75
Is WhatsApp bad for privacy?
(lemm.ee)
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
This is true, but something that should be noted is that, to my knowledge, no law enforcement agency has ever received the supposedly encrypted content of WhatsApp messages. Facebook Messenger messages are not E2E encrypted by default, and there have been several stories about Facebook being served a warrant for message content and providing it. This has, as I understand, not occurred for WhatsApp messages. It is possible, of course, that they do have some kind of access and only provide it to very high-level intelligence agencies, but there's no direct evidence of that.
I would personally say that it's more likely than not that WhatsApp message content is legitimately private, but I'd also agree that you should use something like Signal if you're genuinely concerned about this.
They would better hide those evidences as best as they can, or they would lose a useful source of informations.
That's the whole game of intelligence: to be a step ahead of the opponent, it must believe its safe so you can steal useful informations. As soon as the breach is discovered, it ceases to be useful.
Sure. My point is that, as far as I believe anyone is currently aware, there is no evidence that any law enforcement agency has ever accessed the content of encrypted WhatsApp messages. That does not mean that it has never happened either, but anyone positively claiming so is doing it without actual evidence, which is something we should probably avoid doing.
We can assess the security of the app though. And we should. And we should also bring awareness to the problems of closed sources.
If you log into WhatsApp on another device, does your history show up?
If it does, that means they hold your encryption keys on their server. It's the only way this could work.
It's why with Signal you need to maintain your keys and keep backups. No one else has your keys, so logging in to other devices won't get history without that backup and the keys.
Works this way with encrypted XMPP too, of course.
You have to scan a QR code from the website with your phone, which I'm assuming then facilitates a transfer of the keys.
That's essentially what's been posited by this rando on StackExchange.
https://security.stackexchange.com/questions/119552/how-does-end-to-end-encryption-work-with-whatsapp-web
Does it work if your other devices are offline? That would be telling.