← Back to context

Comment by addandsubtract

17 hours ago

WhatsApp / Meta is also on both sides of the E2EE.

Sure, but so is every security researcher in the world if they want to be, and they only need to get caught shipping exfiltration logic once.

  • > so is every security researcher in the world if they want to be

    Most security researchers lack Meta's history:

    - Testing emotional manipulation features on thousands of users non-consensually

    - Adding spyware on underage users

    - Intercept a rival app's traffic

    - Allowing harm to teen mental health

    And most importantly, most security researchers lack the money and power to fend off the legal consequences of these acts.

    • > Most security researchers lack Meta's history: [...]

      Why would you assume that security researchers don't know about these? If anything, wouldn't all the bad press and scandals make WhatsApp a more likely target of scrutiny?

      > And most importantly, most security researchers lack the money and power to fend off the legal consequences of these acts.

      Yes, security research is generally expensive, but do you have any evidence for Meta taking legal steps against it and making it actively harder? I remember e.g. the controversy around WhatsApp re-encrypting unconfirmed outbound messages to a new key; this was revealed by security researchers and widely discussed. (Not that they're making it easier by providing source code for WhatsApp's cryptography or a debug interface to validate what's actually going on in the client, but neither does e.g. iMessage.)

      In fact, there's a relatively absurd lawsuit against Meta on WhatsApp encryption going on right now, and these claims are widely being repeated all over social media.

      2 replies →