Post #3245637
2026-05-25 03:39 UTC
Reply from @wabetainfo@mastodon.social :
Again, if they were actually doing something like that, people like you would notice it and make it widely known, just as you did originally.
Reply from @mysk@mastodon.social :
Sure, and you’ll hear about it from us when they do 😬
The facts are:
1) WhatsApp, FaceBook, and Instagram have a common group container that is used to share data between them locally on device (we won’t speculate as to what is being shared)
2) Adding WhatsApp group container entitlement to other Meta app, where it stores the chat database in plaintext, would be a trivial technical change on Meta’s part.
It would really go a long way if WhatsApp starts encrypting the chat database at rest as well. I think that’s all we can say right now
Reply from @wabetainfo@mastodon.social :
Encrypting the database certainly wouldn't be a bad thing either way 👍🏻 we will see how things evolve in the future.
Replies (1)
-
@menos@todon.eu 2026-05-25 07:40
@psylo@infosec.exchange Thanks for the background! What would encrypting the database achieve in this context though? For a completely different threat like cops snooping around on your phone, sure, that would be a good idea anyway. But as long as they can freely pass the encryption keys between their own apps, I don't see how that would help in this scenario. We know what kind of exploits they're willing to use (and how much malwareish behavior Google, and probably Apple, os wiling to tolerate from the likes of them) from their "deanonymize Facebook pixels via connections to localhost" stunt. @wabetainfo@mastodon.social @mysk@mastodon.social