Can You Trust WhatsApp? Meta’s Encryption Lawsuit, Snowden’s Warning, and the Illusion of Privacy

Last Updated on January 30, 2026 by Rob Cashman

Can You Trust WhatsApp? A Short Answer

Short answer: WhatsApp claims to use end-to-end encryption based on the Signal Protocol, but that does not mean Meta cannot access metadata, influence key management, or undermine privacy at the app or server level.

A new lawsuit alleges WhatsApp users may have been misled about how private their chats truly are. While the case may fail on proof grounds, it raises a deeper issue: encryption alone does not equal privacy, especially when the app is closed-source and controlled by a data-driven company like Meta.

Bottom line:
You may be protected from casual interception — but you are not protected from Meta’s business model, implementation choices, or long-term surveillance incentives.

This distinction is what most users — and most headlines — miss.


Our Cashman Law Firm, PLLC’s clients have always been the victims of an all‑out assault on their privacy interests. From that perspective, I am briefly commenting on Cyber Kendra‘s “Your WhatsApp Chats May Not Be as Private as Meta Claims, New Lawsuit Alleges” article on a lawsuit which perhaps will reveal that Meta’s WhatsApp client does not truly provide end-to-end encryption to their users (and if they do, the lawsuit will try to show that WhatsApp users’ privacy still are not protected despite Meta claiming that they are ‘using the same encryption technology as the Signal app’).

a newspaper laying on the ground with whatsapp on it

Why This WhatsApp Lawsuit Matters

First of all, kudos to Cyber Kendra for writing this article. More people should be aware of the privacy issues that internet users face every day, whether that comes from using WhatsApp on one’s phone, browsing a website, viewing a video online on a YouTube-like site, or making use of “free” services like those offered by Google where you and your private information are what is being monetized and sold to other companies who wish to make use of that information (for legitimate or less legitimate purposes).

Now for my opinion, and this is not a detraction or a critique of the article — such an article should have been written a THOUSAND TIMES already, and I am saddened that this topic is not already mainstream knowledge. IT IS NOT.


Snowden’s 2013 Warning About Mass Surveillance

The wake-up call for society should have been in 2013, when Edward Snowden (a contractor working for the U.S. National Security Agency) leaked a large trove of classified documents. He demonstrated to the world that:

What Happened After Snowden (And What Didn’t)

To my personal disappointment, Edward Snowden’s revelations led us nowhere. Snowden fled to Russia (who granted him asylum, and then citizenship in 2022), and U.S. politicians on both sides continued to vilify Edward Snowden, those in power lied to the American people under oath (nobody was ever held accountable for their lies), and such programs only multiplied a thousandfold since.

When the Edward Snowden story unfolded, I was already 3 years into running our Cashman Law Firm, PLLC. We were already a year or so after hundreds of internet users were being sued in one lawsuit in NY Federal Courts by companies such as Digital Sin and other adult film companies, so I was surprised, but not surprised when the Edward Snowden story unfolded. I was, however, jaded by the way nothing of substance happened afterwards, “…and the news cycle moved on.”


WhatsApp, Signal, Telegram, and Threema: Do Any Chats Stay Private?

TL;DR: Signal is the most private messaging app by design, WhatsApp uses strong encryption but remains compromised by Meta’s data-driven business model, and Telegram offers powerful features but does not provide end-to-end encryption by default.

When the Edward Snowden story broke, everyone was already using WhatsApp, and I was already suggesting to friends and families that WhatsApp might have a problem with the way they were implementing their encryption protocols and there were privacy issues with their chats. I also used the Signal app, but it wasn’t developed and robust yet (I didn’t think it was a replacement for Telegram and WhatsApp when I played with it last, even a few months ago).

At the time, I even researched and then purchased the Threema app thinking it was the solution to everyone’s privacy problems… until I was the only one of my hundreds of peers and family members who used it. That was a lonely experience because I thought their app was better than all the others as far as privacy features, etc. But even today, nobody buys that app, and nobody uses it. (And to be specific, by ‘nobody’ I mean nobody I could convince. But, apparently Threema wanted it this way.)

After the Edward Snowden debacle, in 2013, I remember seeing an interview by Pavel Durov in the Guardian (the outlet who broke the Edward Snowden story), mentioning this new app which had privacy features that made WhatsApp seem to be no longer a choice to use. I switched to Telegram and convinced my family members to do the same, and for years, I refused to have WhatsApp even installed on any of my phones.

Signal vs WhatsApp vs Telegram — Which Is Most Private?

Short answer: Signal offers the strongest privacy protections by design. WhatsApp uses strong encryption but is weakened by Meta’s control and data practices. Telegram prioritizes features and scale over default encryption.

FeatureSignalWhatsAppTelegram
End-to-end encryption by default✅ Yes (all chats)✅ Yes (all chats)❌ No (only “Secret Chats”)
Open-source code✅ Yes❌ No⚠️ Partial
Uses Signal Protocol✅ Yes✅ Yes❌ No
Metadata collectionMinimalExtensiveModerate
Owned by data-driven company❌ No (nonprofit)✅ Yes (Meta)❌ No (private company)
Requires phone number✅ Yes✅ Yes⚠️ Optional / obscured
Independent audits✅ Regular❌ Limited❌ Limited
Best forMaximum privacyConvenience + reachLarge groups, broadcasting

Bottom Line

  • Signal is best if privacy and trust are your top priorities.
  • WhatsApp is convenient and encrypted, but Meta’s business model creates unavoidable privacy concerns.
  • Telegram is powerful and flexible, but not fully private by default, and should not be mistaken for an end-to-end encrypted messenger.

Encryption alone does not guarantee privacy — governance, transparency, and incentives matter just as much.


Meta’s Acquisition of WhatsApp and the Cambridge Analytica Lesson

In 2014, I remember seeing a report that Facebook (now Meta) acquired WhatsApp for ~21 Billion dollars. I watched an interview between Mark Zuckerberg and Jan Koum promising the world that WhatsApp would remain private, and that Facebook would not be allowed to invade on the privacy features that Jan Koum built into the WhatsApp app. “For 21 Billion dollars, Zuckerberg wants WhatsApp for a REASON. He’s not going to buy it because he’s a nice guy and he loves the app.”

I also had a good idea of what Nathan Myhrvold (the former CTO of Microsoft) was up to when he founded Intellectual Ventures, “the most hated company in tech,” and I knew that Facebook was already involved in patent troll-like dealings. (I wrote about it on my old blog in the “Facebook Huddles with Patent Vampire” article in 2009). So when Zuckerberg acquired WhatsApp, I knew Jan Koum’s promises would never last.

But then in 2018, The Guardian and The New York Times broke major investigative pieces disclosing that Cambridge Analytica retained and weaponized data on tens of millions of Facebook users for political profiling and targeting them for, among other reasons, influencing the 2016 U.S. election and other campaigns. I remember watching Facebook’s stock price drop as soon as that happened, but I was sad to say, I wasn’t surprised.

To be fair to Facebook (whom I villainized at the time, knowing what I knew about them) technically didn’t “sell” its users’ data to Cambridge Analytica; rather, they allowed a third-party app to ‘harvest data’ in compliance with their platform rules, and that data was passed on to Cambridge Analytica and used for political profiling, micro-targeting internet users, and other misuse of their data. But in 2019, the U.S. Federal Trade Commission announced a 5 billion dollar settlement with Facebook over the violations tied to this and other conduct, so my focus at the time went RIGHT BACK to their WhatsApp app and how it could be misused.

We are 13 years later after Edward Snowden, and we are almost ten years after learning that Facebook (now Meta) is simply NOT RELIABLE to be trusted with your chats, but people continue to use WhatsApp, and I have even caved and have it installed to monitor group chats relating to my community and various friends. But I still prefer Telegram (even though I think they are no longer as trustworthy or secure as they once were), and everyone tells me that Signal is still the most secure. I just don’t like their user interface (even though I will admit that it has advanced leaps and bounds since the first time I played with it).


End‑to‑End Encryption vs. App‑Level Backdoors

So back to Cyber Kendra’s article on WhatsApp.

There’s a lawsuit; I’m “surprised.”

WhatsApp may have a back door… are YOU surprised? I’m not.

Will they be able to prove it in the lawsuit? No.

WhatsApp is closed source, which means you cannot analyze the source code to determine whether Meta has built in tracking features or other data‑collection and surveillance mechanisms that effectively undo their claims that “WhatsApp still uses the same encryption as the Signal app.” That might be true, but even with true end-to-end encryption, Meta could have easily built in a back door to access all the chats (using the same protocol does not, by itself, preclude backdoors at the client / app level). Plus, public chats (even on Telegram) has less encryption protection, if not NO ENCRYPTION PROTECTION at all.

But I am sad to say… I can’t imagine that the plaintiffs can prevail here. I can’t imagine that they’ll be able to prove that WhatsApp has within it a ‘backdoor’ undermining any end-to-end encryption they claim is still on that app (in 2017, even Signal said there is no WhatsApp ‘backdoor’).

From a financial motivation perspective, I don’t see why WhatsApp would NOT undermine the privacy interests of their users; for all I know, I probably allowed them to do this explicitly in the Terms of Service (TOS) when I installed the app on my phone. I probably also gave them access to my Contacts List, and who knows what Meta is doing with all of the other data on my phone that it is pulling and sending home for whatever Meta is doing with my data. Meta (Facebook) and Zuckerberg are the owners of the app, and look at what we already know about what they’ve done.

As far as the actual worry — could WhatsApp actually have a backdoor? I would defer to Signal. If the protocol is implemented correctly, AND if users verify keys (do you?), then no, WhatsApp shouldn’t have any backdoor. But even Signal acknowledges that if an application implements key management improperly, a modified client (or a powerful server) could introduce backdoor‑like behavior without changing the Signal protocol itself.

So, here was my understanding when I looked into it:

  • The Signal Protocol is separate from the WhatsApp application, and it is a reliable cryptographic protocol.
  • WhatsApp has in the past made poor implementation choices (e.g., silent key changes and automatic re-encryption) which could have possibly created possible interception vectors.

When Meta states that “WhatsApp is using the same protocol as Signal,” that doesn’t guarantee the absence of backdoors or weaknesses at the client/app level, nor does it prevent a server from compromising the security of the app. Each of those factors is in Meta’s control; they are not weaknesses in the Signal protocol itself.

Personally, I’m not so worried about WhatsApp having a backdoor. I just don’t trust the software because I simply can’t know if they have done something with it. If WhatsApp were still in full control of Jan Koum, then I would trust it more.


Google Logins, Comment Systems, and the Erosion of Anonymity

Taking a step back (since this whole conversation is about what kind of privacy expectation does an internet user have when making use of an app), I am very sad at the state of privacy. I am jaded by what politicians have done to forsake the privacy of the citizens they were elected into power to protect. And any small step that appears to protect us, there are 100 others steps taken to hurt us, and nobody says a thing.

I’ll give you one example. To comment on Cyber Kendra’s privacy-focused article, you need to authenticate through Google — one of the largest data-harvesting companies on earth.

I haven’t used my Google account in years because I pay for my e-mail to be hosted by a company who encrypts it and keeps it private. But forcing me to log in to say anything conditions my participation in this discussion on me feeding my identity and behavior into Google’s surveillance infrastructure.

I know mainstream users haven’t yet internalized that Google is dangerous for the privacy interests of internet users, and the constant ‘tightening of the screws’ forcing us to declare our identity whenever we do something online, but things are getting pretty dark out there — private platforms have been making it practically impossible for a dissenting voice to participate in a conversation anonymously, and nobody is really doing anything to solve the problem. Add to this the worldwide problem where governments are trying to push internet users to link all of their activities, posts, and opinions to their real identity. There’s a big problem brewing, and it’s getting only worse.

Honestly, I don’t think this is unsolvable in theory; it’s just that the actors with the legal and economic power to change course are the ones profiting most from the current surveillance model. So the default keeps tightening: if you want to speak, watch, or read, you are quietly nudged into logging in “for your safety” and leaving another permanent trail.

And in defense of Cyber Kendra — I understand that the decision of website owners to outsource the discussion sections of their websites to Google is not really their “fault”; the economics almost force them to. But the effect of forcing an internet user to authenticate before sharing his opinion is that it causes independent voices to become dependent on an infrastructure that quietly demands more and more of our identity in exchange for speech.

Self‑hosted comments or privacy‑respecting platforms and WordPress plug‑ins exist, but they require more work and money than most small sites can spare, so the path of least resistance runs through Google and friends. In other words, even when site owners mean well, the infrastructure they depend on quietly shifts power away from individual users and toward large intermediaries who monetize identity and data.

Courts as Gatekeepers—and How They’ve Failed in Copyright Cases

The same pattern shows up in my own area: federal court litigation. Courts and judges should be the gatekeepers when lawmakers fail to protect citizens’ privacy and due‑process rights, but in practice they often become another part of the machinery that pressures ordinary people instead of protecting them. I’ve been defending against BitTorrent‑based copyright infringement lawsuits for 16 years now — making noise, speaking to judges, writing and speaking to lawmakers — and literally NOTHING has been done to fix this. WhatsApp will be no different, and this lawsuit will fail.

I *want* to be wrong here.


FAQs

Can WhatsApp really be trusted to keep messages private?

WhatsApp uses end-to-end encryption, but trust depends on more than cryptography. Because WhatsApp is closed-source and owned by Meta, users cannot independently verify how encryption is implemented, how keys are managed, or what data is collected outside message content. Encryption does not prevent surveillance through metadata, backups, or app-level design choices.

Does WhatsApp actually use the same encryption as Signal?

WhatsApp uses the Signal Protocol, which is widely respected. However, using the same protocol does not guarantee the same level of privacy. Signal is open-source and independently audited, while WhatsApp is not. Differences in implementation, key management, and server control can materially affect user privacy even when the underlying protocol is identical.

Is there a WhatsApp backdoor?

There is no publicly proven backdoor in WhatsApp’s encryption. That said, a lack of proof is not proof of absence. Because WhatsApp’s source code is closed, users must rely on Meta’s assurances, or discovery in the lawsuit. App-level backdoors, silent key changes, or server-side manipulation could theoretically undermine privacy without breaking the encryption protocol itself.

What is the WhatsApp encryption lawsuit about?

The lawsuit alleges that WhatsApp users were misled about the level of privacy provided by the app. Specifically, it questions whether Meta’s representations about end-to-end encryption accurately reflect how WhatsApp operates in practice. Even if the lawsuit fails, it highlights unresolved concerns about transparency and trust.

What did Edward Snowden warn about that relates to WhatsApp?

Edward Snowden warned that mass surveillance often operates through cooperation with or pressure on large technology companies, not just through broken encryption. His disclosures showed that metadata collection, infrastructure access, and secret legal processes can defeat privacy even when strong encryption exists.

Can Meta read WhatsApp messages?

Meta claims it cannot read encrypted message content. However, Meta does collect extensive metadata and controls the app, servers, and update mechanisms. Privacy risks do not require reading message text — behavior, relationships, timing, and social graphs can be equally revealing.

Is WhatsApp as secure as Signal?

From a cryptographic standpoint, both rely on the Signal Protocol. From a trust standpoint, they are fundamentally different. Signal is nonprofit, open-source, and designed to minimize data collection. WhatsApp is owned by Meta, whose business model depends on data monetization.

Should I stop using WhatsApp?

That depends on your threat model. For everyday users, WhatsApp may be sufficient to prevent casual interception. For users concerned about surveillance, profiling, or long-term data aggregation, alternatives like Signal may offer stronger privacy guarantees.

Leave a Comment