Earlier quoted context omitted.
It's a falsifiable assumption. Audit the binaries if you want to convince yourself. You will see code to generate and use keys locally, with no mechanism to fetch or share keys from a server. If you want to go beyond generic concerns, there are plenty of academic papers that have looked at Facebook Secret Conversations, found actual issues, and helped get them fixed: https://link.springer.com/article/10.1007/s00145-0…
Why are you so eager to trust an organization that has so often demonstrated it's not worthy of trust? This is Facebook , for pete's sake. The same company that conducted psychological experiments with zero clinical/ethical oversight by manipulating its users' feeds to see if it could cause depression/anxiety (or the opposite). Facebook is evil and you should not trust them even a little bit.
Show HN: ZuccNet – Encrypted Facebook Messaging
41–43 of 43 posts
Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#42Earlier quoted context omitted.
> Whatever they say, they have the keys to decrypt it. This is a baseless assertion.
"When you report a secret conversation, recent messages from that conversation will be decrypted and sent securely from your device to our Help Team for review." So they either have the keys or a way to force the client to decrypt.
Re: Show HN: ZuccNet – Encrypted Facebook Messaging
#43Earlier quoted context omitted.
If you are trusting facebook in any matter, you are misunderstanding something. Whatever they say, they have the keys to decrypt it. It is like trusting the thief to guard your house. I dislike this "ZuccNet" as the real goal should be abandoning facebook ecosystem but I still think that anything for naive people is better than nothing, so thumbs up.
Your assertion is false. Please read the whitepaper. Facebook does not have the key to decrypt messages sent with Secret Conversations. It is generated on-device. You can confirm that using simple reverse engineering tools on, say, the Android APK. Yes, Facebook could subvert the binary by pushing an update. That is the risk you are accepting.