Why does WhatsApp get so little grief from law enforcement?
Something has been bugging me ever since I readTexas AG sues Meta over claims that WhatsApp doesn’t provide end-to-end encryption by Dan Goodin.
If WhatsApp really is end-to-end encrypted, why is Meta so popular with governments when other, less widely used, encrypted apps are getting hassled so much?
There’s a whole Apple–FBI encryption dispute article on Wikipedia. So where is the corresponding controversy for WhatsApp—which is supposedly just as encrypted?
How do all of these facts make sense at the same time?
• As far as external researchers can tell, WhatsApp has end-to-end encryption.
• WhatsApp has more than 3 billion users, more than any of the other encrypted messengers
• Meta remains politically well-connected and influential even in countries where politicians have strong positions against end-to-end encryption.
It’s like, if Tom Bombadil in The Lord of the Rings is both good and powerful, thenwhy is his home forest so infested with evil creatures? Something doesn’t make sense here.
WhatsApp is the biggest mystery on the Internet, if you go by user count. It’s nearly universally used in many places where politicians and law enforcement have no affinity for end-to-end encryption. So where are all the “WhatsApp is enabling [bad people] by refusing access to messages about [significant event]” stories? If Meta was really offering unbreakable end-to-end to such a large user base—they claim more than three billion users—it seems to me that they would be catching hell. The sound of the dogs not barking here is starting to get to me. Maybe Meta lobbyists are so good at politics that they can somehow get governments to be fine with real end-to-end? But is anybody that good at politics?
A recent lawsuit claims that a Meta employee was able to see some WhatsApp message plaintext in an internal application. (More:US authorities reportedly investigate claims that Meta can read encrypted WhatsApp messages) That means one more inconvenient fact to explain. How does this work?
“A worker need only send a ‘task’ (i.e., request via Meta’s internal system) to a Meta engineer with an explanation that they need access to WhatsApp messages for their job,” the lawsuit claims. “The Meta engineering team will then grant access—often without any scrutiny at all—and the worker’s workstation will then have a new window or widget available that can pull up any WhatsApp user’s messages based on the user’s User ID number, which is unique to a user but identical across all Meta products.
And Adrian Găitan writes, in WhatsApp’s “End-to-End Encryption” Is the Biggest Lie in Tech History — And I Can Prove It Mathematically,
WhatsApp is the only major secure messaging app that provides law enforcement with near-real-time surveillance data. A pen register order — a legal instrument that captures the source and destination of communications — is fulfilled by WhatsApp every 15 minutes, automatically, in software. While you’re messaging someone, an agent with a pen register order receives a timestamped packet of metadata every quarter hour showing exactly who you’re communicating with. In near-real time.
Metadata access and the ability of governments to get access to devices and to cloud backups might explain a lot of how Meta can both offer end-to-end encryption and stay well-connected with governments. But those don’t provide all the access that governments want. (Did law enforcement agencies really do all the stuff inDark Wire and then say, well, gosh, we caught so many people doing crimes with relatively little investment, and it worked hella well, let’s just not do it again?)
But maybe it’s possible for the mystery of WhatsApp to make sense. What if their cryptography code is really end to end, no tricks, but the random number generator is somehow gimmicked to limit the number of possible keys? Not to thousands of possible keys like theDebian OpenSSL bug—that would be too easy to spot—but to some set of possible keys that is both
• large enough to look legitimately random and avoid two people ever getting the same private key, and
• small enough to search using computing resources available to Meta?
Meta could gimmick the RNG as a build and release step, so that as few people as possible have to know. Most developers with access to the WhatsApp source code could be kept ignorant of it, like AT&T was able to limit access toRoom 641A.
So for most purposes, for most people, WhatsApp can stay real end-to-end, but if there’s some user whose messages Meta really wants to read (on behalf of some government or just cuz whatevs) they can start a job on a cluster, get the necessary private key, and decrypt? And Meta keeps both security cred and political juice. These things don’t stay secret forever, but if there is an RNG flaw, when it comes out it’s just another oops-a-bug-our-bad-please-update story, and those scroll out of the news cycle’s context window quickly so they can come up with something else.
Bonus links
Trump administration reverses decision to scrap ocean monitoring system by Maya Yang. (You can’t do high-end sonar without temperature and salinity data. Just wait for however long it takes these things to get leaked or declassified—it will turn out that the US Navy was the key member of the range of stakeholders for this project.)
Meta’s CTO says morale is almost ‘the worst it’s ever been’ by Charles Rollet. (Fan theory: the low morale is part of the plan, because the real ML training project is a “leaker prediction AI” that will be the differentiating feature of Meta’s upcoming b2b cloud service. More:‘It’s literally the gulag’: inside the revolt at Meta’s AI unit, where elite engineers were drafted to label data by Alina Maria Stan)
Quote Origin: Punks Are Basically Nice People Pretending To Be Mean, Whereas Hippies Are Mean People Pretending To Be Nice on Quote Investigator
Ads Evading Pi-hole with iOS 27 by Adrian Sutton. (When the Pi-hole blackholes an ad domain the request fails, iOS decides the Wi-Fi must be flaky, and helpfully retries the same request over mobile data — where there’s no Pi-hole in the path. So the ad not only loads, it burns through my data allowance to do it.)
The Retweeting Class by Robin Berjon. (Read the whole thing. Now I have to think, am I collecting and sharing opinions in order to look respectable, or in order to change the situation?)
Open Source vs the Invisible Hand by Andrew Nesbitt. If you handed an economics undergraduate a description of how open source libraries are produced, without saying what it was, and asked them to predict the outcome, they would tell you it doesn’t add up. Non-excludable goods with no price, no contracts, no liability, a median producer headcount of one, and near-total free riding by consumers: there is no model in the textbook under which that arrangement produces anything stable. (What if the answer is something like: Bad IT creates slackful developers. Slackful developers create good IT. Good IT creates micromanaged developers. Micromanaged developers create bad IT?)
‘Agrivoltaics’ can both power AI data centres and increase food production — new study by Joshua M. Pearce. (It’s a good time to be a solar panel sales rep, just saying.)
Hugh Jackman plays Robin Hood as wicked – it’s a badly timed take on the hero of the poor by William Hoff. (Ayn Rand was famously against Robin Hood, and a lot of high finance types are Ayn Rand fans. Maybe this is the start of a trend, and a movie that depictsJ. H. Blair as a big hero is already funded.)