Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

111–120 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#111
post #17

Earlier quoted context omitted.

> Why doesn't FB just apply encryption on all messages? The same reason Gmail can't work with end-to-end encryption--they want to advertise at you based on message content. I highly doubt there is any government intervention in FB's business strategy, but there seems to be plenty of cooperation after the business decisions are made. (The same is largely true with Microsoft, Google, and yes, even Apple.) It's not real…

> The same reason Gmail can't work with end-to-end encryption--they want to advertise at you based on message content. I wonder how they'd do if they were more open about it. "You're getting Gmail for free because we read your email and advertise to you. However, if you want to pay for a premium account (or Google Apps for Work) then we won't advertise to you, won't read your email and we'll even make end-to-end encr…

My intuition is that this will either lead to people going to other providers who do the same but do not mention it or lead to people not caring.

I mean, a large number of people here do know that machines scan their email. In what manner do the majority act? That shows us the revealed preference.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#112
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

Given what modern science knows about mathematics and computer science, you cannot brute-force decrypt messages encrypted by Signal Protocol. Not millions, not hundreds, not tens, not even one.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#113
post #21

Earlier quoted context omitted.

Hi. To move all messages to be E2E encrypted, we need credible solution for web clients and every other platform, including old feature phones. This is easier said than done, but is something we are thinking about. Secret Conversations is a step in the right direction.

I think people underestimate just how ludicrously hard it is to provide an encrypted experience that's as good as plaintext. Even showing a chat on multiple devices becomes a hard problem. I agree with you that it's a step in the right direction, and Viber and Whatsapp have a much easier problem to solve, given that both only support device-to-device messaging. The only app that supports multi-device chats that I kno…

Signal handles sync between phone and desktop just fine.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#114
post #18
post #6

"End-To-End Encrypted ‘Secret Conversations’" in software that is ordinarily used to harvest electronic phone books and rummage through user photos, from a company that made its whole fortune trying to obliterate privacy as a part of human culture? It's going to be pretty high standards of proof to give this anything that resembles credibility.

I am confident Facebook will meet your high standards when it comes to E2E encryption for Messenger.

Thanks for doing this – it's very exciting news. I've avoided FB Messenger for years and now downloaded it today due to this.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#115
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

> Why doesn't FB just apply encryption on all messages? The same reason Gmail can't work with end-to-end encryption--they want to advertise at you based on message content. I highly doubt there is any government intervention in FB's business strategy, but there seems to be plenty of cooperation after the business decisions are made. (The same is largely true with Microsoft, Google, and yes, even Apple.) It's not real…

End to end means that your computer is the only one that can read your gmail email, because the key is stored on your computer and not in the cloud. The whole reason we all moved to webmail from pop3 is to have access to our mailboxes on any device. If you put the key in the cloud and make it decryptable by some user-known data (like a password), there's very little point in having the key - brute forcing a user's key becomes very simple. Also, any legitimate service provider is going to provide a backup way to "recover your password", which means they have a shortcut to decrypting your data. So you can have one or the other, not both. Either you have simple, easy access to your data from multiple devices, or you have secure end to end encryption.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#117
post #30

Earlier quoted context omitted.

ads is a by product. The aim of google is to build AI. For training AI, it needs access to all the data about you. Maybe, google has already succeeded and the singularity has already happened ;-)

A by product of what? 86% of their profits come from advertising[1]. If that's not the definition of an ad company then I don't know what is. [1] - http://adage.com/article/digital/google-q4-2015-earnings/302...

That is not the point. Money is just a mean. Read http://www.artificialbrains.com/google http://bigdata-madesimple.com/12-famous-quotes-on-artificial... http://mashable.com/2015/05/12/elon-musk-fears-larry-page/#1... http://www.pcmag.com/article2/0,2817,2460571,00.asp .

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#118
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

> Why doesn't FB just apply encryption on all messages? The same reason Gmail can't work with end-to-end encryption--they want to advertise at you based on message content. I highly doubt there is any government intervention in FB's business strategy, but there seems to be plenty of cooperation after the business decisions are made. (The same is largely true with Microsoft, Google, and yes, even Apple.) It's not real…

Want to give up on gmail search too ?

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#119

Earlier quoted context omitted.

Reasons from @alexstamos (CSO @ Facebook): - FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it - Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc - Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routi…

Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routing through mobile. I wouldn't use the web version if they had not disabled Jabber access... and then I could use OTR. This trend makes me very sad... IM networks are getting more centralized as ever. I don't feel thankful for this kind of development. End-to-end encryption should not be a feature of the serv…

I honestly find this centralization as worrying as mass surveillance itself. I'm as afraid of the Facebooks of this world as I am of any government, and I don't want all my communication locked in with one company.

This is why I will not use or recommend Signal. Moxie's anti-federation stance is unacceptable to me. It's replacing one problem with another.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#120
I've read the whole thread and I'm surprised that nobody mentionned how easy it would be for Facebook to store the secret keys.

Page 10 of the white paper mentions that there is a remote key stored on Facebook servers which can be used to decrypt the local key. If Facebook still is to be trusted, I don't see what's the deal here.

I think that as soon as you put the words "end-to-end" encryption on a marketing material, you have to be ready to open-source your client. This is the cost that companies aiming to be credible can't escape.

End-to-end encryption without open-source has no value. It is a waste of energy for the company doing that too - or perhaps a marketing cost.

Post reply on HN