Comment by lxgr
16 hours ago
They only need to get caught doing it once to have a gigantic lawsuit on their hands. They could possibly pull it off very selectively, but doing it in a dragnet fashion seems incredibly risky.
16 hours ago
They only need to get caught doing it once to have a gigantic lawsuit on their hands. They could possibly pull it off very selectively, but doing it in a dragnet fashion seems incredibly risky.
What grounds would the lawsuit be based on? I can’t imagine that slurping any kind of data would be inconsistent with their EULA.
The only risk would be the reputational damage. And as far as their bottom line is concerned, the impact of that would be negligible—how many of WhatsApp’s billion(?) users know that it’s supposed to be E2EE, let alone are under the illusion that Meta doesn’t have access to their data?
Publicly stating to not have access to message contents yet doing otherwise, i.e. outright deception, doesn't seem like something you can EULA your way out of in most jurisdictions.
Beyond that, the GDPR and similar laws also impose limits as to what you can EULA away even without being deceptive about it.
At best, it would come down to the details of what their marketing materials have claimed wrt to keeping contents secret. Do you have anything concrete they've promised? I don't remember anything, but maybe that's just my bad memory.
Anything specific from the GDPR you'd apply here?
My suspicion is that things like URL previews, or when the app calls a handler to open a link (YouTube, browser), are still monitored.
So e.g. opening a link to an Amazon product that a friend sent makes you a target for ads in that category.
It's a suspicion, they'd probably argue their EULA allows this. The typical "we have to monitor links for dangerous content" is always the standard bullshit.
This is indeed a common vector of privacy leaks on either the recipient side (to the sender, in this case, if they operate the target of the link for which a preview is being rendered) or to the platform provider (if the preview is rendered server-side). But last time I checked, in WhatsApp, URL previews are rendered exclusively on the sender side and then sent as (E2E encrypted) media to the recipient.