75
submitted 1 year ago by Azzu@lemm.ee to c/privacy@lemmy.ml

And if so, why exactly? It says it's end-to-end encrypted. The metadata isn't. But what is metadata and is it bad that it's not? Are there any other problematic things?

I think I have a few answers for these questions, but I was wondering if anyone else has good answers/explanations/links to share where I can inform myself more.

you are viewing a single comment's thread
view the rest of the comments
[-] BearOfaTime@lemm.ee 1 points 1 year ago

If you log into WhatsApp on another device, does your history show up?

If it does, that means they hold your encryption keys on their server. It's the only way this could work.

It's why with Signal you need to maintain your keys and keep backups. No one else has your keys, so logging in to other devices won't get history without that backup and the keys.

Works this way with encrypted XMPP too, of course.

[-] BraveSirZaphod@kbin.social 2 points 1 year ago

You have to scan a QR code from the website with your phone, which I'm assuming then facilitates a transfer of the keys.

That's essentially what's been posited by this rando on StackExchange.

https://security.stackexchange.com/questions/119552/how-does-end-to-end-encryption-work-with-whatsapp-web

[-] BearOfaTime@lemm.ee 1 points 1 year ago

Does it work if your other devices are offline? That would be telling.

this post was submitted on 23 Oct 2023
75 points (89.5% liked)

Privacy

31609 readers
281 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS