{"id":49355,"date":"2025-09-24T14:53:23","date_gmt":"2025-09-24T18:53:23","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=49355"},"modified":"2025-09-24T14:53:23","modified_gmt":"2025-09-24T18:53:23","slug":"lawsuit-about-whatsapp-security","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2025\/09\/24\/lawsuit-about-whatsapp-security\/","title":{"rendered":"Lawsuit About WhatsApp Security"},"content":{"rendered":"<p><a href=\"https:\/\/www.schneier.com\/blog\/archives\/2025\/09\/lawsuit-about-whatsapp-security.html\">Bruce Schneier<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.schneier.com\/blog\/archives\/2025\/09\/lawsuit-about-whatsapp-security.html\">\n<p>Attaullah Baig, WhatsApp&rsquo;s former head of security, has filed a <a href=\"https:\/\/arstechnica.com\/security\/2025\/09\/former-whatsapp-security-boss-sues-meta-for-systemic-cybersecurity-failures\/\">whistleblower<\/a> lawsuit alleging that Facebook deliberately failed to fix a bunch of security flaws, in violation of its 2019 settlement agreement with the Federal Trade Commission.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/arstechnica.com\/security\/2025\/09\/former-whatsapp-security-boss-sues-meta-for-systemic-cybersecurity-failures\/\">Dan Goodin<\/a>:<\/p>\n<blockquote cite=\"https:\/\/arstechnica.com\/security\/2025\/09\/former-whatsapp-security-boss-sues-meta-for-systemic-cybersecurity-failures\/\"><p>The suit, filed in US District Court for the District of Northern California, recites a litany of purported security and privacy flaws that Meta not only didn&rsquo;t fix after becoming aware of them, but also kept secret, allegedly in violation of a <a href=\"https:\/\/arstechnica.com\/tech-policy\/2019\/07\/ftc-fines-facebook-5-billion-imposes-new-privacy-oversight\/\">$5 billion settlement<\/a> then-Whatsapp parent company Facebook reached with the Federal Trade Commission.<\/p><p>[&#8230;]<\/p><p>During a red-team exercise designed to find and exploit security vulnerabilities so they can be fixed, Baig said he found that roughly 1,500 engineers inside the messenger division had &ldquo;unrestricted access to user data, including personal information covered by the FTC Privacy Order, and could move or steal such data without detection or audit trail.&rdquo;<\/p><p>[&#8230;]<\/p><p>The letter further alleged Meta leaders were retaliating against him and that the central Meta security team had &ldquo;falsified security reports to cover up decisions not to remediate data exfiltration risks.&rdquo;<\/p><p>[&#8230;]<\/p><p>As a result, the former WhatsApp head estimated that pictures and names of some 400 million user profiles were improperly copied every day, often for use in account impersonation scams.<\/p><\/blockquote>\n<p>He says that Meta thought the fixes would hamper user growth. Meta says his claims are distorted and that he was dismissed for poor performance.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/09\/03\/whatsapp-and-instagram-for-ipad-finally\/\">WhatsApp and Instagram for iPad, Finally<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/12\/23\/whatsapp-v-nso-group\/\">WhatsApp v. NSO Group<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/05\/18\/ftc-says-facebook-violated-2020-consent-decree\/\">FTC Says Facebook Violated 2020 Consent Decree<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/10\/17\/whatsapp-more-private-than-imessage\/\">WhatsApp More Private Than iMessage<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/04\/15\/how-a-whatsapp-status-loophole-is-aiding-cyberstalkers\/\">How a WhatsApp Status Loophole Is Aiding Cyberstalkers<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Bruce Schneier: Attaullah Baig, WhatsApp&rsquo;s former head of security, has filed a whistleblower lawsuit alleging that Facebook deliberately failed to fix a bunch of security flaws, in violation of its 2019 settlement agreement with the Federal Trade Commission. Dan Goodin: The suit, filed in US District Court for the District of Northern California, recites a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2025-09-24T18:53:25Z","apple_news_api_id":"21fe733a-e636-43d1-9e27-6d6580d172e6","apple_news_api_modified_at":"2025-09-24T18:53:26Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/AIf5zOuY2Q9GeJ21lgNFy5g","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[25,1156,31,2586,26,41,209,2137,355,1363],"class_list":["post-49355","post","type-post","status-publish","format-standard","hentry","category-technology","tag-facebook","tag-federal-trade-commission-ftc","tag-ios","tag-ios-18","tag-iosapp","tag-lawsuit","tag-legal","tag-meta","tag-privacy","tag-whatsapp"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/49355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=49355"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/49355\/revisions"}],"predecessor-version":[{"id":49356,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/49355\/revisions\/49356"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=49355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=49355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=49355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}