Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
The Courts Encryption Privacy

Whistle-Blower Sues Meta Over Claims of WhatsApp Security Flaws (nytimes.com) 8

The former head of security for WhatsApp filed a lawsuit on Monday accusing Meta of ignoring major security and privacy flaws that put billions of the messaging app's users at risk, the latest in a string of whistle-blower allegations against the social media giant. The New York Times: In the lawsuit filed in the U.S. District Court of the District of Northern California, Attaullah Baig claimed that thousands of WhatsApp and Meta employees could gain access to sensitive user data including profile pictures, location, group memberships and contact lists. Meta, which owns WhatsApp, also failed to adequately address the hacking of more than 100,000 accounts each day and rejected his proposals for security fixes, according to the lawsuit.

Mr. Baig tried to warn Meta's top leaders, including its chief executive, Mark Zuckerberg, that users were being harmed by the security weaknesses, according to the lawsuit. In response, his managers retaliated and fired him in February, he claims. Mr. Baig, who is represented by the whistle-blower organization Psst.org and the law firm Schonbrun, Seplow, Harris, Hoffman & Zeldes, argued in the suit that the actions violated a privacy settlement Meta reached with the Federal Trade Commission in 2019, as well as securities laws that require companies to disclose risks to shareholders.

This discussion has been archived. No new comments can be posted.

Whistle-Blower Sues Meta Over Claims of WhatsApp Security Flaws

Comments Filter:
  • by sinkskinkshrieks ( 6952954 ) on Monday September 08, 2025 @12:52PM (#65646564)
    In spite of its metadata-creating privacy violations. (And I worked for Meta for a bit.)
    • by jhoegl ( 638955 )
      Thats just it, isnt it? If there is no privacy, they have an out for why the data is out there.

      Meta claims security, but doesnt care to apply it.

      Bots all over, and no care for anything. Its almost as if they see their users as pawns.
      • There is no privacy, and privacy apps are only used by scammers and criminals anyway.

  • InfoSec Victims. (Score:4, Insightful)

    by Anonymous Coward on Monday September 08, 2025 @02:19PM (#65646830)

    While most might be wrapped up in the labels (Meta, WhatsApp, etc.), we shouldn’t overlook the core of the issue; an InfoSec professional was fired for merely wanting to do his job. Also known as the job he was hired to do.

    Without getting into detail, I know the fucking feeling. And we should probably be more focused on that than bullshit brands and labels that enable the kind of finger pointing that overlooks the core issue. If InfoSec professionals are going to continue to be targeted and/or become the fall guy/girl, then why in the FUCK would anyone get into the InfoSec profession?

    Good luck convincing some sucker to take that fucking job in the future. If you think you’re untouchable, remember Mudge was fired from Twitter for the exact same thing. Going in front of Congress on the issue didn’t do jack shit. And you ain’t no Mudge. Neither am I.

    • by ffkom ( 3519199 )

      While most might be wrapped up in the labels (Meta, WhatsApp, etc.), we shouldn’t overlook the core of the issue; an InfoSec professional was fired for merely wanting to do his job. Also known as the job he was hired to do.

      If he really thought that "InfoSec professionals are hired to improve security and protect privacy", then he was very, very naive. Company executives hire "InfoSec professionals" to tick off a box on their "cover your ass!"-list, such that they can get a "cyber-crime insurance" and have a scapegoat to point at when the security shit hits the fan. The last thing expected from an "InfoSec professional" is to burden the next quarter bottom line with any substantial cost/effort for implementing real, technical

  • Don't color me surprised, it's Meta.

Brain fried -- Core dumped

Working...