A 10-month Commerce Department probe concluded Meta could view all WhatsApp messages in unencrypted form

  • zergtoshi@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 hours ago

    But the key exchange is not the issue then.
    Access to private keys is.
    If the host system, on which the key exchange runs, is compromised, you’re toast.

    • Railcar8095@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 hours ago

      Where’s the private key? I can get a new phone, log with WhatsApp and download all the historical messages without intruducing any additional password or key.

      I assume they have all the required data too.

      • MalMen@masto.pt
        link
        fedilink
        arrow-up
        1
        ·
        1 hour ago

        @Railcar8095 @zergtoshi actually is not my exlerience with whatsapp, since I have the backups disable, everytime I change phones I lost all my conversations. But since whatsapp is closed source, the app can indeed use encryption to comunicate p2p, but I will allways assume that the key is logged by meta, “just in case”

      • zergtoshi@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        Sounds like a compromised phone in the sense that it doesn’t protect (and instead transmit) the private key.