this post was submitted on 23 Oct 2023
76 points (89.6% liked)

Privacy

31982 readers
385 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

And if so, why exactly? It says it's end-to-end encrypted. The metadata isn't. But what is metadata and is it bad that it's not? Are there any other problematic things?

I think I have a few answers for these questions, but I was wondering if anyone else has good answers/explanations/links to share where I can inform myself more.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 36 points 1 year ago* (last edited 1 year ago) (17 children)

Metadata is all the content of a message besides the actual text content of the message (i.e. what you type). Examples would be the date and time it is sent, what users these messages were sent to / from, and the IP addresses of both parties. (The availability of metadata varies from messenger to messenger).

I like this example: If you only text your Aunt Sally, who lives in Alaska, twice per year to wish her a happy birthday and Christmas, just by looking at the metadata someone could infer the meaning of your messages, as well as your relationship to the person you're messaging. To a point this is true about any messages you sent.

As for Whatsapp specifically, it being end-to-end doesn't really matter imo, as the application is not open source and is owned by an advertising / social media company. As long as the code is closed source, you cannot be sure:

  1. That your messages are encrypted at all
  2. That your encryption keys are kept on-device, and not plainly available to a centralized party
  3. That the encryption the application is using is securely implemented

At least for applications handling truly sensitive information (for the average person only their messenger and browser), you should be using open source software. The easiest recommendations I can make are:

  1. Browsers: Firefox, Thorium, Brave (disabled all cryptocrap)
  2. Messengers: Signal, SimpleX Chat, XMPP

Anyways, I hope this was a satisfactory answer.

[–] [email protected] 1 points 1 year ago* (last edited 1 year ago) (2 children)

What use is this knowledge through metadata to them? Let's say I have no Facebook account and no other apps by Meta. There are no ads within WhatsApp. What do they gain by having this data about me?

[–] [email protected] 3 points 1 year ago

They know your relationships with other people, and could infer things about you which will be stored in their servers regardless of whether you have a Facebook account, I believe if you search for "shadow accounts" you can read more about that

[–] [email protected] 2 points 1 year ago

they can sell the information tied to your phone number or IP address to other companies, so they in turn now what ads to bombard you with.

load more comments (14 replies)