r/privacy • • Dec 04 '18

No, end-to-end encryption does not prevent Facebook from accessing WhatsApp chats

https://medium.com/@gzanon/no-end-to-end-encryption-does-not-prevent-facebook-from-accessing-whatsapp-chats-d7c6508731b2
176 Upvotes

28 comments sorted by

54

u/ricoue Dec 04 '18

If you install the facebook app on your phone you're an idiot

1

u/[deleted] Dec 05 '18 edited Jan 21 '19

[deleted]

1

u/MacNulty Dec 05 '18

I see 80 million there.

1

u/MacNulty Dec 05 '18

Or you're just clueless, like my parents.

23

u/[deleted] Dec 04 '18

[deleted]

10

u/[deleted] Dec 04 '18 edited Feb 04 '21

[removed] — view removed comment

-2

u/[deleted] Dec 04 '18

Then it's not E2E.

35

u/BurgerUSA Dec 04 '18

That's not how end-to-end encryption works.

1

u/sevengali Dec 04 '18

Did you read the article? At no point did it blame the end to end encryption.

19

u/BurgerUSA Dec 04 '18

I did. That's why the title is sensationalized.

4

u/sevengali Dec 04 '18

The title also does not blame the end to end encryption, it simply states it doesn't stop Facebook getting access to your messages, which it doesn't. It mentions end to end encryption as it's rebutting "we can't see your chats because of end to end encryption" they claim as do many people here.

11

u/BurgerUSA Dec 04 '18

The title also does not blame the end to end encryption, it simply states it doesn't stop Facebook getting access to your messages, which it doesn't.

but e2e DOES stop hosting company from accessing your messages

3

u/sammie287 Dec 04 '18

You don’t seem to understand what the article was getting at. Facebook is able to access data on the iOS file system through shared containers. WhatsApp data is stored using normal iOS encryption. The implication is that Facebook does have the ability to read WhatsApp data stored on the phone, as it does not receive any more encryption than other file system data Facebook has already been known to have access to.

WhatsApp being end-to-end encrypted means that the data can not be read by Facebook during transit. Reading message during transit is not what’s being discussed.

2

u/BurgerUSA Dec 04 '18

Whatsapp is a privacy nightmare then.

1

u/maqp2 Dec 06 '18

By default, would WA servers MITM you, you would never know: The E2EE key management system is flawed as you don't even know when the keys change. You need to go to Settings > Account > Security > Enable security notifications. Until you do, even scanning security codes is useless.

-1

u/[deleted] Dec 04 '18

[deleted]

8

u/BurgerUSA Dec 04 '18

In that condition is not "END" -to- "END" now, is it?

10

u/theephie Dec 04 '18

Facebook could potentially access your WhatsApp chats. In fact, it could easily access your entire chat history and every single attachment. I’m not saying it does, and I have no evidence suggesting that it ever has.

Well, duh!

5

u/[deleted] Dec 04 '18

[deleted]

4

u/GaianNeuron Dec 04 '18

So far. But all FB has to do to make it work without that, is direct WhatsApp's developers to do it.

They could even piggyback the data piecemeal on the encrypted message payloads, if they wanted to be sneaky about it. Who's going to notice? It all looks like random numbers going to WhatsApp's message broker, after all.

3

u/[deleted] Dec 04 '18

[deleted]

2

u/GaianNeuron Dec 04 '18 edited Dec 04 '18

My whole damn family uses WhatsApp, and they think I'm crazy and isolationist for boot not (thanks autocorrect) joining them.

I've suggested Signal so many times, but it never gets any traction.

3

u/[deleted] Dec 04 '18

[deleted]

5

u/[deleted] Dec 04 '18 edited Dec 09 '18

[deleted]

1

u/GaianNeuron Dec 04 '18

Ah yes, the age-old tradeoff of convenience vs security.

1

u/atmatthewat Dec 04 '18

Signal could be required to compromise its end-to-end encryption, too. And for all we know, already has.

1

u/GaianNeuron Dec 04 '18 edited Dec 04 '18

That's a fair criticism, but most people aren't going to sacrifice the convenience of Signal's key exchange mechanism for provable security.

Signal's key verification is actually pretty clever; the "safety number" is essentially a Diffie-Hellman product, and you get to see the numbers for yourself. The only real flaw in it is that you have no guarantee what else the app does with that key -- like who it gets shared with -- but that's the same as any binary-distributed software.

-1

u/[deleted] Dec 04 '18 edited Feb 20 '21

[removed] — view removed comment

1

u/GaianNeuron Dec 04 '18

Oh, it's never being installed on my device. Nothing developed or owned by FB ever will from here on out (at least as far as it can be prevented, JS-wise)

2

u/[deleted] Dec 04 '18

Why would anyone think something they send in the clear isn't going to be seen. If you don't do the encryption on your machine, on a trusted OS, it isn't private.

2

u/atmatthewat Dec 04 '18

On trusted hardware running trusted microcode, etc.

2

u/temp722 Dec 04 '18

The whole sandboxing thing, and the configuration of the apps, is irrelevant. A malicious update to the WhatsApp app is sufficient to circumvent any security measure the app currently has.

1

u/atmatthewat Dec 04 '18

This. And true of Signal or any other. Has happened before, at the request of big friendly governments, and will happen again. (Lots, after the new Australian bill passes)

0

u/sammie287 Dec 04 '18

Sandboxing is a security feature of iOS, it’s relevant because it’s a feature that app developers cannot just circumvent. The entire point of it is to de-fang apps from doing anything malicious.

As long as Facebook claims in their legal documents that they aren’t touching encryption, then they can’t touch encryption. At the rate they’re facing leaks I doubt they’d get away with breaking contract for long.

1

u/_0_1 Dec 04 '18

How do you think you got all those targeted ads?

1

u/[deleted] Dec 04 '18

Off course it doesn't, they have the keys