7 ms·
I find the wordsmithery on Meta's statement the most interesting: “We do not track your *PRECISE* location, we don’t keep logs of who everyone is messaging and
by rdrd 1y ago
I find the wordsmithery on Meta's statement the most interesting:
“We do not track your *PRECISE* location, we don’t keep logs of who everyone is messaging and we do not track the *PERSONAL* messages people are sending one another," it added. “We do not provide *BULK* information to any government.”
- Saris 1y agoIf you read around their points, it sounds like they track general location, log group messages, and provide specific information on request to a government.
- bboygravity 1y ago"'specific information request to government" == fully automated requests for literally everything all the time.
- changoplatanero 1y agoI think group messages would still be considered personal. It would only be messages you send to a business or in a group with a business that wouldn't be personal.
- cess11 1y agoThey're under the CLOUD Act, doesn't matter what their policies say.
- orthecreedence 1y agoPRISM too.
- chgs 1y agoAren’t groups end-end encrypted still, with key exchange on joining groups?
- femto 1y agoDoes the WhatsApp program generate and store/mange the private keys? If so, it would be possible for the program to send private keys on request, effectively backdooring the endpoint. Such an arrangement would allow Meta to put its hand on it heart and truthfully say it is end-to-end encrypted (on the network), whilst still providing a way around it.
- lxgr 1y agoYes, but users can compare fingerprints (sure, most probably don't, but it's definitely a deterrence against MITMing all conversations by default), receive warnings whenever fingerprints change etc. There's also supposedly a key transparency service deployed (similar to Certificate Transparency), but I haven't looked into that in detail.
- BenjiWiebe 1y agoSharing private keys gets around all that.
- lxgr 1y agoThat would require explicit code to do so, which would probably be extremely hard to explain away.
- gkbrk 1y agoAre people publicly archiving, reverse engineering, and auditing every single version of Whatsapp? Would you even know if you got a special copy of Whatsapp (still signed by Meta and valid) that has this explicit code?
- lxgr 1y ago> Are people publicly archiving, reverse engineering, and auditing every single version of Whatsapp? Absolutely for archiving: https://androidapks.com/whatsapp-messenger/com-whatsapp/old/ https://androidapks.com/whatsapp-messenger/com-whatsapp/old/ Reverse engineering to some extent as well – it's an extremely popular app, and as such attracts both security researchers and bloggers that just want to get scoops on new features behind feature flags etc. > Would you even know if you got a special copy of Whatsapp (still signed by Meta and valid) that has this explicit code? Given the above, it's feasible – at least on Android, it's fairly easy to hash the .apk you've received and compare it to publicly know versions. The threat of somebody finding unusual code on their phone will probably not deter targeted deploys by sophisticated/state level actors to specific users, but it goes some way towards making it implausible that everybody is running a backdoored version, potentially backdoored by Meta themselves, which is arguably the goal.
- mgraczyk 1y agoAnd they are legally required to do this in most places
- luis8 1y agoI don't know why you are being downvoted. https://transparency.meta.com/reports/government-data-requests/country/US/ https://transparency.meta.com/reports/government-data-reques... They can't see your messages but then can give ips or accounts that can be inferred to be related given the info meta has access to
- selcuka 1y agoAlso take the "can't see your messages" statement with a grain of salt. Like the famous Lotus Notes backdoor [1] they might have given the government an easy(ier) way to decrypt those messages. The backdoor in Lotus Notes (differential cryptography) wasn't a secret. It was public information. Ray Ozzie used it as a way to circumvent US encryption export laws. Today companies have to be more discrete. [1] http://www.cypherspace.org/adam/hacks/lotus-nsa-key.html http://www.cypherspace.org/adam/hacks/lotus-nsa-key.html
- perihelions 1y agoMeta can also just lie about it. If they were secretly granting backdoor root access to some NSA spooks, like Microsoft did with PRISM or AT&T did with 641A, most likely no one would find out, so, there'd be zero actual downside to simply lying.
- EGreg 1y agoThey usually just do a mea culpa: Camera: https://www.bitdefender.com/en-us/blog/hotforsecurity/facebook-app-for-ios-caught-accessing-camera-in-background https://www.bitdefender.com/en-us/blog/hotforsecurity/facebo... Audio: https://news.ycombinator.com/item?id=41424016 https://news.ycombinator.com/item?id=41424016 Conversations: https://www.vice.com/en/article/facebook-said-it-wasnt-listening-to-your-conversations-it-was/ https://www.vice.com/en/article/facebook-said-it-wasnt-liste... Mass surveillance: https://thehill.com/video/facebook-spying-on-users-new-report-details-social-networks-mass-surveillance/9305488/ https://thehill.com/video/facebook-spying-on-users-new-repor... Across the web: https://www.wired.com/story/ways-facebook-tracks-you-limit-it/ https://www.wired.com/story/ways-facebook-tracks-you-limit-i... Beacon: https://www.wired.com/2007/12/facebook-ceo-apologizes-lets-users-turn-off-beacon/ https://www.wired.com/2007/12/facebook-ceo-apologizes-lets-u... Apps: https://www.theguardian.com/news/2018/mar/17/cambridge-analytica-facebook-influence-us-election https://www.theguardian.com/news/2018/mar/17/cambridge-analy... People who aren't even on facebook: https://www.vox.com/2018/4/20/17254312/facebook-shadow-profiles-data-collection-non-users-mark-zuckerberg https://www.vox.com/2018/4/20/17254312/facebook-shadow-profi... Others do it too, e.g. Amazon: https://www.bloomberg.com/news/articles/2019-04-10/is-anyone-listening-to-you-on-alexa-a-global-team-reviews-audio?embedded-checkout=true https://www.bloomberg.com/news/articles/2019-04-10/is-anyone... But Facebook has always been on a whole other level https://www.theguardian.com/technology/2018/apr/17/facebook-people-first-ever-mark-zuckerberg-harvard https://www.theguardian.com/technology/2018/apr/17/facebook-...
- bdangubic 1y agoI will never understand how anyone in their right mind can use any product owned by Meta…
- gnarlouse 1y agoYep. Learning to read legal is an invaluable modern skill.
- 1oooqooq 1y agoit's well know they track group messages and messages (metadata), messages to business accounts (these they can read in full as the client send to a meta owned private key), and who forwards media to who (deduplication and cdn) and links (thanks to previews) and it scans and uploads your contact list in full all the time.
- sudahtigabulan 1y agoDe Morgan's transformations come in handy here :^)
- bawolff 1y agoI mean, i would be pretty shocked if meta refused to honour american search warrants/NSL. The real question is where they draw the line, not if they do it ever.
- NoOn3 1y agoUnfortunately, They has no lines.
- lotharcable 1y agoMeta works by identifying users, modelling their behavior, and then combining that data with third party sources (typically your financial activities) and then selling access to that data to third parties. Mostly for advertising. When you use credit or debit cards your transactions and data related to it is collected and sold. When you apply for mortgages and close on a house all that information you put in there is collected and sold. When you put your address in for the post office, when you apply for a drivers or fishing license... Your local governments collect that information and sell access to it. Meta tries to then tie in your online and app/phone activity with your legal/financial identity it can obtain through partner data brokers. This is Facebook's businesses model. So, yes, this data is available to pretty much anybody that is willing to pay for it. Which includes governments. None of this should be surprising to anybody at this point. Apple, Google, Microsoft, etc.. all of these companies will do this to greater or lesser extents nowadays since has worked out so well for Meta's bottom line.
- NitpickLawyer 1y agoThey don't need meta's cooperation for this, they can burn one of their 0-click 0-day exploits and target everyone they need to.
- edm0nd 1y agoAdditionally the NSA has all Meta and WhatsApp servers directly tapped and can just harvest data, oops i mean 'meta data', that way. Then just pass that info to Israel when their internal systems get an alert on good intel.
- ALLTaken 1y agoWow that is next level WORD SMITHERY!! Zuck dribbled and 3D Chessed the Law META DATA. Literally they did say truthfully they "only" read all the Meta Data, which is actually all data of the company Meta.
- ben_w 1y ago> Zuck dribbled and 3D Chessed the Law Mixed metaphors aside, you can't cheat the law by naming yourself something. Well, you can try, but the courts take a dim view of it.
- pcthrowaway 1y ago> > Zuck dribbled and 3D Chessed the Law > Mixed metaphors aside Zapp hit that bullseye, causing the rest of the dominoes to fall like a house of cards. Checkmate.
- lowwave 1y ago> Then just pass that info to Israel when their internal systems get an alert on good intel. And on top of that if you want make any money with company like X, you need to send your biometrics to some company in Israel. What is this Israel and surveillance capitalism? Or has this always being the case, and I am just now start to realizing it.
- 1y ago
- msgodel 1y agoI wonder if the people of Iraq have an intuitive understanding of just how much more useful the information Facebook does track is like we do.
- dash2 1y agoThis, also “logs of who EVERYONE is messaging”
- imjonse 1y ago"we don’t keep logs of who EVERYONE is messaging" just selected people then?
- netsharc 1y ago"We don't log whom Zuck is messaging, and therefore the statement 'we don't keep logs of who[m] everyone is messaging' is mathematically true!"
- beejiu 1y agoYep, they confirm it here: https://faq.whatsapp.com/444002211197967/?locale=en_US https://faq.whatsapp.com/444002211197967/?locale=en_US "This may include information about how some users interact with others on our service."
- ben_w 1y ago> we don’t keep logs of who everyone is messaging Surely they must, how else are the messages… you know… available when you use the app?
- abeppu 1y agoI'm not saying I believe their statement, but in principle they could be storing messages indexed by recipient and have the sender id be part of the encrypted content? Then you can drop messages in each user's inbox as they arrive, from which the user's app can read, but not have stored enough information to retroactively query "Show me everyone Alice has talked to"?
- d0gsg0w00f 1y agoIME, they're stored on device only. If you've ever moved phones this becomes painfully obvious unless you've setup backups to your personal Google Drive (native integration with app).
- cosmicgadget 1y ago"We" don't but these other guys with logins do.
- beejiu 1y agoRe: "we don’t keep logs of who everyone is messaging" From https://faq.whatsapp.com/444002211197967/?locale=en_US https://faq.whatsapp.com/444002211197967/?locale=en_US: > In the ordinary course of providing our service, WhatsApp does not store messages once they are delivered or transaction logs of such delivered messages. Undelivered messages are deleted from our servers after 30 days. As stated in the WhatsApp Privacy Policy, we may collect, use, preserve, and share user information if we have a good-faith belief that it is reasonably necessary to (a) keep our users safe, (b) detect, investigate, and prevent illegal activity, (c) respond to legal process, or to government requests, (d) enforce our Terms and policies. This may include information about how some users interact with others on our service. We also offer end-to-end encryption for our services, which is always activated. End-to-end encryption means that messages are encrypted to protect against WhatsApp and third parties from reading them. Additional information about WhatsApp's security can be found here. Note specifically "information about how some users interact with others on our service", which contradicts their claim they don't keep logs of which people are messaging each other.
- dataflow 1y agoAren't push notifications logged and used for getting people's data? This was in the news over a year ago: https://www.wired.com/story/apple-google-push-notification-surveillance/ https://www.wired.com/story/apple-google-push-notification-s...
- eddythompson80 1y agoIn general, all your personal information stored with Google or Apple or any other American company is subject to getting requested by a court order. If you listen to any of the True Crime podcasts, you'll always hear how google searches and cell tower location are always presented in a trial as evidence. People here always think they are so smart saying > Actualllly you can't prove that it was me who made that search query. > Actualllly you can't prove that it was me who had that cellphone around that cell tower. Could have been anybody. I could have been hacked. Judges always allow those evidence and jury always views it as incriminating. What makes more sense, that some unknown hacker hacked into your account and googled something about the thing you're here for, or that you actually just googled it yourself?
- tehjoker 1y agoWhen a CIA drone operator and their commander is behind the button, they give even less of a shit than a jury. No one will ever prosecute them.
- brewdad 1y agoI was on a jury where data like this harvested from Facebook pushed us beyond a reasonable doubt. There was just enough doubt to acquit or have a hung jury with only the physical evidence and eye witnesses. There was plenty of doubt with only the social media stuff. When you put all of it together, we reached a verdict pretty quickly.
- lxgr 1y agoDefinitely, but they don't have to contain any (plaintext) message content for encrypted messengers. On Android, push notifications were always processed by the receiving app, so it can just decrypt a payload directly (or download new messages from the server and decrypt these); on iOS, this isn't as reliable (e.g. swiping the app out of the app switcher used to break it in several iOS versions), but "VoIP notifications" and the newer "message decryption extension" [1] are. The same principle applies to Web Push – I believe end-to-end encryption is even mandatory there. [1] https://developer.apple.com/documentation/usernotifications/modifying-content-in-newly-delivered-notifications https://developer.apple.com/documentation/usernotifications/...
- zug_zug 1y agoThis is just a lie. I personally know somebody who worked at meta and they had a whole set of teams dedicated to building tools for governments to mass-export data based on their queries Now I don't know the exact details of which governments had which access (was it just for warrants, which nations, what was the line between actual terrorist versus persecuting journalists), but there was absolutely bulk export and the fact that they are lying about it makes me inclined to presume the worst.
- dotBen 1y agoRemember Snowden outlined the Google<>US government interface: The US agency would type in the gmail address of the subject (ie the primary key/identifier) and somewhere between the agency and Google a decision would be automatically made as to whether the owner of the account was a US person* or not. If yes - FISA warrant was required If no - the US agency user would have immediate access to the entire google account (think Google Take Out). In other words, if you were not a US person there was no duty to protect data. * = US Person is either a US citizen located anywhere in the world or anyone of any nationality who is physically in the US (current interpretation includes visa holders, visitors and even undocumented but that's shifting)
- paradox242 1y agoIsn't it more likely that Meta has been infiltrated by Mossad, just as they no doubt have by other intelligence services and they use these insiders to exfiltrate location data on specific targets?
- megous 1y agoSandberg herself does teary, falsehood ridden war propaganda videos for Israel, these days. Microsoft shared data early on with IDF to help target their users (would have to check their ToS to see if there's a clause for that there). I doubt there's any need to hide anything inside these kinds of companies. Leaders there likely believe they're doing the right thing helping "the good cause" by supporting extrajudicial executions of people. At worst they'll have to kick out employees who'll raise their voices, like they already did many times. No biggie.
- SoftTalker 1y agoThis is the company that built a secret localhost listener on Android so that they could track users across websites even in private mode. Do not believe this for a second. I'm much more inclined to believe they track everything in high precision and also MITM all the messages. Especially now that they are inserting ads.
- jen729w 1y ago> Especially now that they are inserting ads. I'm no apologist for Facebook, none of whose services I use. But get your facts straight. They are not 'inserting ads' in your chats, as you imply. AFAIK they are adding adds to the never-used 'Updates' tab. Annoying from an ad perspective, no doubt. Vastly different from a are-they-MITMing-your-messages perspective.
- SoftTalker 1y agoThanks for clarifying. I don't use any Meta stuff so I only read about it.
- glenstein 1y agoIt's like the game where you say the same sentence but emphasize a different word each time. "WE don’t keep logs of who everyone is messaging..." "We don't KEEP logs of everyone who is messaging..." "We don't keep logs of EVERYONE who is messaging..." Etc.
- blintz 1y agoThis isn’t some conspiracy, it’s just CYA. They know your general location from your IP and device APIs, they don’t encrypt business messaging, and they comply with subpoenas.
- FpUser 1y agoWhy would anyone care what they say. Judging by their previous behavior it is safe to say that if their lips are moving - they're lying
- advisedwang 1y agoIt's not that nefarious. > We do not track your PRECISE location If they log IP addresses, they can't say they don't log location at all. > we don’t keep logs of who everyone is messaging Seems like a pretty strong claim > we do not track the PERSONAL messages people are sending one another I don't know much about their business offering, but it seems likely it's not e2e encrypted or has some kind of escrow. Businesses often multiple people to be able to access an account and that is best done without e2e encryption... let alone auditing requirements. > We do not provide BULK information to any government Because they are subject to subpoena and search warrants. They are legally required to provided tailored information to governments. ==== All in all it's pretty much what you'd expect for Whatsapp's "e2e but otherwise conventional saas" approach. If you want better, use signal.
- smolder 1y agoYes, it's lying with a tiny bit of plausible deniability.
- Simon_O_Rourke 1y agoThat's doubly suspicious, so they can, by that statement readily hand over your imprecise other-than-personal messages at an individual level to the Israelis.
- selivanovp 1y agoIt’s a lie. Russia Ukraine war demonstrated clearly that everything you write in whatsapp, your location, any photo etc are easily accessible and monitored in real time by USA government and their three letter agencies.