And if so, why exactly? It says it’s end-to-end encrypted. The metadata isn’t. But what is metadata and is it bad that it’s not? Are there any other problematic things?
I think I have a few answers for these questions, but I was wondering if anyone else has good answers/explanations/links to share where I can inform myself more.
In the iOS Appstore you can see which data they want to obtain.
The biggest problem is that it uploads your entire contact list and thus social network to Facebook. That alone tells them a lot about who you are, and crucially, also leaks this information about your friends (whether they use it or not).
With contacts disabled it’s a pain to use (last time I tried you couldn’t add people or see names, but you could still write to people after they contacted you if you didn’t mind them just showing up as a phone number).
It still collects metadata - who you text, when, from which WiFi - which reveals a lot. But if both you and your contact use it properly (backups disabled or e2e encrypted), your messaging content doesn’t get leaked by default. They could ship a malicious version and if someone reports your content it gets leaked, of course, but overall, still much better than e.g. telegram which collects all of the above data AND doesn’t have useful E2EE (you can enable it but few do, and the crypto is questionable).
WhatsApp Moderators Can Read Your Messages - https://gizmodo.com/whatsapp-moderators-can-read-your-messages-1847629241
…if someone reports them
but how can they read them when its encrypted?
Yes.