Earlier quoted context omitted.
In Australia its illegal to encrypt user data with out the ability to decrypt it. Do they offer this service in Australia? Yes. Then they have the keys.
Facebook isn't doing the encrypting. You are. You have the key on the phone.
Show HN: ZuccNet – Encrypted Facebook Messaging
31–40 of 43 posts
Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#32Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#33Earlier quoted context omitted.
Your speculation is not interesting to me. What is interesting to me are actual bugs and vulnerabilities that credible people have found and gotten fixed: https://link.springer.com/chapter/10.1007/978-3-319-63697-9_...
With respect, I don't think the other commenter is deferring to Facebook's abilities and openness to resolve bugs in the cryptographic process, but pointing out ways they can continue to act that align with open questions from their past. e.g. https://www.cnet.com/news/facebook-bug-has-camera-activated-... Where the question arises: was it a bug that the camera was on, or that it was revealed inadvertently? Hence the…
1) well.. their CEO is a scumbag.
2) not only the CEO is a scumbag, apparently there are plenty more where he came from (scumbagland??)of them in there: https://www.forbes.com/sites/davidphelan/2019/02/01/apple-bl...
That second point didn't "just" happen. It was organized. It was planned. It was tested. It was approved. It was rolled out. And I didn't read about 10-50-100 people quitting/getting fired after this fallout. So.. another day at work. This time they got busted. So with CA. So with experimenting on our psychology by manipulating order of showing posts (effectively cancelling out the chronological order).
PS: and right when I thought I would only post positive messages on HN from now one.. a FB post comes up..!! PS2: I guess FB is useful to some. I wish them the best!! (there is a positive note!)
Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#34Earlier quoted context omitted.
> Whatever they say, they have the keys to decrypt it. This is a baseless assertion.
In Australia its illegal to encrypt user data with out the ability to decrypt it. Do they offer this service in Australia? Yes. Then they have the keys.
[1]https://www.independent.co.uk/life-style/gadgets-and-tech/go...
Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#35Earlier quoted context omitted.
Your speculation is not interesting to me. What is interesting to me are actual bugs and vulnerabilities that credible people have found and gotten fixed: https://link.springer.com/chapter/10.1007/978-3-319-63697-9_...
With respect, I don't think the other commenter is deferring to Facebook's abilities and openness to resolve bugs in the cryptographic process, but pointing out ways they can continue to act that align with open questions from their past. e.g. https://www.cnet.com/news/facebook-bug-has-camera-activated-... Where the question arises: was it a bug that the camera was on, or that it was revealed inadvertently? Hence the…
If you think the contrary, then the evidence is in the client.
Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#36Earlier quoted context omitted.
If you are trusting facebook in any matter, you are misunderstanding something. Whatever they say, they have the keys to decrypt it. It is like trusting the thief to guard your house. I dislike this "ZuccNet" as the real goal should be abandoning facebook ecosystem but I still think that anything for naive people is better than nothing, so thumbs up.
Your assertion is false. Please read the whitepaper. Facebook does not have the key to decrypt messages sent with Secret Conversations. It is generated on-device. You can confirm that using simple reverse engineering tools on, say, the Android APK. Yes, Facebook could subvert the binary by pushing an update. That is the risk you are accepting.
That's exactly the kind of risk you should never accept when it comes to Facebook.
Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#37Facebook Messenger already has Secret Conversations, which is end-to-end encrypted mode based on the Signal protocol. Here's the technical whitepaper: https://about.fb.com/wp-content/uploads/2016/07/messenger-se... Here's some of the academic work on messaging franking that it has driven: https://eprint.iacr.org/2017/664.pdf Here's the instructions how to use it: https://www.facebook.com/help/messenger-app/1084673321…
> If you think a message you've received in a secret conversation goes against our Community Standards, you can report it. Learn more about what a secret conversation is. When you report a secret conversation, recent messages from that conversation will be decrypted and sent securely from your device to our Help Team for review. We won't tell the person you're talking to that you reported it.
Since Facebook's software is managing the keys, they have the ability to decrypt Secret Conversations. You have to trust Facebook not to snoop. Whereas w/ ZuccNet, the public keys can be exchanged via a separate channel from Facebook, thus rendering Facebook unable to snoop.
Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#38Earlier quoted context omitted.
With respect, I don't think the other commenter is deferring to Facebook's abilities and openness to resolve bugs in the cryptographic process, but pointing out ways they can continue to act that align with open questions from their past. e.g. https://www.cnet.com/news/facebook-bug-has-camera-activated-... Where the question arises: was it a bug that the camera was on, or that it was revealed inadvertently? Hence the…
The original statement I had disputed was "[Facebook has] the keys to decrypt [Secret Conversations messages]", which is false. If you think the contrary, then the evidence is in the client.
Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#39Earlier quoted context omitted.
If you are trusting facebook in any matter, you are misunderstanding something. Whatever they say, they have the keys to decrypt it. It is like trusting the thief to guard your house. I dislike this "ZuccNet" as the real goal should be abandoning facebook ecosystem but I still think that anything for naive people is better than nothing, so thumbs up.
> Whatever they say, they have the keys to decrypt it. This is a baseless assertion.
So they either have the keys or a way to force the client to decrypt.
Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#40Earlier quoted context omitted.
The original statement I had disputed was "[Facebook has] the keys to decrypt [Secret Conversations messages]", which is false. If you think the contrary, then the evidence is in the client.
I'm perfectly willing to accept that they don't have access to the keys. But that's not the only kind of security failure -- the "steel door in a wooden frame" sorts of issues. For example: can the app take screenshots of decrypted messages?
Without reproducible builds and a transparent codebase, we'll simply never know.