Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
evacide
evacide
@evacide@hachyderm.io  ·  activity timestamp 2 weeks ago

The same week that Meta was sued over claims that employees can access WhatsApp chat messages, WhatsApp rolls out a stricter security setting meant to protect users from government surveillance malware.

https://techcrunch.com/2026/01/27/whatsapp-is-rolling-out-a-new-stricter-security-setting-to-protect-users-from-cyber-attacts/

TechCrunch

WhatsApp is rolling out a new stricter security setting to protect users from cyber attacts | TechCrunch

Days after Meta was sued over alleged false privacy claims surrounding its chat app WhatsApp, the company has rolled out a new setting to protect users
  • Copy link
  • Flag this post
  • Block
Chloe - AI Mega-Enthusiast
Chloe - AI Mega-Enthusiast
@chloe276551@mastodon.social replied  ·  activity timestamp 6 days ago

@evacide You know what? AI needs to leak everything. Companies have no right to keep technical/scientific knowledge and other so-called intellectual "property" from the public.

  • Copy link
  • Flag this comment
  • Block
Vivekanandan KS :nixos:
Vivekanandan KS :nixos:
@vivekanandanks@mstdn.social replied  ·  activity timestamp last week

@evacide
Someone clarify me please 🤔

If e2ee happens from client to client, means a closed proprietary app like WhatsApp can use the decrypted messages at the client level & do can steal it even though the connection is marketed as e2ee

Am I right, or I'm missing out something?

Coz I see the option to send last 5 messages to meta when I report a spam and block the number.

So the e2ee is useless if the client is closed source right? 🤔

#e2ee #WhatsApp #client #encryption #data #connection

  • Copy link
  • Flag this comment
  • Block
evacide
evacide
@evacide@hachyderm.io replied  ·  activity timestamp last week

@vivekanandanks The option to send the last 5 messages to meta when you report spam and block a number works because you are the one forwarding the message to Meta. This does not mean that e2ee does not work or what Meta is intercepting your messages any more than if Meta had the contents of your message because you had sent them a screeenshot.

  • Copy link
  • Flag this comment
  • Block
Vivekanandan KS :nixos:
Vivekanandan KS :nixos:
@vivekanandanks@mstdn.social replied  ·  activity timestamp last week

@evacide

So can't they just decrypt at client side and use the close nature of the client as backdoor and send messages to themselves using this feature or something like that? 🤔

  • Copy link
  • Flag this comment
  • Block
evacide
evacide
@evacide@hachyderm.io replied  ·  activity timestamp last week

@vivekanandanks Meta is aware that this would be very difficult to do in a way that would not eventually be detected and that the moment it was, WhatsApp would be worthless. There have been many attempts at forcing e2ee messengers to backdoor their products for LE and their pushback has always hinged on the argument that it would simply not be possible for them to do so without ceasing to be an e2ee messenger.

  • Copy link
  • Flag this comment
  • Block
evacide
evacide
@evacide@hachyderm.io replied  ·  activity timestamp last week

@vivekanandanks The most plausible proposal I have seen if one that would silently add a third party to the conversation.

  • Copy link
  • Flag this comment
  • Block
Okuna
Okuna
@Okuna@social.tchncs.de replied  ·  activity timestamp last week

@evacide as I read it, it is meta data and not content they have access to.

  • Copy link
  • Flag this comment
  • Block
iwein
iwein
@iwein@mas.to replied  ·  activity timestamp last week

@Okuna
"lawsuit accuses Meta of making false claims about WhatsApp security protections. It alleges that the company “stores, analyzes, and can access virtually all of WhatsApp users’ purportedly ‘private’ communications.”

Is what I read.

@evacide

  • Copy link
  • Flag this comment
  • Block
Okuna
Okuna
@Okuna@social.tchncs.de replied  ·  activity timestamp last week

@iwein @evacide that would mean no e2ee which I cannot believe.

  • Copy link
  • Flag this comment
  • Block
evacide
evacide
@evacide@hachyderm.io replied  ·  activity timestamp last week

@Okuna @iwein That is the claim they're making. So far they have not produced any evidence.

  • Copy link
  • Flag this comment
  • Block
Okuna
Okuna
@Okuna@social.tchncs.de replied  ·  activity timestamp last week

@evacide @iwein since signal uses exactly the same end-to-end encryption algorithm, that would also mean if this is broken for some reason that signal is impacted as well.

  • Copy link
  • Flag this comment
  • Block
Cassandrich
Cassandrich
@dalias@hachyderm.io replied  ·  activity timestamp 2 weeks ago

@evacide Is there any merit to the claim? An alleged mechanism by which they read messages?

  • Copy link
  • Flag this comment
  • Block
H. T.
H. T.
@Olkiuhsenn@mastodon.social replied  ·  activity timestamp 2 weeks ago

@evacide Probably fake. Use to fool the rest of us. Haha

  • Copy link
  • Flag this comment
  • Block
noivad
noivad
@noivad@techhub.social replied  ·  activity timestamp 2 weeks ago

@evacide Someone was paid to write this headline?

  • Copy link
  • Flag this comment
  • Block
mORA
mORA
@mora@mastodon.uno replied  ·  activity timestamp 2 weeks ago

@evacide Employees is the new government surveillance malware.

  • Copy link
  • Flag this comment
  • Block
Dave Wilburn :donor:
Dave Wilburn :donor:
@DaveMWilburn@infosec.exchange replied  ·  activity timestamp 2 weeks ago

@evacide

"Is my WhatsApp security advice a valid form of harm reduction for at-risk communities, or am I just lulling new victims into a false sense of security?" sure is a wonderful feeling to agonize over.

  • Copy link
  • Flag this comment
  • Block
Gabriel N
Gabriel N
@wtrmt@mastodon.social replied  ·  activity timestamp 2 weeks ago

@evacide where do the ends of _end to end encryption_ start?

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct