For open source messengers, you can check whether they actually encrypt your messages and whether the server has access to your encryption keys but what about WhatsApp? Since it’s not open source, you can’t be sure that the encryption keys aren’t sent to the server, right? Has there been a case where a government was able to access WhatsApp chats without reading them from the phone itself?

  • cjf
    link
    fedilink
    English
    arrow-up
    10
    ·
    1 year ago

    I believe this is down to what they define as being end to end encrypted.

    It’s no secret that WhatsApp adopted Signal’s encryption protocol just before Meta acquired them, but since it’s all closed source we don’t know if they’ve changed anything since the announcement in 2016 that all forms of communications on WhatsApp are now encrypted and rolled out.

    Within WhatsApp’s privacy policy, it’s important to note that they only mention end to end encryption when it comes to your messages. Everything else is apparently “fair game” for collection. Of note, the Usage and Log information point details all the metadata they collect on you automatically, including how you use the service; how long you use the service; your profile info; the groups you’re in; whether you’re online; and the last time you were online, to name a few things.

    I guess what I’m trying to say is that technically they are end to end encrypted by definition, and whilst they’ve gone ahead and implemented things such as encrypted backups (that you must enable) to make it harder for them to read your message contents, they can still collect a lot of metadata on every user.

    • cmeerw@programming.dev
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 year ago

      It’s no secret that WhatsApp adopted Signal’s encryption protocol just before Meta acquired them, but since it’s all closed source we don’t know if they’ve changed anything since the announcement in 2016 that all forms of communications on WhatsApp are now encrypted and rolled out.

      There is an Open Source implementation of the WhatsApp protocol: yowsup

      • cjf
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        I’ve not seen this before. This is really neat! Thanks for sharing ❤️

    • SheDiceToday@eslemmy.es
      link
      fedilink
      arrow-up
      3
      ·
      1 year ago

      And the metadata is enough to get convictions. A person was convicted back in 2019 or so based on the metadata of her whatsapp conversation with a reporter. Natalie something, I think.

      • cjf
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        It wouldn’t surprise me if WhatsApp’s model on this is what the UK government were thinking of with the Online Safety Bill when they tried to enforce a back door in encrypted messengers.

        It’s incredible just how much more interesting metadata can be than the actual message contents.

        Explaining this to people when they ask why I don’t use WhatsApp is pretty difficult though.

        I wouldn’t feel comfortable if I found out that what I thought was just a casual walk down the street mindlessly chatting with a friend turned out to also involve a third party neither of us were aware of tracking all of our movements.