Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Except, as far as I know, Facebook/WhatsApp shouldn't be able to read the messages people send each other over the WhatsApp network because of end-to-end encryption:

https://whispersystems.org/blog/whatsapp/



They say the network communication is encrypted between end points but they don't say analysing is not being done prior to encryption on your end. What I mean is it is possible for the communication over the network to be encrypted between Bob and Alice but everything Bob writes to Alice could easily be used by WhatsApp/Facebook prior to being sent. They could even go as far as to encrypt it and just transmit your side of the conversation to their servers for later analysis.


Whatsapp is encrypted in transit. It is still stored on their servers. So they can read your messages.

Edit: Link -- https://www.eff.org/secure-messaging-scorecard


They claim end-to-end encryption, which means they don't store it unencrypted.

From a wired article about it:

"Textsecure has actually already been quietly encrypting Whatsapp messages between Android devices for a week. The new encryption scheme means Whatsapp messages will now travel all the way to the recipients? device before being decrypted, rather than merely being encrypted between the user?s device and Whatsapp?s server."


That doesn't mean they (Whatsapp) don't have decryption keys either.


If it was stored on their server I would assume I would be able to get my old messages when I change phone but it didn't happen last time I did, plus they could have implemented web also for iOS without relying on your phone to show messages in the browser (through more permissive android functionality), no?


Well they don't need to store your whole message, once they have processed it and updated their profile database with whatever is of value to them they will most likely delete it. They should all happen within minutes if not seconds of you sending the message.


I believe messages pass through the servers, but once a message makes it to your device, its online copy gets deleted.



True, but this doesn't stop them from cataloguing who I'm talking to. That data can be very valuable with facebook's model.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: