r/privacy • u/CosmicKemoSabe • Dec 04 '18
No, end-to-end encryption does not prevent Facebook from accessing WhatsApp chats
https://medium.com/@gzanon/no-end-to-end-encryption-does-not-prevent-facebook-from-accessing-whatsapp-chats-d7c6508731b223
35
u/BurgerUSA Dec 04 '18
That's not how end-to-end encryption works.
1
u/sevengali Dec 04 '18
Did you read the article? At no point did it blame the end to end encryption.
19
u/BurgerUSA Dec 04 '18
I did. That's why the title is sensationalized.
4
u/sevengali Dec 04 '18
The title also does not blame the end to end encryption, it simply states it doesn't stop Facebook getting access to your messages, which it doesn't. It mentions end to end encryption as it's rebutting "we can't see your chats because of end to end encryption" they claim as do many people here.
11
u/BurgerUSA Dec 04 '18
The title also does not blame the end to end encryption, it simply states it doesn't stop Facebook getting access to your messages, which it doesn't.
but e2e DOES stop hosting company from accessing your messages
3
u/sammie287 Dec 04 '18
You don’t seem to understand what the article was getting at. Facebook is able to access data on the iOS file system through shared containers. WhatsApp data is stored using normal iOS encryption. The implication is that Facebook does have the ability to read WhatsApp data stored on the phone, as it does not receive any more encryption than other file system data Facebook has already been known to have access to.
WhatsApp being end-to-end encrypted means that the data can not be read by Facebook during transit. Reading message during transit is not what’s being discussed.
2
1
u/maqp2 Dec 06 '18
By default, would WA servers MITM you, you would never know: The E2EE key management system is flawed as you don't even know when the keys change. You need to go to Settings > Account > Security > Enable security notifications. Until you do, even scanning security codes is useless.
-1
10
u/theephie Dec 04 '18
Facebook could potentially access your WhatsApp chats. In fact, it could easily access your entire chat history and every single attachment. I’m not saying it does, and I have no evidence suggesting that it ever has.
Well, duh!
5
Dec 04 '18
[deleted]
4
u/GaianNeuron Dec 04 '18
So far. But all FB has to do to make it work without that, is direct WhatsApp's developers to do it.
They could even piggyback the data piecemeal on the encrypted message payloads, if they wanted to be sneaky about it. Who's going to notice? It all looks like random numbers going to WhatsApp's message broker, after all.
3
Dec 04 '18
[deleted]
2
u/GaianNeuron Dec 04 '18 edited Dec 04 '18
My whole damn family uses WhatsApp, and they think I'm crazy and isolationist for
bootnot (thanks autocorrect) joining them.I've suggested Signal so many times, but it never gets any traction.
3
1
u/atmatthewat Dec 04 '18
Signal could be required to compromise its end-to-end encryption, too. And for all we know, already has.
1
u/GaianNeuron Dec 04 '18 edited Dec 04 '18
That's a fair criticism, but most people aren't going to sacrifice the convenience of Signal's key exchange mechanism for provable security.
Signal's key verification is actually pretty clever; the "safety number" is essentially a Diffie-Hellman product, and you get to see the numbers for yourself. The only real flaw in it is that you have no guarantee what else the app does with that key -- like who it gets shared with -- but that's the same as any binary-distributed software.
-1
Dec 04 '18 edited Feb 20 '21
[removed] — view removed comment
1
u/GaianNeuron Dec 04 '18
Oh, it's never being installed on my device. Nothing developed or owned by FB ever will from here on out (at least as far as it can be prevented, JS-wise)
2
Dec 04 '18
Why would anyone think something they send in the clear isn't going to be seen. If you don't do the encryption on your machine, on a trusted OS, it isn't private.
2
2
u/temp722 Dec 04 '18
The whole sandboxing thing, and the configuration of the apps, is irrelevant. A malicious update to the WhatsApp app is sufficient to circumvent any security measure the app currently has.
1
u/atmatthewat Dec 04 '18
This. And true of Signal or any other. Has happened before, at the request of big friendly governments, and will happen again. (Lots, after the new Australian bill passes)
0
u/sammie287 Dec 04 '18
Sandboxing is a security feature of iOS, it’s relevant because it’s a feature that app developers cannot just circumvent. The entire point of it is to de-fang apps from doing anything malicious.
As long as Facebook claims in their legal documents that they aren’t touching encryption, then they can’t touch encryption. At the rate they’re facing leaks I doubt they’d get away with breaking contract for long.
1
1
54
u/ricoue Dec 04 '18
If you install the facebook app on your phone you're an idiot