A 10-month Commerce Department probe concluded Meta could view all WhatsApp messages in unencrypted form

  • zergtoshi@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    8
    ·
    20 hours ago

    They can log anything they want and have nothing useful, if the encryption protocol is sound.
    Have a look at how TLS is designed, if you want to know more.

    • Treczoks@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      16 hours ago

      I know my way around cryptography, therefor I am skeptical. If push comes to shove, they can simply command the Whatsapp App to silently surrender the keys. Nobody would know, it is a closed source app and protocol, and they can hide what they are doing inside the (probably) TLS encrypted stream.

      • zergtoshi@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        20 hours ago

        But the key exchange is not the issue then.
        Access to private keys is.
        If the host system, on which the key exchange runs, is compromised, you’re toast.

        • Railcar8095@lemmy.world
          link
          fedilink
          English
          arrow-up
          8
          arrow-down
          1
          ·
          19 hours ago

          Where’s the private key? I can get a new phone, log with WhatsApp and download all the historical messages without intruducing any additional password or key.

          I assume they have all the required data too.