Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

161–170 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#161
post #151

Is this some sort of elborate trolling? Can an exact match for a FB-provided binary be recreated from the open source code? If it's a No, then it's back to trusting FB to do the right thing and it doesn't make a slightest difference what exact protocol it's running or if the source was peer-reviewed behind closed doors.

As moxie has stated elsehwere in the comments here, they have confirmed that Messenger is using their open-source libs and I am sure that other people will do a bit of disassembly on the on-device binaries to confirm this fact.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#162

Ill try Facebook messenger on emulated android without a google account. Not a chance that I share all my phone contacts and everything else in permissions, simply so I can talk privately with my friends that are stuck in Facebook.

Can't you use a phone-only google account which you otherwise don't use for anything else? I haven't used Android, but would you be able to use your real email account in K9, while using a dummy account for the device itself?

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#163
post #98

One thing I don't understand how Signal implemented by platform providers is supposed to work with lawful interception? Either it doesn't work, in which case we expect law enforcement to just give up the right to wiretap things with a warrant (which seems unlikely) or it does work and is less private than one would expect.

It does not support interception, and LEOs are going to have to learn to live with just metadata or use targetted attacks to compromise endpoints.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#164

what's the difference between - Messenger - plain vanilla messages i get in Facebook web site - 'chat' messages, were I to turn on 'chat' in Facebook web site i'm not asking rhetorically. i honestly can't keep up with all the messaging avenues availabale today...

In theory they are the same, but with this recent release there is now a class of messages that are send device-to-device and cannot be viewed via the web interface.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#165
post #135

Earlier quoted context omitted.

> digital prisons Did you just coin that? It appropriately captures what is going on, but without having the positive connotation that comes from a 'walled garden'. I love the phrase. As an example outside of messaging, I have a fitbit and 'digital prison' so aptly describes what happens with my personal health data. I can't get my heart rate data out of their prison, because the fitbit warden doesn't see it fit to g…

"Walled garden" is more appropriate than "digital prison". No one is being sentenced involuntarily to these enclosures, they are voluntarily choosing to accept them because of what is inside them.

"Cult compound" is probably how I would describe it. Sure, you can leave, but there is immense social pressure to continue in what has become the norm, despite there clearly being something not okay with what is going on. And good luck convincing others to leave when you do.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#166
post #133
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

> I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? I worked for Facebook; I am friends with the people who developed this: I would like to reassure you strongly (well, as much as an Internet stranger can) on their motives. They are the good guys, and this was develop with people being spied on by abusive governments in mind — because…

I'm former FB Infra and agree with your first point re: motives. There's a lot of true believers working in the security space at Facebook, and I have tons of respect for them. I used to work closely with many of them.

However, scaling and/or capacity is not the reason E2E encryption isn't applied on all messages. The crypto operations are relatively trivial in terms of cpu.

This comment summarizes what FB's CSO said about why they are not launching E2E broadly yet. It boils down to usability concerns. Sounds like they are working on it:

https://news.ycombinator.com/item?id=12055567

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#167

Earlier quoted context omitted.

Reasons from @alexstamos (CSO @ Facebook): - FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it - Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc - Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routi…

Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routing through mobile. I wouldn't use the web version if they had not disabled Jabber access... and then I could use OTR. This trend makes me very sad... IM networks are getting more centralized as ever. I don't feel thankful for this kind of development. End-to-end encryption should not be a feature of the serv…

Unfortunately your use case, while valid, is for a very small demographic. In general people want the guaranteed experience that locked in products give them.

A lot of people like to sideline complain about that, but tech is no longer its own customer -- there are billions of users who have different preferences than us and they are a lot more lucrative.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#168
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

> Why doesn't FB just apply encryption on all messages? The same reason Gmail can't work with end-to-end encryption--they want to advertise at you based on message content. I highly doubt there is any government intervention in FB's business strategy, but there seems to be plenty of cooperation after the business decisions are made. (The same is largely true with Microsoft, Google, and yes, even Apple.) It's not real…

Text advertisements are cheap, bandwidth-wise. I wonder if they couldn't just send everybody dozens of advertisements, and decide on the client side what to show. Or even, download a dozens of MBs of graphical ads with each app update / the first time you visit the site.

You could go further and do something like, email sent by people to people is off-limits and will be end-to-end encrypted and not looked at - but (almost) all automatically generated email is fair game and will be processed. Google already does that with Google Now (and shows you your flights, package deliveries etc.). I really prefer them making more explicit what they look at and what not.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#169
post #21

Earlier quoted context omitted.

Hi. To move all messages to be E2E encrypted, we need credible solution for web clients and every other platform, including old feature phones. This is easier said than done, but is something we are thinking about. Secret Conversations is a step in the right direction.

I think people underestimate just how ludicrously hard it is to provide an encrypted experience that's as good as plaintext. Even showing a chat on multiple devices becomes a hard problem. I agree with you that it's a step in the right direction, and Viber and Whatsapp have a much easier problem to solve, given that both only support device-to-device messaging. The only app that supports multi-device chats that I kno…

http://Wire.com supports encrypted multi-device chats.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#170
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

Reasons from @alexstamos (CSO @ Facebook): - FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it - Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc - Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routi…

Signal Protocol already supports multi-device. We've encouraged them to enable that for Secret Conversations.

Voice/video etc are obviously straightforward; hopefully they'll continue to iterate towards support for e2e by default.

Post reply on HN