And if so, why exactly? It says it’s end-to-end encrypted. The metadata isn’t. But what is metadata and is it bad that it’s not? Are there any other problematic things?

I think I have a few answers for these questions, but I was wondering if anyone else has good answers/explanations/links to share where I can inform myself more.

  • Oha@lemmy.ohaa.xyz
    link
    fedilink
    arrow-up
    106
    arrow-down
    3
    ·
    edit-2
    2 years ago

    It says it’s end-to-end encrypted.

    Whatsapp is closed source and made by a advertising company. Wouldnt really count on that

    Edit: Formatting

    • meseek #2982@lemmy.ca
      link
      fedilink
      arrow-up
      21
      arrow-down
      2
      ·
      2 years ago

      “We just capture what you wrote and to whom before it gets encrypted and sent; we see nothing wrong with that” —Mark Zuckerberg, probably

    • folkrav@lemmy.world
      link
      fedilink
      arrow-up
      21
      arrow-down
      2
      ·
      edit-2
      2 years ago

      Saying they do E2EE but not doing it would be a literal massive scale fraud. Can’t say I put Meta past those behaviors to be fair though lol

      But as the other guy said, metadata is already a lot.

    • miss_brainfart@lemmy.ml
      link
      fedilink
      arrow-up
      14
      ·
      edit-2
      2 years ago

      They don’t really need the actual contents of your messages if they have the associated metadata, since it is not encrypted, and provides them with plenty of information.

      So idk, I honestly don’t see why I shouldn’t believe them. Don’t get me wrong though, I fully support the scepticism.

      • bouh@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        2 years ago

        All they need is the encryption key for the message, and it’s not the message itself.

        • BearOfaTime@lemm.ee
          link
          fedilink
          arrow-up
          6
          ·
          2 years ago

          If they keys are held by them, they have access.

          When you log into another device, if all your chat history shows up, then their servers have your encryption key.

    • MiddledAgedGuy@beehaw.org
      link
      fedilink
      arrow-up
      5
      ·
      2 years ago

      This is what I came to express as well. Unless the software is open source, both client and server, what they say is unverifiable and it’s safest to assume it’s false. Moreover, the owning company has a verifiable and well known history of explicitly acting against user privacy. There is no reason to trust them and every reason not to.