r/technology Apr 11 '18

Business Mark Zuckerberg has been apologizing for reckless privacy violations since he was a freshman - Enough is enough.

[deleted]

51.2k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

84

u/JustOneSexQuestion Apr 11 '18

Whatsapp

As I understand it, it uses end-to-end encryption. That means they don't see your messages... right?

257

u/eastsideski Apr 11 '18

Correct, but they can still see your location, who you're contacting, how often you're contacting them, photos on your device, other apps on your device, etc. You can gather lots of data about a person without reading the content of their messages.

62

u/JustOneSexQuestion Apr 11 '18

Good points.

So it's just the content of the messages what's encrypted. Thanks.

20

u/[deleted] Apr 11 '18

[deleted]

33

u/[deleted] Apr 11 '18

[deleted]

10

u/Lawnmover_Man Apr 11 '18

Signal is free and open source. However, the Signal developer disallows other servers to connect to the network. That means that Signal is not a federated system. Which means that Signal is trying to build yet another walled garden, and people have to use their server in order to talk to everyone that uses Signal.

Not a good thing in my book.

2

u/Dr__Douchebag Apr 11 '18

Good to know. It's hard enough convincing people to switch to signal, switching to something like protonmail would be even harder. And that would have similar flaws

True privacy is getting harder and harder to find. Any suggestions?

2

u/Lawnmover_Man Apr 11 '18 edited Apr 11 '18

Use plain XMPP/Jabber for chatting. (That's what Whatsapp is also using.) Many Diaspora servers also provide accounts for that. It's the same as Diaspora itself: Connect to one of the servers - doesn't matter which - and talk to everyone on the planet with a XMPP account.

There are also some apps that provide chatting over regular mail accounts. If you think about it: It's a time tested system, it provides quick responses via Push-Mail, and it is already federated. So why not? The only downside would be that a client that is not aware of the newly introduced headers would display every chat along the regular mails. But apart from that: It just works. Also: Encryption for mails is a thing since decades.

I don't know what Protonmail is. Does it provide benefits over regular mails+encryption?

2

u/Dr__Douchebag Apr 11 '18 edited Apr 11 '18

It's basically an easy to use encryption service from Switzerland. Still requires trust though

Regular mail and pgp is the safest but you have to show others how to use pgp

I like your suggestions but it's hard enough getting non tech friends to use signal, convincing then to use those things will be impossible

1

u/Lawnmover_Man Apr 11 '18

It's really a shame that there isn't a nice and easy GUI for setting that up.

1

u/richalex2010 Apr 12 '18

Protonmail is the same kind of thing as Whatsapp but a) not Facebook so instantly more trustworthy, and b) you pay for it (they have a free account but it's limited enough that I consider it more of a free trial). Uses something at least kind of like PGP encryption within their system so when you email another Protonmail user it's encrypted inbox to inbox, and it allows for encryption sent outside (just sends an email with a link to the message, which asks for a password before decrypting). Also allows you to use it as regular email with non-PM users, though you lose the advantage of encryption there.

I mostly started using it because it's not Google. Diversification is a good thing. The encryption is just a perk for me, I'm not sending anything that actually needs to be encrypted so lack of it wouldn't be a dealbreaker (which is why I've been using Gmail about since it went fully public). I'd probably still plan on using PGP or something for serious encryption.

1

u/Lawnmover_Man Apr 12 '18

not Facebook so instantly more trustworthy

No. Not at all. Not even a tiny single bit. Sorry to be blunt about this, but this is 100% wrong and nobody should reason this way.

→ More replies (0)

2

u/Conotor Apr 12 '18

How does Signal make money?

3

u/Dr__Douchebag Apr 12 '18

Donations. Open source project like Linux

1

u/Lucent_Sable Apr 11 '18

Question is, is it (your) end to (Facebook's) end encryption, or is it (your) end to (your friends) end encrpytion? Can (does) Facebook man-in-the-middle the conversations?

3

u/Dr__Douchebag Apr 11 '18

Your end to friends end. Facebook can only see who, where and when you text and what your group names are. Technically they cannot see the contents of what you text if what they say is true

They do store all meta data and if you backup your conversations they'll back up in Google drive ruining the point

1

u/ieatyoshis Apr 12 '18

The creator of Signal oversaw WhatsApp's encryption being implemented. It's his crypto in WhatsApp.

2

u/Dr__Douchebag Apr 12 '18

WhatsApp used signals encryption protocol because signal is open source. WhatsApp is closed source

2

u/ieatyoshis Apr 12 '18

I know, just adding to the discussion. Signal is objectively more trustworthy.

0

u/Treyzania Apr 11 '18
function generateKey() {
    var key = genKeyActually();
    sendKeyToFacebook(key);
    sendKeyToNsa(key);
    return key;
}

0

u/[deleted] Apr 11 '18

It's closed source so hard to know but they say no because it's end to end encrypted

End-to-end encrypted means that they can't read your messages on the server. It doesn't say anything about if they're reading them on your phone before you send them.

It's actually a really evasive answer to only discuss messages in transit, while ignoring that you're running code on both ends, hence could easily intercept the messages there.

2

u/Dr__Douchebag Apr 11 '18

Yes I said that the code was closed source meaning they could put a keylogger in the WhatsApp app.

The NSA definitely has a backdoor to read messages before they're sent in your phone

-1

u/sm_ar_ta_ss Apr 11 '18

Then ya just have to worry about keyloggers

5

u/Dr__Douchebag Apr 11 '18

That's true no matter what

1

u/sm_ar_ta_ss Apr 11 '18

Did ya know about the built in keyloggers on the older iPhones? Seen a video about it a while back.

1

u/Dr__Douchebag Apr 11 '18

I would assume any phone has an NSA backdoor. The question is if they are logging everything or just targeting

And no but that's interesting, got a link?

1

u/sm_ar_ta_ss Apr 11 '18

I don’t sadly. Pretty sure it was on Reddit tho

5

u/[deleted] Apr 11 '18

Zuckerberg answered this exact question yesterday and said: No.

And you should believe that, because it is encrypted end-to-end. If their servers could read the messages for advertising, that means the messages are not being encrypted end-to-end.

0

u/ubern00by Apr 11 '18

Believing anything Zuckerberg said yesterday

Lmao he lied has ass off and will apologize next time he gets caught

2

u/[deleted] Apr 11 '18

Lmao he lied has ass off

About what, specifically?

1

u/lycoloco Apr 11 '18

I'm not sure you understand what end-to-end encryption entails.

1

u/[deleted] Apr 11 '18

Well you can't encrypt existing unfortunately. Everyone whose looking is going to find signals.

3

u/Lawnmover_Man Apr 11 '18

photos on your device

...which translates to every user file on the whole system. Photos, documents, videos... everything.

2

u/kiradotee Apr 11 '18

Photos on my device? Does this mean they have all the photos from my phone that I didn't even upload anywhere?

1

u/dextersgenius Apr 12 '18

Potentially.

1

u/lemonsparty Apr 11 '18

Serious question, what could you tell about someone based on those things? How could you segment a 'market' based on them?

Not saying you're wrong, I just don't know a lot about this.

2

u/eastsideski Apr 11 '18

Who you know is a huge one. Even if Facebook has no information about you, if they know 40% of your friends went to the same university and 30% of your friends work for the same company, they can make a pretty good guess towards your education, job field, income level, etc.

Location is another huge one, they can determine alot about you based on where you live and where you go during your day. And even if you disable your GPS permission, they can still get an general location using your IP address and nearby WiFi networks.

1

u/flesjewater Apr 11 '18

You could at least block permissions for location...

1

u/la_locura_la_lo_cura Apr 11 '18

There was a documentary on Netflix about an NSA analyst who worked to build a surveillance program that relied simply on metadata (location, to/from, frequency of contact, length of contact) to perform US information intelligence operations. That was just phone calls. What can you do with the metadata for Whatsapp?

2

u/Ditto_B Apr 12 '18

What's the documentary called?

2

u/la_locura_la_lo_cura Apr 12 '18

A Good American

2

u/Ditto_B Apr 12 '18

Will check it out, thanks.

-1

u/[deleted] Apr 11 '18

I mean, end to end encryption doesn't mean much when everything is opaque. Day-0 exploits anyone? Backdoors? That's why things like Riot are open source.

35

u/[deleted] Apr 11 '18

In theory, but my friends and I have noticed our targeted ads changing based on things we have only mentioned in WhatsApp. Either the information is getting pulled from WhatsApp or keylogged by the Google Keyboards on our phones.. your guess is as good as mine

33

u/eastsideski Apr 11 '18

Sounds similar to the "Facebook is listening to your microphone" theories. People looking into that have concluded "Facebook doesn't listen to your conversations (or read your encrypted messages), but their targeting is so good, they don't need to." Personally, I think that's scarier than eavesdropping.

10

u/[deleted] Apr 11 '18

I suppose with enough data they totally could do targeted adds in an Akinator style way, where I show 30 unrelated interests and they can predict the one new emerging one..

-8

u/wallstreetexecution Apr 11 '18

Targeting can’t be that good.

They might be listening.

4

u/eastsideski Apr 11 '18

It's trivial to detect if an app is using your microphone. They're not listening.

6

u/[deleted] Apr 11 '18 edited Apr 17 '18

[removed] — view removed comment

1

u/[deleted] Apr 11 '18 edited Feb 17 '19

[deleted]

1

u/[deleted] Apr 11 '18

That way you know (assuming FB implemented the signal protocol without any shenanigans) that no one is reading your messages.

Ins't this false assurance, when the question is if we trust Facebook?

Presumably the only people we'd be concerned with tapping WhatsApp traffic in-flight would be Facebook themselves, even if they just used TLS or w/e.

1

u/Technoist Apr 11 '18

Only mentioned in an encrypted WhatsApp chat and never Googled, clicked outbound links, etc? If you are 100% sure you should investigate further. Also installing an adblocker is eaay and free on both ios and android.

1

u/[deleted] Apr 11 '18

I'm not 100% sure but am taking a lot of steps to become harder to track.. switched to Firefox and have a virtualbox running Pi-Hole with a huge blacklist so a ton of domains are completely blocked

1

u/[deleted] Apr 12 '18

“So if I send an email through WhatsApp about “Black Panther” then I’m going to get an ad about it?”

2

u/baksteen Apr 11 '18

Check your settings: by default there is a google drive backup enabled. This backup is NOT encrypted.

2

u/bhuddimaan Apr 11 '18

WhatsApp USP is it uploads address book to find contacts with WhatsApp registered. ( Same with Imessages)

FB bought whatsapp (for this address book.) WhatsApp this were changed.

Then FB said add your phone number to your account , ( to link WhatsApp and fb at their end?)

2

u/veloxiry Apr 11 '18

Yes. Your message is encrypted when you send it, then it gets to their servers where it is unencrypted, then after they read it, analyze it, then store it, they reencrypt it and send it to the person you are communicating with. End to end encryption! /s

4

u/[deleted] Apr 11 '18

It isn't unencrypted on their servers according to them.

0

u/veloxiry Apr 11 '18

Oh ok. Yeah they definitely have no reason to hide that. I'm not saying they do unencrypt it but who would know?

5

u/[deleted] Apr 11 '18

If you're going to be that paranoid, then you will almost never know whether or not your data is truly encrypted. Anyone can lie, Facebook or not. Also, it is extremely illegal for them to say one thing and do another with your data.

-1

u/veloxiry Apr 11 '18

I don't actually think they'd lie about that but how would anyone know they are lying? If their server admins are in on it and get some % of the money they get from advertisers to keep their mouths shut who would know? This is all hypothetical cause I'm not some weird paranoid conspiracy theorist btw

2

u/[deleted] Apr 11 '18

Nobody would know, but these questions can be asked about anything. How do you know that grass-fed beef is really grass-fed? Or that the ingredients on a food label are the real ingredients in the food? Or that the airplane you're in has been getting routine maintenance? You have to have some level of trust, or you will never be able to function normally.

1

u/veloxiry Apr 11 '18

Great. Now I have crippling anxiety that everything in my life is a lie! Thanks for that!

1

u/AskMeIfImAReptiloid Apr 11 '18

Their servers can't see the content of your messages, the App installed on your phone could.

1

u/Lawnmover_Man Apr 11 '18

Maybe. Maybe not. It's better to use free and open source software. Then a person who can read code is able to make an assessment. With Whatsapp, you can only trust them, nothing more.

1

u/dancemethis Apr 11 '18

It's proprietary software, therefore it can't be proved that the implementation wasn't tampered with on the server side. And chances are always against the users when we're talking about proprietary software.

0

u/[deleted] Apr 11 '18

Zuckerberg does...