Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

101–110 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#101
post #41

Earlier quoted context omitted.

In what way is it worse?

What if he's scored as a threat and reported to the FBI? A human can understand sarcasm, jokes, or hyperbole. An algorithm is going to see scary words and add them to the 'dangerous' score.

> What if he's scored as a threat and reported to the FBI?

Then he'll be referred to a human, who may or may not understand sarcasm, jokes, or hyperbole?

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#102
post #81
post #56

Earlier quoted context omitted.

The concern is less MITM and more a compromise of the server, but close enough. Check my parallel response to Omnipresent's comment.

Fair enough, whatever is the easiest for the attacker :). I'm checking Cyph and its "Trust On First Use" concept. Very interesting.

If you're dropping by defcon, you should catch the talk. There'll be very little focus on this mechanism specifically since we want to share a bunch of things people can actually freely use (and this isn't one of them), but you can catch Ryan afterwards and spark a conversation to find out more.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#103
post #40

Earlier quoted context omitted.

I made the comparison to Cyph for a reason. Every time Cyph comes up, there's some amount of lively debate about whether they've actually got working in-browser code signing (which they filed a patent on). I'd argue they do, but I'm also one of the guys who reviewed the implementation.

Even if they have been able to successfully get in-browser code signing working, how can they possibly gaurantee no leakage of data? I mean, there are so many inroads, from mitm to rogue browser plugins... It seems (near) impossible to secure them all.

Rogue browser plugins can be discounted as that's tantamount to a compromised device in the context of a downloaded E2EE app. MITM, well it's E2EE with trust-on-first-use for the crypto logic and implements the works when it comes to web security protocols, such as HPKP. There's enough mitigation there. TOFU in this context would mean once you visit once, the logic that's pinned in the browser then performs signature validation on crypto logic from then on.

No one's gonna get it perfectly right. Signal's probably the closest in terms of the cleanness of the protocol. It'd be neat to see Cyph implement the Signal Protocol in-browser as well, but that's neither here nor there. Ultimately, all of this will shift an attacker's focus away from owning the messaging application (or any component of it, be it the servers, the connection, etc.) to owning the devices and the users directly.

Your next technical battles will be in device security and user-friendly secure authentication. Your existing wars against your users (think phishing) will continue to heat up.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#104
post #78
post #61

It's worth remembering that this does not protect metadata. It's believed (though not known for sure) that WhatsApp logs metadata for their encrypted messages, and it looks like Facebook do the same here. If you want to resist mass surveillance this is not a good solution.

I'd argue that WhatsApp and FBM adopting signal have been some of the highest-impact movements toward resistance of mass surveillance, largely due to sheer numbers and accessibility. Sure, there is room for improvement, but having 0.000001% of t he population using an ultra-secure messenger doesn't have the same impact. And hopefully those improvements will happen in time.

The point is that metadata is more valuable for mass surveillance purposes than content. WhatsApp and FBM do nothing to protect metadata.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#105
post #46
post #5

Earlier quoted context omitted.

I think the more likely scenario is they know the value of the conversations they datamine, but don't want to lose customers to these other message apps that tout their encryption. So they do the bare minimum to support encryption while still having access to most data.

Over here in the real world, Facebook does not need to worry about "[losing] customers to these other message apps that tout their encryption" because the latter are not even in the game. There are only a few messaging apps that matter, because the value of the app is in its network and who it can connect you to rather than some feature checklist for the HN crowd. Dropping secure E2E encryption into an app that is de…

If barely anyone uses it then how is it a game changer? Please update us in a few months with usage statistics.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#106
post #83

Earlier quoted context omitted.

That's nice! :) What did the OP mean by "No secure way to verify code or store keys (in web browser) without routing through mobile" ?

There's no way for a site to securely store keys in the browser. The server can't put them there because then the server would have them too. A client-side script could generate them, but it can't store them without extensions (or the server via some JS it sends) also having access to them. This is why Signal and WhatsApp require the client to run on the phone - the phones are doing the decryption for the web apps. T…

Actually, Signal works without routing the messages trough your phone. Instead they use a browser extension to store the keys client side, which acts as a full client with its own, separate keypair.

You could even register only the browser, without having a smartphone at all.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#107
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

Reasons from @alexstamos (CSO @ Facebook): - FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it - Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc - Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routi…

    Hundreds of millions use Messenger from a web browser.
    No secure way to verify code or store keys without 
    routing through mobile.
I wouldn't use the web version if they had not disabled Jabber access... and then I could use OTR.

This trend makes me very sad... IM networks are getting more centralized as ever. I don't feel thankful for this kind of development. End-to-end encryption should not be a feature of the service provider, but the client. The way this works with Whatsapp/FB/Google just requires us to believe that their proprietary client is actually doing what it promises. And for me that I don't have a smartphone they just don't even promise anything.

I just wish I could use XMPP or Matrix with my non-nerdy friends. There was this time Google seemed to not be evil with GTalk/XMPP, but then... The business cynicism that dominates this industry, allowing people to claim that they "connect people" at the same time that they put everyone in digital prisons, makes me really want to leave computing and go live in a cave.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#108
post #14

This article doesn't mention it, but Facebook Messenger will be using the Signal protocol: https://whispersystems.org/blog/facebook-messenger/ also, here is the white paper (from the above post): https://fbnewsroomus.files.wordpress.com/2016/07/secret_conv...

I'm pretty sure (actually positively sure) the article mentions this.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#109
post #55
post #26

I'm really skeptical about this. First of all, Facebook collects more user data than just about any company out there. They make most of their money off of advertising and harvesting user data and metadata. Facebook is just about the last company I'd trust to encrypt data of mine. It's like them saying, "hey, I know we make most of our revenue off of collecting user data but I think we should throw away a huge portio…

It is opt in because there is a huge base of users who use Messenger via the web, and trying to do E2E in that environment is a fool's errand. If you had ever tried to deliver a crypto improvement to an actual shipping product I am sure you would know what sort of limitations one needs to operate within, but please feel free to continue risking other people's lives for the sake of feeling smug in your ignorant dismis…

Let me be clear, I believe this is a step in the right direction. However, I remain generally skeptical of Facebook because I do not agree with a lot of their practices.

I did not mean to be smug, I'm sorry if I came off that way. I understand what you are saying about E2E in the browser and I admit that your point is valid. I did not realize there was even a version of Messenger for the browser (I've only used the app version long ago).

Could you elaborate on how my comment risks the lives of others? I'm quite confused by that statement.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#110
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

Am I confused? Isn't it impossible to brute force a single properly encrypted message? (where properly means that the protocol and implementation are sound and so on)

This makes a lot of assumptions, like the NSA hasn't broken algorithms we consider secure, that they're not somehow sharing keys, or using a gimped algorithm on purpose, etc.
Post reply on HN