Hacker News new | ask | show | jobs
by changoplatanero 359 days ago
I think group messages would still be considered personal. It would only be messages you send to a business or in a group with a business that wouldn't be personal.
1 comments

They're under the CLOUD Act, doesn't matter what their policies say.
Aren’t groups end-end encrypted still, with key exchange on joining groups?
Does the WhatsApp program generate and store/mange the private keys? If so, it would be possible for the program to send private keys on request, effectively backdooring the endpoint. Such an arrangement would allow Meta to put its hand on it heart and truthfully say it is end-to-end encrypted (on the network), whilst still providing a way around it.
Yes, but users can compare fingerprints (sure, most probably don't, but it's definitely a deterrence against MITMing all conversations by default), receive warnings whenever fingerprints change etc.

There's also supposedly a key transparency service deployed (similar to Certificate Transparency), but I haven't looked into that in detail.

Sharing private keys gets around all that.
That would require explicit code to do so, which would probably be extremely hard to explain away.
PRISM too.