It only uses some of signal’s code. Not necessarily the OOTB key storage and security.
Comment on Lawsuit Alleges That WhatsApp Has No End-to-End Encryption
REDACTED@infosec.pub 2 weeks agoWell, Whatsapp uses signal. Bad timing
Candice_the_elephant@lemmy.world 2 weeks ago
qyron@sopuli.xyz 2 weeks ago
How?
Appoxo@lemmy.dbzer0.com 2 weeks ago
Unless proof is given, assume troll
REDACTED@infosec.pub 2 weeks ago
Read the article? An app using signal does not imply that your data is still encrypted from corporations or government. Your neighbour joe is not very likely to break already established SSL, so using signal feels like someone is trying to sell me a bridge. Sense of false security.
HereIAm@lemmy.world 2 weeks ago
WhatsApp is using Signals protocol for communication: signal.org/blog/whatsapp-complete/
I don’t fully understand what it entails, but from what I understand is that yes, WhatsApp is using the same encryption and message flow that signal uses, but you’re still using Meta’s app, and they can just read the plaintext message from there.
qyron@sopuli.xyz 2 weeks ago
To my knowledge, under Signal, the encription keys are locally generated and stored, and the traffic flows between end points as a closed packet.
This does not seem to be the case here, as the keys are generated and stored outside your equipment and, thus, are viable to be used by a third party to access packets.
But I admit I speak heavily burdened by technical ignorance.
kuhli@lemmy.dbzer0.com 2 weeks ago
My understanding is they’re sending a request to your device that then decrypts and uploads messages, not storing the keys outside your device.
Candice_the_elephant@lemmy.world 2 weeks ago
Or they can make a copy of the encryption keys on creation. Using the code is very different than using the code unedited, or using all the code.
REDACTED@infosec.pub 2 weeks ago
Read more than just the title ffs
qyron@sopuli.xyz 2 weeks ago
I did and nowhere is Signal mentioned in the article.
You state Whatsapp uses Signal. So, again: how?
REDACTED@infosec.pub 2 weeks ago
The article does not describe what encryption it uses, it described how they’re abusing it. Whatsapp using Signal protocol is public knowledge.
What I’m trying to say is that a company using signal for it’s messaging app does not imply your data is safe from that company or governments.