# What a new lawsuit claims about WhatsApp’s end-to-end encryption | Proton

**URL:** https://discuss.privacyguides.net/t/what-a-new-lawsuit-claims-about-whatsapp-s-end-to-end-encryption-proton/35020
**Category:** General
**Tags:** article
**Created:** 2026-01-28T18:23:50Z
**Posts:** 46

## Post 1 by @Blackbird — 2026-01-28T18:23:50Z

> **[What a new lawsuit claims about WhatsApp’s end-to-end encryption | Proton](https://proton.me/blog/whatsapp-encryption-lawsuit)**
>
> A class-action lawsuit challenges WhatsApp’s end-to-end encryption claims. We break down the allegations, denials, and what’s actually known.

---

## Post 2 by @fria — 2026-01-28T18:28:19Z

> It’s important to distinguish between allegations and established facts. The complaint does not include technical evidence demonstrating a cryptographic backdoor or otherwise proving that WhatsApp’s encryption has been compromised. At this stage, the claims remain unproven.

That kinda kills it right there for me. Just claims with no evidence.

---

## Post 3 by @Blackbird — 2026-01-28T18:30:41Z

That’s definitely a clickbait title.

---

## Post 4 by @anon52807678 — 2026-01-28T18:37:12Z

Can’t create a backdoor just for yourself without it becoming a huge juicy target for everyone else. I call BS.

---

## Post 5 by @Blackbird — 2026-01-28T18:42:41Z

![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/f/9/f95713e636db3c3b5ee38015f70f2bc24d081bb5.png)

---

## Post 6 by @otterfoghornrainfall — 2026-01-28T19:10:56Z

What a confusing lawsuit. At one point it says

> As the whistleblowers here have explained

but there are no whistleblower testimonies or explanations offered. While I don’t trust Meta I see nothing presented to invalidate their claims of E2EE. Feels frivolous unless more evidence becomes available.

---

## Post 7 by @privacy.slouchy — 2026-01-28T19:18:09Z

There’s a [decent discussion](https://www.reddit.com/r/privacy/comments/1qo313s/lawsuit_claims_meta_can_see_whatsapp_chats_in) addressing this on r/privacy

From what I understand, Meta has gone to great length to articulate on the record that encryption has not been broken. The whistleblower alleges Meta does not need to break E2EE, as the messages can be accessed at rest. [This comment](https://reddit.com/comments/1qo313s/comment/o1yitdm?context=3) is pretty informative:

> [36. As the whistleblowers here have explained, WhatsApp and Meta store and have unlimited access to WhatsApp encrypted communications, and the process for Meta workers to obtain that access is quite simple. A worker need only send a “task” i.e., request via Meta’s internal system) to a Meta engineer with an explanation that they need access to WhatsApp messages or their job. The Meta engineering team will then grant access—often without any scrutiny at all—and the worker’s workstation will then have a new window or widget available that can pull up any WhatsApp user’s messages based on the user’s User ID number, which is unique to a user but identical across all Meta products.](https://storage.courtlistener.com/recap/gov.uscourts.cand.463150/gov.uscourts.cand.463150.1.0.pdf)
> 
> [37. Once the Meta worker has this access, they can read users’ messages by opening the widget; no separate decryption step is required. The WhatsApp messages appear in widgets commingled with widgets containing messages from unencrypted sources. Messages appear almost as soon as they are communicated—essentially, in real-time. Moreover, access is unlimited in temporal scope, with Meta workers able to access messages from the time users first activated their accounts, including those messages users believe they have deleted.](https://storage.courtlistener.com/recap/gov.uscourts.cand.463150/gov.uscourts.cand.463150.1.0.pdf)

---

## Post 8 by @anon52807678 — 2026-01-28T19:37:09Z

> Although Meta has kept the circle on its fraud small, it has not kept it small enough. It attempted to prevent dissemination of this information by heavily siloing workers in different groups and telling them to “stay in [their] lane” when and if they started to piece together the truth. As discussed below, Meta also actively misrepresented the facts about its access and storage when journalists came close to discovering the truth. Meta has also tried to prevent the truth from coming out by imposing onerous nondisclosure agreements on its workers, essentially threatening the full force of one of the world’s richest companies if any of these individuals dared reveal what goes on behind closed doors at the company. These efforts have now failed, but they worked for many, many years by obscuring the truth.

They need a literary agent more than they need an attorney, honestly

---

## Post 9 by @anon98749087 — 2026-01-28T20:15:33Z

Why is the burden of proof to prove that there is a backdoor? I’m not saying there is, but this is proprietary software from a highly untrustworthy company that regularly loses lawsuits for abusing user data? Why isn’t the burden of proof on Meta to prove there isn’t a backdoor? Of course they can’t prove that because it would require open sourcing their code in a way that allowed reproducible builds. It just rubs me the wrong way, this “there’s no proof" argument that is prevalent on this forum. It’s a massive double standard.

---

## Post 10 by @jonah — 2026-01-28T20:26:08Z

> [@anon98749087](#):
>
> It just rubs me the wrong way, this “there’s no proof" argument that is prevalent on this forum. It’s a massive double standard.

I’m not _super_ interested in this story, because the most likely answer is that WhatsApp is and has always been doing what I’ve said they’ve always been doing for years now lol

> [@If you could only choose between SMS and Whatsapp, what would you choose and why?](https://discuss.privacyguides.net/t/if-you-could-only-choose-between-sms-and-whatsapp-what-would-you-choose-and-why/14905/3):
>
> My spicy hot take is that I would use SMS. Some facts: Neither WhatsApp nor SMS protect metadata. WhatsApp’s flagging system [breaks](https://arstechnica.com/gadgets/2021/09/whatsapp-end-to-end-encrypted-messages-arent-that-private-after-all/) E2EE. This is especially relevant in group chats, because you have to trust every single member, which of course becomes more difficult the more there are. Because of this, WhatsApp employs about 1000 moderators whose job is to review messages. Do companies like Signal who make products which are actually secure do this? No. Additionally, my theory is: Metadata …

---

## Post 11 by @privacy.slouchy — 2026-01-28T20:29:13Z

> [@anon98749087](#):
>
> Why is the burden of proof to prove that there is a backdoor… Why isn’t the burden of proof on Meta to prove there isn’t a backdoor?

That’s just how US code of justice works. The plaintiff submits evidence of wrongdoing, the defendant attempts to dismiss those allegations. Innocent until proven guilty, even if the defendant is evil (often, especially)

---

## Post 12 by @anon98749087 — 2026-01-28T20:34:08Z

Yeah, but this isn’t a US court, this is a privacy forum.

When the mods are on here essentially defending Meta instead of asking Meta to prove they’re doing what they say they do, it makes me scratch my head.

---

## Post 13 by @anon52807678 — 2026-01-28T20:35:34Z

> [@anon98749087](#):
>
> Why isn’t the burden of proof on Meta to prove there isn’t a backdoor?

Because the party initiating the action must prove their claims? It would be insane to live in a world if the opposite were true.

---

## Post 14 by @privacy.slouchy — 2026-01-28T20:38:30Z

> [@anon98749087](#):
>
> this isn’t a US court

This thread is a discussion about a US lawsuit

And ‘innocent until proven guilty’ is everyday philosophy. Otherwise we could make arbitrary accusations on a whim. Believing an accusation because we ‘feel’ it’s just is immoral and unreasonable. Extraordinary claims demand extraordinary evidence

I look forward to seeing this whistlebower’s evidence; I have not yet found any

---

## Post 15 by @fria — 2026-01-28T20:40:15Z

> [@anon98749087](#):
>
> It just rubs me the wrong way, this “there’s no proof" argument that is prevalent on this forum. It’s a massive double standard.

You’re making the assumption that I don’t want meta to open source WhatsApp, of course I do that would be great. I think every messenger should be open source with reproducible builds so you can prove it’s not backdoored. I also think if you’re going to make claims that something is backdoored you should have evidence as well, both can be true. The attitude I see a lot more commonly is that everything made by a big tech company is automatically backdoored which I don’t think is a reasonable assumption. Closed source software can be analyzed still through the binary, security researchers are always analyzing these popular programs looking for vulnerabilities. I would think if WhatsApp wasn’t E2EE they would’ve found that out by now.

It’s worth noting that Signal actually [helped](https://signal.org/blog/whatsapp-complete/) WhatsApp implement their E2EE and [disagrees](https://signal.org/blog/there-is-no-whatsapp-backdoor/) that there’s a WhatsApp backdoor, although the blog posts are a bit old now.

---

## Post 16 by @anon98749087 — 2026-01-28T20:51:27Z

This _is not_ a court. There are no repercussions for Meta if people on this forum question their continuously shady data practices. Therefore it is not insane to use their terrible reputation and repeatedly terrible behavior to inform whether something might be likely or not. Repeat, this is a privacy forum, _not_ a US court. We do not need to uphold US burden of proof standards when discussing an issue on a _forum_. Continue to stan for Meta, and I’ll continue to scratch my head over why that’s happening on a privacy forum.

---

## Post 17 by @anon52807678 — 2026-01-28T20:58:23Z

> [@anon52807678](#):
>
> Meta has also tried to prevent the truth from coming out by imposing onerous nondisclosure agreements on its workers, essentially threatening the full force of one of the world’s richest companies if any of these individuals dared reveal what goes on behind closed doors at the company.

Are we to believe that no hostile intelligence agency made it worth their while, and that a bunch of nondisclosure agreements are all that’s holding this thing together? That’s why conspiracy theories are so hard to believe, even though some of them occasionally turn out to be true.

---

## Post 18 by @anon52807678 — 2026-01-28T21:07:00Z

> [@anon98749087](#):
>
> This _is not_ a court.

It’s a thread about a court _case_ with far reaching implications if the claims are true, Meta’s reputation notwithstanding. I can think these claims are fictional while continuing to hate on its products and avoiding them for other reasons. Most people here are no fans of them either. But everyone should be interested in the truth

---

## Post 19 by @anon51983832 — 2026-01-28T21:14:42Z

I think @fria has made it clear. Sometimes it might seem that maintaining a rational position implies supporting a demon like Meta, but I don’t believe that’s the case either. There’s no evidence yet, period. Going beyond that is mere irrational and conspiratorial speculation. And if evidence suddenly emerged tomorrow, I wouldn’t be surprised.

Personally, I find the position of the moderators commendable and exemplary. I don’t work in the technology world, so years ago I let myself be carried away by my ignorance and thought everything was “bugged.” But reading this forum and others equally or more technical, I realize that we must trust the evidence, as well as the technologies and technical methodologies.

Moreover, conspiracy theories lead to inaction. Following these chains of reasoning, one can end up deducing that any mobile device or computer is compromised (Pixel phones with GrapheneOS included).

---

## Post 20 by @anonymous544 — 2026-01-28T21:20:30Z

Theyre not stanning for Meta lol. Wanting evidence that there’s a backdoor does not mean they are defending Meta. It means they are demanding a _reason_ to believe that there’s a backdoor. Meta’s privacy-invasive history can of course be a reason to believe such a thing. It’s the reason why I and _pretty much everyone here_ does not use WhatsApp. But that reason is not enough to spread it around the internet as a _factual statement_, that there is “in fact” and without-a-doubt a (kleptographic) backdoor.

---

## Post 21 by @otterfoghornrainfall — 2026-01-28T21:22:05Z

> [@privacy.slouchy](#):
>
> The whistleblower alleges Meta does not need to break E2EE

Where do they allege this? I didn’t see anything akin to this while looking over the filing, albeit it I am at work and not able to give it a rigorous read right now.

I’m also not seeing how this:

> A worker need only send a “task” (i.e., request  
> via Meta’s internal system) to a Meta engineer with an explanation that they need access to  
> WhatsApp messages for their job

lines up with this:

> Meta has kept the circle on its fraud small

The first claim makes it sound widely accessible to staff and engineers, while the other claims aggressive obfuscation.

I’m interested in the claims made, but until the case goes to discovery or the whistleblower releases information, there is very little here. 4 paragraphs of vague claims in a 50 page filing is just not enough. I don’t use Meta products because I have no trust in them, but I don’t want to rely on confirmation bias like I see all throughout that reddit thread you linked.

---

## Post 22 by @anon98749087 — 2026-01-28T21:23:10Z

Y’all are missing the point. Prove to me there is no backdoor? You can’t? That is then a double standard.

---

## Post 23 by @anonymous544 — 2026-01-28T21:25:35Z

Who is the other party in the double standard? I’m looking through the post history here and I don’t see any you bring up.

---

## Post 24 by @anon42475305 — 2026-01-28T21:28:33Z

> [@anon98749087](#):
>
> Why is the burden of proof to prove that there is a backdoor? I’m not saying there is, but this is proprietary software from a highly untrustworthy company that regularly loses lawsuits for abusing user data? Why isn’t the burden of proof on Meta to prove there isn’t a backdoor? Of course they can’t prove that because it would require open sourcing their code in a way that allowed reproducible builds. It just rubs me the wrong way, this “there’s no proof" argument that is prevalent on this forum. It’s a massive double standard.

Because  
A) the evidence suggests there is no backdoor  
B) that is the claim being made, there is always a burden of proof when making a claim; otherwise, the claim is utterly meaningless.

If people would think critically for two seconds, they would realise that WhatsApp has a vested interest in E2EE because it saves them the massive PITA of being on the hook for moderating those messages. Using E2EE with poor metadata privacy gives Meta the absolute best of both worlds; they collect massive swaths of data to target advertisements without any liability for the messages sent on their platform.

There are also a lot of leaked and/or public police documents and court proceedings detailing how messages either have not been retrieved from Meta, have been retried via unencrypted iCloud/Google Drive backups, or have been obtained directly on the device. It is not reasonable to assume this is all a facade to give the impression that WhatsApp uses E2EE.

---

## Post 25 by @lyricism — 2026-01-28T21:49:14Z

You understand that courts don’t ask people to prove negatives not because of some exceptional standard they have specific to the court system but because doing so is logically incoherent in any context, right?

What can be asserted without evidence can be dismissed without evidence. If you make a claim, you have the burden of proof. This isn’t law, it’s simple logic.

---

## Post 26 by @otterfoghornrainfall — 2026-01-28T21:55:15Z

Speaking only for myself- I do not use WhatsApp because their claims are not proven, and I will not use it (except where forced) unless they prove those claims. But I also would need proof of the opposite to claim it as fact.

---

## Post 27 by @anon52807678 — 2026-01-28T22:10:59Z

> [@otterfoghornrainfall](#):
>
> The first claim makes it sound widely accessible to staff and engineers, while the other claims aggressive obfuscation.

It’s such a silly document it borders on being a skit.

Of the 50 or so pages, only about 200 words are a non-technical explanation of how this thing is intended to work, based on some anonymous whistleblower accounts. The rest is just a list of grievances, everything from Pegasus and Cambridge Analytica to the negative impact of Instagram on teenage mental health, and how Meta is always under fire for everything under the sun, so E2EE is obviously fake too

---

## Post 28 by @anonymous544 — 2026-01-28T22:11:15Z

> [@fria](#):
>
> That kinda kills it right there for me. Just claims with no evidence.

Personally i really wouldnt discount it just yet. It’s very recent, so new information is bound to come up. This is only a complaint, and complaints lay out the claims, not the evidence. I think pre-trial are where evidence is gathered and stuff. Maybe during this phase, subpoenas/requests for production can be served to obtain evidence of the claim, etc. But as of right now, it’s only a legal complaint where the plaintiffs are demanding a jury trial.

 ![{70B5C92A-6D8A-48A0-9C95-ABDB2A7C02CC}](https://forum-uploads.privacyguidesusercontent.com/original/3X/d/c/dc466bde3d4eed1fc963896dde2b028f2da8d037.png)

Edit: got some things wrong, but here is a description of the process/timeline for a civil case from a .gov website: [Civil Cases](https://www.uscourts.gov/about-federal-courts/types-cases/civil-cases)

---

## Post 29 by @win11.shading291 — 2026-01-28T22:25:20Z

I accuse you of murder. You can’t prove you didn’t kill anyone? Then you must be guilty.

This is the same line of arguments as ‘you have nothing to fear if you have nothing to hide’.

It’s not a double standard, it’s a fallacy.

There’s a reason why ‘innocent until proven guilty’ is a foundation of most modern society today.

---

## Post 31 by @lyricism — 2026-01-28T22:29:28Z

I do think there’s something to be said for 9 attorneys attaching their names to this. That would be a pretty large waste of money (even for a class action, the lawyers are spending their time on this instead of something else they could potentially be getting paid for) and risky for their legal licenses if they filed this despite knowing they had nothing behind it. However, that’s not evidence itself, it at best is an indicator that it might be worth keeping an eye on this for any evidence that does come from it.

---

## Post 32 by @privacy.slouchy — 2026-01-28T22:39:28Z

> [@lyricism](#):
>
> I do think there’s something to be said for 9 attorneys attaching their names to this

At this early stage, with the limited information provided, this is my main takeaway too: serious lawyers seem to back this case. The first firm listed (URQUHART & SULLIVAN, LLP) is a large law practice. They have nothing to gain & much reputation to lose by accepting a frivolous case that gets thrown out before trial

---

## Post 33 by @otterfoghornrainfall — 2026-01-28T22:39:30Z

> [@lyricism](#):
>
> lawyers are spending their time on this instead of something else they could potentially be getting paid for)

What makes you believe they are not being paid for this case unless they win?

---

## Post 34 by @anon0179693 — 2026-01-28T22:49:35Z

Yikes kinda divisive  
do wanna give a shoutout to some people who actually got me into speed without the article.

Honestly I can see the confusion with section 37, 38 and 39, impying some kind of backdoor action is happening  
sure their encryption itself may not be backdoored but some implication is there and honestly only one way to find out is around the end of the trial, because as others said, it is likely not the encryption itself (and we doubt it is as it seems the lawsuit implies using different means so we will see overall)

Safe to say that internally at WhatsApp things have been, oof, very loose lately, I think there was a similar situation before it and now this. But this kind of like “loose” actions is settng a dangerous precedent for whatsapp.

And this is exactly why I will never give in to apps like viber and whatsapp but that’s besides the point.

---

## Post 35 by @lyricism — 2026-01-29T01:13:47Z

That’s just how class actions work, at least usually.

---

## Post 36 by @otterfoghornrainfall — 2026-01-29T06:28:32Z

TIL. Thank you.

---

## Post 37 by @Blackbird — 2026-01-29T07:47:47Z

It’s a good thing this post didn’t get everyone riled up. :grinning_face_with_smiling_eyes:

---

## Post 38 by @anon0179693 — 2026-01-29T08:10:15Z

surprisingly yeah

---

## Post 43 by @beantaco — 2026-01-31T09:24:22Z

I get the sense @anon98749087 and the people here countering them are talking past each other.

My interpretation is

- @anon98749087
  - Is discussing trust, not legal burden of proof, and people have a right to choose to distrust a technology (WhatsApp in this case) without proof.
  - We in the privacy community have distrusted many other technologies because they are closed source, so why not also distrust WhatsApp?

- People countering @anon98749087
  - Are discussing legal burden of proof, and WhatsApp is not (yet) proven to have deceived everyone w.r.t. encryption.
  - Want to see evidence before spreading allegations that WhatsApp’s encryption provides no confidentiality, for instance, telling WhatsApp users that WhatsApp’s encryption is compromised.

Is the above correct or am I misinterpreting?

I would never use WhatsApp, at least not willingly, and I have told people WhatsApp is unsafe, saying that Meta is a surveillance company and WhatsApp is closed source, but will not (yet) tell others WhatsApp’s encryption is compromised.

---

## Post 44 by @Succotash91 — 2026-02-03T21:47:21Z

Isn’t the point of the lawsuit is to bring WhatsApp internals/tech details into public view? The lawsuit forces WhatsApp to prove its claims about E2EE, the next step is getting those out of the courtroom and onto GitHub and into newspapers.

---

## Post 45 by @me — 2026-04-10T15:54:41Z

There hasn’t been that major of an update as of yet, but there has been _some_ progress since `2/04/2026`. Here is a docket of the case from PaceMonitor:

> **[Dawson et al v. Meta Platforms, Inc. et al (3:26-cv-00751), California...](https://www.pacermonitor.com/public/case/62720541/Dawson_et_al_v_Meta_Platforms,_Inc_et_al)**
>
> Dawson et al v. Meta Platforms, Inc. et al (3:26-cv-00751), California Northern District Court, Filed: 01/23/2026

Some non-major but _relevant_ points in the legal timeline as of `4/10/2026`:

- **Friday, March 27, 2026**
  - Meta (defendant) files a motion to dismiss the case (#29). I unfortunately don’t have the PDF document because PacerMonitor requires a subscription, so I’m not aware of what arguments they’re making for the dismissal.
  - The plaintiffs must file a response to that motion (argue why the case should not be dismissed) by `4/10/2026` ( **which is today!!!** ).
  - The defendant must file a reply to that response (argue why the plaintiff’s response does not hold, but can’t make any new arguments outside of what was given in the original motion to dismiss) by `4/17/2026`.
  - The hearing will take place on `6/2/2026` to determine whether the motion to dismiss is granted or denied.

- **Monday, March 30, 2026**
  - Judge Lin—the judge to preside over the case—cancels the date of the hearing (“Pursuant to Judge Lin’s Standing Order for Civil Cases”, which can be found [here](https://cand.uscourts.gov/judges/rfl/lin-rita-f)) (#32). This does not mean the motion to dismiss has been granted or denied.
  - The current dates for the “Joint Case Management Statement” (`4/15/2026`) and “Initial Case Management Conference” (`4/22/2026`) are cancelled, and a new date will be given only after the motion to dismiss is resolved (#33).

- **Thursday, April 02, 2026**
  - Stipulation (#34): Both the plaintiff and defendant agree to extend the due dates for their response and reply, respectively. There is a PDF document associated with this stipulation, but again I do not have access to it so I’m not aware of the reasons they provide.

- **Friday, April 03, 2026**
  - Judge Lin grants the stipulation (#36).
  - New response due date: `4/24/2026`.
  - New reply due date: `5/15/2026`.

I’m not fully sure what “Joint Case Management Statement” and “Initial Case Management Conference” entails. It seems to be about setting a schedule for the case. Timelines and deadlines are given for hearings, trials, discovery of evidence, etc. Meta’s motion to dismiss basically halted these two things. No timeline for the case can be established until Meta’s motion to dismiss is resolved (#33).

Unfortunately, there is _currently_ no hearing date set for the motion. This means that the motion will remain unresolved, and no dates (like for discovery) can be set for the case management. I wonder how this will affect the overall evidence-gathering throughout the case. Hopefully someone in the field can weigh in on this. It would also be beneficial if someone could provide access to the PDF documents for the motion (#29) and stipulation (#34).

As of right now, no evidence has been obtained, so the claims of the plaintiffs still only amount to allegations. I urge others to keep an eye out on this case.

---

## Post 46 by @otterfoghornrainfall — 2026-04-10T18:12:06Z

Thanks for the update, I haven’t kept up on this and was wondering what’s been happening.
