It’s E2EE alright. Just, don’t ask what “ends” we’re talking about.
Comment on Lawsuit Alleges That WhatsApp Has No End-to-End Encryption
herseycokguzelolacak@lemmy.ml 22 hours ago
WhatsApp client is closed source. Any claims around E2EE is pointless, since it’s impossible to verify.
cley_faye@lemmy.world 15 hours ago
Canigou@jlai.lu 6 hours ago
Their mouth and Zuckerberg’s ass
escapeVelocity@lemmy.ca 12 hours ago
TMBE
Trust me bro encryption
CeeBee_Eh@lemmy.world 14 hours ago
Any claims around E2EE is pointless, since it’s impossible to verify.
This is objectively false. Reverse engineering is a thing, as is packet inspection.
snowboardbumvt@lemmy.world 13 hours ago
Reverse engineering is theoretically possible, but often very difficult in practice.
I’m not enough of an expert in cryptography to know for sure if packet inspection would allow you to tell if a ciphertext could be decrypted by a second “back door” key. My gut says it’s not possible, but I’d be happy to be proven wrong.
black0ut@pawb.social 12 hours ago
Hell, as far as I know, E2EE would be indistinguishable from client to server encryption, where the server can read everything. You can see the channel is encrypted, but you can’t know who has the other key.
herseycokguzelolacak@lemmy.ml 6 hours ago
The easiest way to break E2EE is to copy your private key to Meta’s servers. It’s very easy to implement, and close to impossible to detect.
herseycokguzelolacak@lemmy.ml 7 hours ago
No it is not. Whatsapp gets several updates a month. How do you keep up with that rate?
escapeVelocity@lemmy.ca 12 hours ago
Outside of open-source. That shit is usually illegal
CeeBee_Eh@lemmy.world 12 hours ago
It isn’t. Otherwise security research would never happen for proprietary software and services.
drmoose@lemmy.world 3 hours ago
In the US CFAA is so draconian that in certain aspects it can be very illegal to reverse engineer code behind explicit ToS which whatsapp make you agree to click-wrap upon installing the app. So Meta could easily sue you with very good chance of winning. I work in security and reverse engineer a lot of stuff but just because my company has lawyers that will protect me (also I’m not an american) but generally americans are super fucked here.
escapeVelocity@lemmy.ca 7 hours ago
SureSure no white hat never been sued before
Sinthesis@lemmy.today 13 hours ago
Now you just need Meta to allow you on their networks to inspect packets and reverse engineer their servers because as far as I know, WhatsApp messages are not P2P.
Flipper@feddit.org 9 hours ago
For Facebook it doesn’t matter if its e2e. They control the client on both sides. They can just let the client sent the clear text data to them.