Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

31–40 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#31
I'm not immediately seeing any insight into whether this covers conversations initiated in-browser. If this does exist, it'd be interesting to see how they've tackled the security of crypto logic in-browser and compare it to what Cyph has in place for in-browser code signing.

Reading the technical docs now (https://fbnewsroomus.files.wordpress.com/2016/07/secret_conv...).

Edit: Yep, this seems device-to-device; there doesn't seem to be a web component here. Still useful given how many people use messenger primarily via phone, and I suspect implementation wasn't hard given WhatsApp did it first. It would be neat to see if Messenger and WhatsApp are ever bridged through this.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#33

Earlier quoted context omitted.

> Why doesn't FB just apply encryption on all messages? The same reason Gmail can't work with end-to-end encryption--they want to advertise at you based on message content. I highly doubt there is any government intervention in FB's business strategy, but there seems to be plenty of cooperation after the business decisions are made. (The same is largely true with Microsoft, Google, and yes, even Apple.) It's not real…

> (b) we've entered a new cultural era, where the levels of privacy enjoyed in the past are no longer socially normal. Yeah, that whole Bill of Rights thing just needs to go away, right?

My comment was descriptive, not normative.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#34
post #31

I'm not immediately seeing any insight into whether this covers conversations initiated in-browser. If this does exist, it'd be interesting to see how they've tackled the security of crypto logic in-browser and compare it to what Cyph has in place for in-browser code signing. Reading the technical docs now ( https://fbnewsroomus.files.wordpress.com/2016/07/secret_conv... ). Edit: Yep, this seems device-to-device; the…

Device to device. As you are aware, doing this in a browser in a manner that is not begging for failure is next to impossible.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#35
post #34
post #31

I'm not immediately seeing any insight into whether this covers conversations initiated in-browser. If this does exist, it'd be interesting to see how they've tackled the security of crypto logic in-browser and compare it to what Cyph has in place for in-browser code signing. Reading the technical docs now ( https://fbnewsroomus.files.wordpress.com/2016/07/secret_conv... ). Edit: Yep, this seems device-to-device; the…

Device to device. As you are aware, doing this in a browser in a manner that is not begging for failure is next to impossible.

Could you elaborate on why applying signal protocal in a browser is next to impossible?

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#36
post #28
post #17

Earlier quoted context omitted.

> The same reason Gmail can't work with end-to-end encryption--they want to advertise at you based on message content. I wonder how they'd do if they were more open about it. "You're getting Gmail for free because we read your email and advertise to you. However, if you want to pay for a premium account (or Google Apps for Work) then we won't advertise to you, won't read your email and we'll even make end-to-end encr…

The wording "we read your email" isn't quite accurate. There is nobody at google who goes through davb's emails one by one.

Yeah, worse, he's being scored by highly imperfect algorithms.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#37
post #21
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

Hi. To move all messages to be E2E encrypted, we need credible solution for web clients and every other platform, including old feature phones. This is easier said than done, but is something we are thinking about. Secret Conversations is a step in the right direction.

"feature phones" sounds like newspeak. Why are they called that? If anything I'd think they'd be called "lack-of-feature-phones".

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#38
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

Reasons from @alexstamos (CSO @ Facebook):

- FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it

- Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc

- Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routing through mobile.

"We don't want to disrupt people's current experience."

Source: https://twitter.com/alexstamos

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#39
As much as this is a step in the right direction, you have to specifically enable encryption for individual conversations in Messenger. This implementation seems a little sketchy to me. They really should just encrypt every conversation automatically. Otherwise, encryption only encourages scrutiny.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#40
post #34
post #31

I'm not immediately seeing any insight into whether this covers conversations initiated in-browser. If this does exist, it'd be interesting to see how they've tackled the security of crypto logic in-browser and compare it to what Cyph has in place for in-browser code signing. Reading the technical docs now ( https://fbnewsroomus.files.wordpress.com/2016/07/secret_conv... ). Edit: Yep, this seems device-to-device; the…

Device to device. As you are aware, doing this in a browser in a manner that is not begging for failure is next to impossible.

I made the comparison to Cyph for a reason. Every time Cyph comes up, there's some amount of lively debate about whether they've actually got working in-browser code signing (which they filed a patent on). I'd argue they do, but I'm also one of the guys who reviewed the implementation.
Post reply on HN