last week security flaw finders at cryptowallet startup Zengo went public with ways to revive seemingly self-destructed View Once material.
https://zengo.com/whatsapps-view-once-privacy-issue/
Essentially, the API servers treated View Once messages as normal messages but with a flag on them saying: Please only show this once. A rogue app able to talk to those servers could just ignore that request.
Zengo used Meta's bug bounty program in August to report the security weakness to WhatsApp....
and heard nothing back - As a result of the disclosure, WhatsApp tweaked its code a few days later to make it harder to get around the View Once requirements, and at first it appeared to have worked
"While generally the fix was a good initial step in the right direction by Meta’s WhatsApp, it is still not enough," Zengo cofounder Tal Be'ery wrote in an explainer on Monday.
fundamental problem is that these supposedly evaporating messages are still being sent to platforms that shouldn't be getting them
¯\(°_o)/¯
i wouldn't trust any service that claims self destruct msgs will actually self destruct and be gone forever from everywhere..... Especially not Meta 😂