TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

End-to-end encryption does not prevent Facebook from accessing WhatsApp chats

173 点作者 humanetech超过 6 年前

13 条评论

Strom超过 6 年前
There&#x27;s no need for theoretical chat history leaks, there&#x27;s already a practical one in place. Online WhatsApp backups aren&#x27;t encrypted with end-to-end encryption. [1][2] WhatsApp keeps being &quot;helpful&quot; and aggressively suggests users turn on online chat backup, without mentioning on the same screen that this means your chat history will be uploaded without end-to-end encryption. The history is encrypted with a key that is sent to WhatsApp servers. This is used to provide a passwordless backup restore function even when you lose your phone. You contact WhatsApp with your mobile number and WhatsApp sends you back a code that is used to derive the key that was used to encrypt the backup which was sent to Apple&#x2F;Google.<p>All of this makes Zuckerberg&#x27;s claims that law enforcement can&#x27;t read the messages because Facebook can&#x27;t pretty misleading. Law enforcement could get the backup from Apple&#x2F;Google and the key from WhatsApp and have access to the whole chat history. There are apps already available to help you through this process. [3]<p>--<p>[1] <i>Media and messages you back up aren&#x27;t protected by WhatsApp end-to-end encryption while in iCloud.</i> <a href="https:&#x2F;&#x2F;faq.whatsapp.com&#x2F;en&#x2F;iphone&#x2F;20888066&#x2F;" rel="nofollow">https:&#x2F;&#x2F;faq.whatsapp.com&#x2F;en&#x2F;iphone&#x2F;20888066&#x2F;</a><p>[2] <i>Media and messages you back up aren&#x27;t protected by WhatsApp end-to-end encryption while in Google Drive.</i> <a href="https:&#x2F;&#x2F;faq.whatsapp.com&#x2F;en&#x2F;android&#x2F;20887921&#x2F;" rel="nofollow">https:&#x2F;&#x2F;faq.whatsapp.com&#x2F;en&#x2F;android&#x2F;20887921&#x2F;</a><p>[3] <i>Elcomsoft Explorer for WhatsApp 2.30 can now download and decrypt Android user’s encrypted WhatsApp communication histories</i> <a href="https:&#x2F;&#x2F;blog.elcomsoft.com&#x2F;2018&#x2F;01&#x2F;extract-and-decrypt-whatsapp-backups-from-google&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.elcomsoft.com&#x2F;2018&#x2F;01&#x2F;extract-and-decrypt-whats...</a>
评论 #18479973 未加载
评论 #18479881 未加载
评论 #18479869 未加载
评论 #18479924 未加载
StavrosK超过 6 年前
I don&#x27;t understand this argument. &quot;Facebook control the WhatsApp code, therefore they can do whatever they want, therefore they can read your messages&quot;. I mean, yeah, by that metric, Signal could too, and every other encrypted messenger. We never relied on &quot;Facebook can&#x27;t change the code&quot; for security, so I don&#x27;t see how this post brings any new information to the table.<p>I don&#x27;t even know why it goes into backup folder details and things, as if they matter. If Facebook wanted to change the code to read your chats, they wouldn&#x27;t have to count on the existence of a specially named folder, they could just change the code to send the chats to them directly.
评论 #18479671 未加载
评论 #18479666 未加载
评论 #18479677 未加载
评论 #18479664 未加载
评论 #18479691 未加载
评论 #18480258 未加载
评论 #18479890 未加载
评论 #18479969 未加载
评论 #18479879 未加载
petters超过 6 年前
&gt; it would take a good iOS developer just a few days to put in place code in both the Facebook and WhatsApp apps that could discretely copy this database from one app to the other, via their shared container.<p>Weird article. If modifying the WhatsApp app is on the table, there are trivial ways to send decrypted messages elsewhere.
sergioj97超过 6 年前
I think the encryption thing was more about Facebook not being able to intercept your messages, read&#x2F;store them, and remain unnoticed. Of course they can &quot;still&quot; read your messages as they could rewrite the app in a few subtle ways to achieve that easily, but that&#x27;s nothing new.<p>I guess that if the app starts looking for the chats within the devices, it would be much easier to spot than it would if the messages were just analyzed as they went through WhatsApp&#x27;s servers (so that&#x27;s what the encryption is for).
plantfbsdff超过 6 年前
He is saying data can be access by facebook on your phone since its simply using keychain to store your message and they have access to that keychain. They could theoretically send your entire chat history to facebook. End-to-end encryption does not entail they are not snooping on your phone, just that when the message is sent, it is encrypted.
sarabande超过 6 年前
I&#x27;ve never programmed for an app store -- what&#x27;s the security measure that ensures the Signal version you install corresponds to some trusted state of the code base?
评论 #18479744 未加载
评论 #18479737 未加载
samblr超过 6 年前
Facebook treats our Whatsapp message content just like it&#x27;s feed.<p>Here is what happened few weeks ago : I exchanged whatsapp messages with a well known founder. Lo and behold - news about him and his startup are all over my facebook feed. Some which was published years ago.<p>We live in echo chambers.
m-p-3超过 6 年前
End-to-end encryption like these shouldn&#x27;t be considered private as long as no one else than yourself control the private key.<p>It&#x27;s not as convenient, but misplacing trust into corporation that has no interest in your privacy is dangerous.
discoball超过 6 年前
Common sense says that since FB owns WhatsApp no one should trust it. It&#x27;s no different than if China owned WhatsApp. I mean WeChat. Just common sense.
sidcool超过 6 年前
Title is a bit misleading in my opinion. If you back up your chats to Google Drive, they obviously won&#x27;t be E2E encrypted.
umairj超过 6 年前
I have also noticed seeing ads related to my voice calls and images shared over WhatsApp. Has anyone else noticed the same?
throwaway648超过 6 年前
and os companies can install key loggers on your device&#x2F;machine. and chipset manufacturers can backdoor the system. and so on.<p>no piece of hardware or software is safe from evil deeds of people building them.
addedlovely超过 6 年前
Messages may be sent encrypted, but I bet they are analysed before being encrypted. Without an external independent audit I&#x27;m not sure I&#x27;d trust Zuck.