cross-posted from : https://lemmy.zip/post/71321898
Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance


Telegram and whatsapp never had encryption. Also - they just give your messages on law enforcement request, always have.
Signal - how does it work with signal again?
Telegram has shitty 1-to-1 encryption but no group encryption.
WhatsApp claims to use the same encryption algorithms as Signal, but you can’t audit it.
They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.
Which is clever, to be fair. Whether or not that’s legal is already a court case. The law is so frightfully grey.
Its also a failure of the user’s access control and operating security.
Once a third party has access to the secure environment, that environment is and will always be compromised.
Is the user made aware of this by the operator (signal, telegram, et al)?
If not, it’s a big haul to get to competency. The operator should be educating users on how to limit compromise.
It NEVER advertises itself as such.
IIRC Signal DOES warn you about this, first when you make an account, and then when you try to save media files, and when you try to start a group chat. The others aren’t remotely secure anyway and I have no interest in attempting to defend them.
WhatsApp uses signal protocol
But that does not prevent Meta from accessing your messages.
How?
WhatsApp is owned by meta
Signal protocol is end to end encrypted
Yes. How does that happen? You open the app you type a message you hit send. In that process WhatsApp has access to your clear text message that they get from the keyboard. They can do whatever they want with that. They could encrypt your message with your key and also one of their keys. They could send those together so that they look like one message but at their servers split their copy off.
Damn
You don’t ask too many questions about signal cos the answers don’t make you any more confident.