Here is a succinct summary of what is happening that you can send to all of your contacts:
The way I see it, a red line has been crossed today, and there's no coming back from it. Until now (if we believe their prior claims), sending a WhatsApp message generated keys for two people:
Nobody else could possibly decrypt the message.
From now on, if you enable this feature (opt-in for now), keys are generated for:
As explained in Meta's own whitepaper, the processing is done server-side. Meaning, messages are no longer E2E encrypted between your phone and the recipient's phone (which is the very definition of E2EE). They're now decrypted and read by WhatsApp servers to produce those summaries, much like a man-in-the-middle attack.
I don't think that can be considered end to end encryption any longer, but instead it sort of becomes encryption in transit... which is what every other app (e.g.: Telegram) or any other website (HTTPS) is already doing nowadays.
The urge was so strong, WhatsApp has finally killed E2EE in the name of AI.
The way I see it, a red line has been crossed today, and there's no coming back from it. Until now (if we believe their prior claims), sending a WhatsApp message generated keys for two people:
- You
- Me
Nobody else could possibly decrypt the message.
From now on, if you enable this feature (opt-in for now), keys are generated for:
- You
- Me
- Meta
As explained in Meta's own whitepaper, the processing is done server-side. Meaning, messages are no longer E2E encrypted between your phone and the recipient's phone (which is the very definition of E2EE). They're now decrypted and read by WhatsApp servers to produce those summaries, much like a man-in-the-middle attack.
I don't think that can be considered end to end encryption any longer, but instead it sort of becomes encryption in transit... which is what every other app (e.g.: Telegram) or any other website (HTTPS) is already doing nowadays.
The urge was so strong, WhatsApp has finally killed E2EE in the name of AI.