WhatsApp has been dragged into court with its biggest selling point in the dock.
A lawsuit in a San Francisco US district court claims the app’s end-to-end encryption is basically theatre, with users from Australia, Mexico and South Africa seeking damages.
Meta, which owns WhatsApp, has dismissed the case as “false and absurd.”
The complaint relies on unnamed “courageous whistleblowers” who allegedly describe an internal process in which staff can request access to a user’s messages by simply submitting a task request to an engineer.
The filing claims: “A worker need only send a ‘task’ (i.e., request via Meta’s internal system) to a Meta engineer with an explanation that they need access to WhatsApp messages for their job,” before adding: “The Meta engineering team will then grant access, often without any scrutiny at all and the worker’s workstation will then have a new window or widget available that can pull up any WhatsApp user’s messages based on the user’s User ID number, which is unique to a user but identical across all Meta products.”
It then goes for the throat with: “Once the Meta worker has this access, they can read users’ messages by opening the widget; no separate decryption step is required,” and claims the chats appear “essentially, in real-time” and that “access is unlimited in temporal scope”.
The problem is that the lawsuit, at least in the excerpted claims, does not lay out technical detail to prove how end-to-end encryption is bypassed, which is the sort of missing plumbing that tends to matter when you are accusing a security feature of being a marketing sticker.







