For Facebook it doesn’t matter if its e2e. They control the client on both sides. They can just let the client sent the clear text data to them.
Comment on Lawsuit Alleges That WhatsApp Has No End-to-End Encryption
herseycokguzelolacak@lemmy.ml 3 weeks ago
WhatsApp client is closed source. Any claims around E2EE is pointless, since it’s impossible to verify.
Flipper@feddit.org 2 weeks ago
escapeVelocity@lemmy.ca 2 weeks ago
TMBE
Trust me bro encryption
CeeBee_Eh@lemmy.world 2 weeks ago
Any claims around E2EE is pointless, since it’s impossible to verify.
This is objectively false. Reverse engineering is a thing, as is packet inspection.
snowboardbumvt@lemmy.world 2 weeks ago
Reverse engineering is theoretically possible, but often very difficult in practice.
I’m not enough of an expert in cryptography to know for sure if packet inspection would allow you to tell if a ciphertext could be decrypted by a second “back door” key. My gut says it’s not possible, but I’d be happy to be proven wrong.
black0ut@pawb.social 2 weeks ago
Hell, as far as I know, E2EE would be indistinguishable from client to server encryption, where the server can read everything. You can see the channel is encrypted, but you can’t know who has the other key.
herseycokguzelolacak@lemmy.ml 2 weeks ago
The easiest way to break E2EE is to copy your private key to Meta’s servers. It’s very easy to implement, and close to impossible to detect.
escapeVelocity@lemmy.ca 2 weeks ago
Outside of open-source. That shit is usually illegal
CeeBee_Eh@lemmy.world 2 weeks ago
It isn’t. Otherwise security research would never happen for proprietary software and services.
escapeVelocity@lemmy.ca 2 weeks ago
SureSure no white hat never been sued before
drmoose@lemmy.world 2 weeks ago
In the US CFAA is so draconian that in certain aspects it can be very illegal to reverse engineer code behind explicit ToS which whatsapp make you agree to click-wrap upon installing the app. So Meta could easily sue you with very good chance of winning. I work in security and reverse engineer a lot of stuff but just because my company has lawyers that will protect me (also I’m not an american) but generally americans are super fucked here.
Sinthesis@lemmy.today 2 weeks ago
Now you just need Meta to allow you on their networks to inspect packets and reverse engineer their servers because as far as I know, WhatsApp messages are not P2P.
herseycokguzelolacak@lemmy.ml 2 weeks ago
No it is not. Whatsapp gets several updates a month. How do you keep up with that rate?
cley_faye@lemmy.world 2 weeks ago
It’s E2EE alright. Just, don’t ask what “ends” we’re talking about.
Canigou@jlai.lu 2 weeks ago
Their mouth and Zuckerberg’s ass