Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Even if WhatsApp's crytpo is as flawless in implementation as we'd like FB still has access to all that metadata.

Note that this argument is even more problematic for OpenPGP-encrypted email, as such email sends all metadata and some message data in plaintext.



Note that this argument is even more problematic for OpenPGP-encrypted email, as such email sends all metadata and some message data in plaintext.

I ususally respect tptacek a lot but when it comes to Whatsapp I actively avoid it if at all possible, preferring Telegram even if the crypto is more than questionable. Same goes for mail: I prefer it - even unencrypted - over Whatsapp.

For some of us our treat model is more concerned about Facebook and less about major TLAs.

With Whatsapp I have to expect that all metadata about me - and my friends - are fed into Facebook and datamined from here to eternity and back again or until the end of the world as we know it.

I have little to hide but given the catastrophically bad ad targeting of Facebook (yes, I am still a happily married father, a Java developer, a Norwegian. I don't need ANY more ads for dating websites until I specifically change my profile to let you know, THANK YOU. I would be happy to learn about useful developer tools or underrated fast food restaurants though. I also appreciated the uber ad with bundled coupon in google maps a few weeks ago and tested uber for the first time.)

Given the same catastrophically bad targeting and given that it is the same owner who as far as I know hasn't yet apologised for his remarks about how trusting him was stupid it wouldn't surprise me if is more a WHEN than a IF that Facebook is going to sell everyones data to insurance companies, support scam call centers etc.


I agree with not using WhatsApp due to it's ties to FB and metadata issues, but Telegram is arguably even worse. They've been (rightfully) panned for implementing their own crypto and doing it poorly. You should be using Signal on a phone if you're trying to use a secure messenger.


You should be using Signal on a phone if you're trying to use a secure messenger.

I am not trying to use a secure messenger. I am trying to use a good one without ratting on my friends to the worst (as in size x badness) company I am aware of. Ohh, and I don't want to be be part of their network effect either.)


All reasonable views, but I don't think that's a Telegram given their track record. At this point I'd put more trust in a transport-encrypted-without-end-to-end messenger than Telegram, and there are plenty of good options in that space (e.g. Discord, or hell, AIM). And if you want genuine security there are good decentralised options: XMPP (Conversations et al), Riot/Matrix, possibly Wire.


I'm not advocating for WhatsApp or PGP encrypted email, I'm pointing out that people who make the line in the sand at "decentralized vs centralized" are boiling the problem too far down.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: