← Back to context

Comment by jcgl

13 hours ago

WhatsApp is E2EE, but Meta controls both ends. Instead of reading your plaintext on the server, they read it on the client. Not that tricky.

I presume the hardest part would be avoiding detection via decompilation and other reverse engineering techniques. Not familiar with that space (can anyone here shed some light?), but it seems likely that an entity with Meta’s resources would be able to figure that out.

E2EE probably protects well against bulk data collection (traffic analysis would sniff out sending 2x volume of data pretty quickly). But something more subtle and targeted, smuggled out in various fields of various protocols, would be hard to detect.

They only need to get caught doing it once to have a gigantic lawsuit on their hands. They could possibly pull it off very selectively, but doing it in a dragnet fashion seems incredibly risky.

  • What grounds would the lawsuit be based on? I can’t imagine that slurping any kind of data would be inconsistent with their EULA.

    The only risk would be the reputational damage. And as far as their bottom line is concerned, the impact of that would be negligible—how many of WhatsApp’s billion(?) users know that it’s supposed to be E2EE, let alone are under the illusion that Meta doesn’t have access to their data?

  • My suspicion is that things like URL previews, or when the app calls a handler to open a link (YouTube, browser), are still monitored.

    So e.g. opening a link to an Amazon product that a friend sent makes you a target for ads in that category.

    It's a suspicion, they'd probably argue their EULA allows this. The typical "we have to monitor links for dangerous content" is always the standard bullshit.