t actually private. Lawyers are asking the court to certify a class-action.

  • tyler ( tyler@programming.dev ) 
    link
    fedilink
    arrow-up
    35
    ·
    8 months ago

    Meta Is Being Sued Over Whether WhatsApp Really Encrypts Your Messages

    No, they’re being sued over whether Meta can read your messages, not whether e2e is implemented. I covered this in a different comment the other day, but these are not mutually exclusive, which is why Meta can be completely truthful about e2e encryption being on and yet the lawsuit can still be correct.

      • JackbyDev ( JackbyDev@programming.dev ) 
        link
        fedilink
        English
        arrow-up
        3
        ·
        8 months ago

        Imagine a scenario where your app checks for stuff, say links to a competitor’s website, prior to encrypting and sending the message. Then, if such information was found, it notifies someone. This would still be genuine end to end encryption while still snooping on messages.

      • tyler ( tyler@programming.dev ) 
        link
        fedilink
        arrow-up
        2
        ·
        8 months ago

        It is though. Think of it this way. You are a spy, you are communicating with someone over Signal. Signal is e2e. The person you are talking with doesn’t know you are a spy. They’ve verified that Signal is working and yet their secrets keep getting out. They go to law enforcement and say “they’re a spy” and you say “no I’m not, it’s e2e, nothing could have been getting out!”.

        If you can read the text on the screen, then it’s past the point of e2e. e2e is just about transmission. It has nothing to do with the endpoints.

        In this case Meta can utilize iOS App Groups which allows applications by the same company to access shared data. So imagine the easiest to understand scenario.

        You get a message on WhatsApp. Your Operating System takes a screenshot of the message, and sends it off to the FBI. Nothing has broken e2e here. Your OS can’t be trusted (in this example).

        Now let’s expand it:

        • You get a message on WhatsApp
        • WhatsApp takes a screenshot of the message and saves it to its storage. It does NOTHING ELSE WITH IT.
        • Facebook (which you also have installed) now accesses that shared data store, utilizing iOS App Groups, takes the screenshot, and sends it to Meta.

        Nothing has broken e2e here. The client can’t be trusted, so no matter what you do, e2e doesn’t have to be broken, since the company is untrustworthy. They can claim e2e, implement fully working auditable e2e, and still exfiltrate your data.

        Of course, WhatsApp probably isn’t taking screenshots. They can just save off the text after they decrypt it (even if they use the Signal protocol).

    • fonix232 ( fonix232@fedia.io ) 
      link
      fedilink
      arrow-up
      9
      ·
      8 months ago

      Yep. E2EE is only worth anything if you trust the client on both ends. Meta, being in control of the WhatsApp app (aka the client) thus can access the message contents even if there’s full E2EE, simply by scanning it after decryption.

    • Yeah, I deleted all my Meta accounts several months ago and have never felt better or looked back honestly. lol The most I miss is getting funny memes from my spouse on Instagram, but she can just show me in person and that’s real connection anyways.

  • berty ( berty@feddit.org ) 
    link
    fedilink
    arrow-up
    11
    ·
    8 months ago

    Reminder: whatsapp chat backups (to google account) are unecrypted by default unless you opt in for encryption and write down a very long rescue passphrase.

  • elgordino ( elgordino@fedia.io ) 
    link
    fedilink
    arrow-up
    6
    ·
    8 months ago

    One thing it sure as hell doesn’t encrypt is the links in your messages. They’re clearly sent to Meta to be ‘unfurled’. You can tell because sometimes a zoom like will unfurl to ‘too many requests try later’ so it’s obviously being done by some massive bot.

    • entwine ( entwine@programming.dev ) 
      link
      fedilink
      arrow-up
      3
      ·
      8 months ago

      By unfurl, are you referring to OGP metadata? That’s pretty common and used by a lot of non-Meta software. That’s probably loaded by your Whatsapp client directly.

      Btw, I’m not saying Meta doesn’t read your links. Anyone who thinks Whatsapp is actually private is an idiot.

      • elgordino ( elgordino@fedia.io ) 
        link
        fedilink
        arrow-up
        2
        ·
        8 months ago

        Yeah that’s it. If it ran locally it wouldn’t regularly show ‘rate limit exceeded’ messages. Its happening because it’s running server side in meta land.

  • atro_city ( atro_city@fedia.io ) 
    link
    fedilink
    arrow-up
    5
    ·
    8 months ago

    People don’t use WhatsApp because it’s encrypted. In fact, nobody I know uses it because of encryption. They don’t even know it’s encrypted nor what that means. Even if it were proven that WhatsApp didn’t encrypt a thing, or that Facebook reads everything you write, the majority would shrug and say “but everybody else uses it”. Most people just don’t give two shits about anything beyond themselves.