And if so, why exactly? It says it’s end-to-end encrypted. The metadata isn’t. But what is metadata and is it bad that it’s not? Are there any other problematic things?
I think I have a few answers for these questions, but I was wondering if anyone else has good answers/explanations/links to share where I can inform myself more.
It says it’s end-to-end encrypted.
Whatsapp is closed source and made by a advertising company. Wouldnt really count on that
Edit: Formatting
They don’t really need the actual contents of your messages if they have the associated metadata, since it is not encrypted, and provides them with plenty of information.
So idk, I honestly don’t see why I shouldn’t believe them. Don’t get me wrong though, I fully support the scepticism.
It can be fully end to end encrypted and still drop keyword-based metadata into the envelope. But also, I am pretty sure that the feds can access the keys if they need to. It’s e2e encrypted, but that doesn’t mean the key stays on your device.
TL;DR: Yes it is, it’s terrible. What would you expect from a Facebook product? Use Signal instead.
Thank you, but I’m looking for actual arguments that would sway someone that is trying to come to a rational conclusion. “The reputation of the company is bad” is of course valid evidence, but it would be much more interesting to know what Facebook actually gains from having users on WhatsApp.
First, it is very likely that the WhatsApp encryption is compromised, it definitely shouldn’t be trusted, as it is completely proprietary and thus not transparent to users and independent auditors. Also, unlike Signal, WhatsApp doesn’t encrypt any metadata. The biggest source of WhatsApp user data for Facebook though are address books. When you grant WhatsApp permissions to access your contacts, that data is sent to Facebook servers unencrypted. That way, Facebook can see the names and phone numbers of all of your contacts. This is not just bad for you, it’s also bad for everyone whose phone number you saved in your address book, their data is sent to Facebook, even if they don’t use any Facebook services themselves. Also, when you have WhatsApp or any app installed on your phone, it by default has access to many things that you can’t control or restrict. For example, it can access some unique device identifiers and look at stuff like the list of apps you have installed on your phone or access sensors like the gyroscope and accelerometer which can absolutely be used to track you. It’s better to keep shady apps like those made by Facebook, Google, Amazon, Microsoft or other surveillance corporations off your devices. Use FOSS alternatives with a proven track record like Signal if they are available.