A 10-month Commerce Department probe concluded Meta could view all WhatsApp messages in unencrypted form

  • baatliwala@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 hours ago

    You can actually report a message to WhatsApp within the app. If you report the message it then the full text gets sent to WhatsApp.

      • a4ng3l@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        32 minutes ago

        Any reported message ? Back when I was doing anti spam at my ISP we could read reported spam from our customers. Obviously not all mails from / to the customers. That would be way disproportionate.

        • NaibofTabr@infosec.pub
          link
          fedilink
          English
          arrow-up
          3
          ·
          21 minutes ago

          If this is true:

          If you report the message it then the full text gets sent to WhatsApp.

          That means there’s a software switch that dumps a plaintext copy of a supposedly encrypted message when flipped.

          Therefore, all you need to read any WhatsApp message is the ability to flag the message as “reported”, and access to wherever the plaintext copies get sent.

          Considering how often security is an afterthought for corporations, the access part is probably easy.

          • a4ng3l@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            15 minutes ago

            The easiest implementation of this is that the recipient of an infringing message flags it from its local client. At that point it’s not encrypted if their claim of e2ee is true.

            It also means that only parties involved in the message exchange can flag / report them.

            Corporations are often not so monolithic ; the guys doing abuse are likely not the one who try to milk users (looking at you marketing).