A 10-month Commerce Department probe concluded Meta could view all WhatsApp messages in unencrypted form

    • zergtoshi@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 hours ago

      But the key exchange is not the issue then.
      Access to private keys is.
      If the host system, on which the key exchange runs, is compromised, you’re toast.

      • Railcar8095@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 hours ago

        Where’s the private key? I can get a new phone, log with WhatsApp and download all the historical messages without intruducing any additional password or key.

        I assume they have all the required data too.

        • MalMen@masto.pt
          link
          fedilink
          arrow-up
          1
          ·
          1 hour ago

          @Railcar8095 @zergtoshi actually is not my exlerience with whatsapp, since I have the backups disable, everytime I change phones I lost all my conversations. But since whatsapp is closed source, the app can indeed use encryption to comunicate p2p, but I will allways assume that the key is logged by meta, “just in case”

        • zergtoshi@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 hours ago

          Sounds like a compromised phone in the sense that it doesn’t protect (and instead transmit) the private key.