Live data from Hacker News

Show HN: ZuccNet – Encrypted Facebook Messaging

github.com

21–30 of 43 posts

Re: Show HN: ZuccNet – Encrypted Facebook Messaging

#21
post #12

I would still stay away from Facebook even with this. That platform is a data miner. Nothing more, nothing less.

And all these years I've been using it as a photo sharing site, trip planning site, event planning site, news aggregator, messenger, and about a dozen other things.

Data mining is the price you pay to have those things for free. I'll leave it up to individuals to decide whether or not it's worth the cost.

Re: Show HN: ZuccNet – Encrypted Facebook Messaging

#23
post #3

I bet Facebook gets a lot more value out of tracking you across services and locations than from the actual contents of your messages. This doesn't address it; if you're willing to go to these lengths, just switch to another platform that encrypts E2E.

True, if you can get your friend to care enough to install this exotic app, you can also get them to install the WhatsApp alternative of the day...

Re: Show HN: ZuccNet – Encrypted Facebook Messaging

#24
post #18
post #16

Earlier quoted context omitted.

This is whitepaper, it is not implementation of closed source application. Let me explain how this works in PR world. You publish (with all the bells and whistles) that you have end to end encryption and explain protocol that uses asymmetric cryptography (just for the sake of simplicity I will simplify - you have public and private key, you send public key to all chatters with you, they will encrypt randomly generate…

Your speculation is not interesting to me. What is interesting to me are actual bugs and vulnerabilities that credible people have found and gotten fixed: https://link.springer.com/chapter/10.1007/978-3-319-63697-9_...

With respect, I don't think the other commenter is deferring to Facebook's abilities and openness to resolve bugs in the cryptographic process, but pointing out ways they can continue to act that align with open questions from their past.

e.g. https://www.cnet.com/news/facebook-bug-has-camera-activated-...

Where the question arises: was it a bug that the camera was on, or that it was revealed inadvertently? Hence the discussion of trust in the client. That is an instance where Facebook lost some of that trust "in buckets".

It's true that "shit happens", but when it "happens" reptitively the questions begin to emerge. I don't think that's unfair. I mean, I'm sure few people would use a stock Ford Pinto as their regular driver, regardless of Ford's intentions or engineering capabilities.

Re: Show HN: ZuccNet – Encrypted Facebook Messaging

#26
post #17

Earlier quoted context omitted.

but it is a safe assumption

It's a falsifiable assumption. Audit the binaries if you want to convince yourself. You will see code to generate and use keys locally, with no mechanism to fetch or share keys from a server. If you want to go beyond generic concerns, there are plenty of academic papers that have looked at Facebook Secret Conversations, found actual issues, and helped get them fixed: https://link.springer.com/article/10.1007/s00145-0…

Why are you so eager to trust an organization that has so often demonstrated it's not worthy of trust?

This is Facebook, for pete's sake. The same company that conducted psychological experiments with zero clinical/ethical oversight by manipulating its users' feeds to see if it could cause depression/anxiety (or the opposite).

Facebook is evil and you should not trust them even a little bit.

Re: Show HN: ZuccNet – Encrypted Facebook Messaging

#28
post #5

Facebook Messenger already has Secret Conversations, which is end-to-end encrypted mode based on the Signal protocol. Here's the technical whitepaper: https://about.fb.com/wp-content/uploads/2016/07/messenger-se... Here's some of the academic work on messaging franking that it has driven: https://eprint.iacr.org/2017/664.pdf Here's the instructions how to use it: https://www.facebook.com/help/messenger-app/1084673321…

The metadata of our conversations is really more important than the content most of the time. Especially if FB is tracking the conversation participants before and after the chat.

If we chat and then shortly there after you search for some fringe political group, it's pretty safe to see that as a strong indication that I'm involved with that group. Or if my geolocation places me at some political event and we chat during or just after it, you're implicated.

FB doesn't need the contents of messages, they need the metadata plus all the other user tracking.

Re: Show HN: ZuccNet – Encrypted Facebook Messaging

#29
post #17

Earlier quoted context omitted.

but it is a safe assumption

It's a falsifiable assumption. Audit the binaries if you want to convince yourself. You will see code to generate and use keys locally, with no mechanism to fetch or share keys from a server. If you want to go beyond generic concerns, there are plenty of academic papers that have looked at Facebook Secret Conversations, found actual issues, and helped get them fixed: https://link.springer.com/article/10.1007/s00145-0…

The app can auto-update itself at any time and install some binaries that do share the key with the server; trust is virtue of every single thing the company (im this case FB) can do and auto-updates is one of them.

Re: Show HN: ZuccNet – Encrypted Facebook Messaging

#30
post #18
post #16

Earlier quoted context omitted.

This is whitepaper, it is not implementation of closed source application. Let me explain how this works in PR world. You publish (with all the bells and whistles) that you have end to end encryption and explain protocol that uses asymmetric cryptography (just for the sake of simplicity I will simplify - you have public and private key, you send public key to all chatters with you, they will encrypt randomly generate…

Your speculation is not interesting to me. What is interesting to me are actual bugs and vulnerabilities that credible people have found and gotten fixed: https://link.springer.com/chapter/10.1007/978-3-319-63697-9_...

[deleted]
Post reply on HN