logoalt Hacker News

prakashn27yesterday at 7:37 PM9 repliesview on HN

Ex-WhatsApp engineer here. WhatsApp team makes so much effort to make this end to end encrypted messages possible. From the time I worked I know for sure it is not possible to read the encrypted messages.

From business standpoint they don’t have to read these messages, since WhatsApp business API provide the necessary funding for the org as a whole.


Replies

46493168yesterday at 8:29 PM

Facebook has never been satisfied with direct funding. The value is in selling attention and influencing users’ behavior.

show 1 reply
maqpyesterday at 8:54 PM

Nice! Hey, question: I noticed Signal at one point had same address on Google Play Store as WA. Can you tell us if Signal devs shared office space with WA during integration of the Signal protocol? Related to that, did they hold WA devs' hand during the process, meaning at least at the time it was sort of greenlighted by Moxie or something. If this is stuff under NDA I fully understand but anything you can share I'd love to hear.

yarauutayesterday at 10:31 PM

So how was Andreas Schjelderup caught sharing minor content?

show 1 reply
M95Dyesterday at 9:36 PM

From what you know about WA, is it possible for the servers to MitM the connection between two clients? Is there a way for a client to independently verify the identity of the other client, such as by comparing keys (is it even possible to view them?), or comparing the contents of data packets sent from one client with the ones received on the other side?

Thanks.

show 1 reply
bossyTeachertoday at 4:04 AM

> Ex-WhatsApp engineer here. WhatsApp team makes so much effort to make this end to end encrypted messages possible. From the time I worked I know for sure it is not possible to read the encrypted messages.

None of this makes the point you want to make. Being a former engineer. The team making "so much effort". You "knowing for sure". Like many in security, a single hole is all it takes for your privacy to pour out of your metaphorical bag of sand.

mike_dyesterday at 10:11 PM

I have no doubt that that rank and file engineers were not aware of the underlying functionality that allowed for plain text content to be read.

Nobody would ever create a SendPlainTextToZuck() function that had to be called on every message.

It would be as simple as using a built in PRNG for client side key generation and then surreptitiously leaking the initial state (dozens of bytes) once in a nonce signing or something when authenticating with the server.

show 1 reply
NoImmatureAdHomtoday at 1:10 AM

The backups are either unencrypted by default or have keys held by Meta / your backup provider. I think this means three-letter agencies can see your chats, just with a slight delay.

Another comment above mentions that you can recover conversation histories with just your phone number--if that's true then yup. The E2EE is all smoke and mirrors.

blindriveryesterday at 8:03 PM

It only takes one engineer in all the teams at Whatsapp that has different directives to make all your privacy work completely useless.

show 4 replies
ewuhicyesterday at 10:45 PM

[flagged]