this post was submitted on 21 Aug 2025
169 points (98.8% liked)

Privacy

41168 readers
1077 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

A Russian state-backed messenger application called Max, a rival to WhatsApp that critics say could be used to track users, must be pre-installed on all mobile phones and tablets bought in the country starting next month, the Russian government said on Thursday.

The decision to promote Max comes as Moscow, locked in a standoff with the west over Ukraine, is seeking greater control over the internet. The Kremlin said in a statement that Max, which will be integrated with government services, would be on a list of mandatory pre-installed apps on all “gadgets”, including mobile phones and tablets, sold in Russia from 1 September.

you are viewing a single comment's thread
view the rest of the comments
[–] Rose@lemmy.zip 0 points 3 days ago (2 children)

WhatsApp uses the Signal protocol for end-to-end encryption, so Meta only collects the metadata. Still enough to convict, but better than anything from Putin.

[–] quick_snail@feddit.nl 5 points 2 days ago (1 children)

Not when Meta works with NSO group to backdoor the app. Then they can read all your messages.

[–] Rose@lemmy.zip 2 points 2 days ago (1 children)

Has there been any evidence of that? Intercepting the traffic or disassembling the app would show some signs if true.

[–] quick_snail@feddit.nl 2 points 2 days ago (1 children)

Yeah dude, tons. Look at Citizen Lab's work. They did an very detailed exposé with Amnesty International too

[–] Rose@lemmy.zip 3 points 2 days ago (1 children)

A vulnerability allowing to exploit an app is not the same thing as a backdoor. Moreover, being able to gain full access to someone's device does not prove that an app's end-to-end encryption is faulty. The same kind of exploit most likely could be used to read messages from Signal and definitely other apps.

[–] quick_snail@feddit.nl 2 points 2 days ago* (last edited 2 days ago) (1 children)

That's my point. The e2ee is worthless marketing because they work with cybermercinary groups to ensure they have exploits to gain access to the device.

NSLs require backdoors. Meta is a US corporation. But, sure, you can pretend that these exploits aren't intentional. That's their plausible deniability.

[–] Rose@lemmy.zip 1 points 2 days ago* (last edited 2 days ago) (1 children)

Likewise, you can pretend to be sure it's a backdoor without any proof and then also believe there's more that's not been exposed. Signal is also US-based, by the way. What software do you trust not to have vulnerabilities that could be abused by the likes of NSO Group and why?

[–] quick_snail@feddit.nl 2 points 2 days ago* (last edited 2 days ago) (2 children)

SimpleX is probably best. Wire is much more practical for day to day, but the metadata in Wire might literally get you killed.

[–] Rose@lemmy.zip 1 points 2 days ago

Going by your logic though, what would stop a Five Eyes country like the UK from pressuring the developer of SimpleX into creating a backdoor? Besides, as discussed, even if it were bulletproof, it's improbable that the victim would have no other apps on their device, one of which could be exploited by the likes of NSO Group. The creators of Android and iOS are also obviously US-based, so your point would have to apply to them as well. From there, if someone remotely gains full access to the device, it won't matter if you use Signal, Telegram, WhatsApp, SimpleX, or that new Russian thing. However, having e2ee is still better than nothing in that it protects from other attack vectors, like the ISP analyzing the traffic and reporting to the government.

[–] Vendetta9076@sh.itjust.works 1 points 2 days ago (1 children)

Gonna have to explain that last part there chief. What's wire?

[–] Amaterasu@lemmy.world 3 points 3 days ago* (last edited 3 days ago)

Not sure why this got downvoted. Was there any real proofs that WhatsApp msgs can get decrypted and read by the central server?

Besides the AI shit that is optional. Not advocating for WhatsApp but we need to keep the conspiracy theory out of the equation.