Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

171–180 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#172
post #62

Reasons from not enabling it by default by @alexstamos (CSO @ Facebook): - FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it - Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc - Hundreds of millions use Messenger from a web browser. No secure way to verify co…

Signal Protocol already supports multi-device. We've encouraged them to enable that for Secret Conversations, and hopefully they'll continue to iterate towards support for e2e by default.

Signal protocol supports multi-device when the device is capable of storing the keys (like the Signal desktop app). His point about web browsers still stands I believe.

Although you could use local storage, you would have to do that with every browser you logged into and also somehow make it user-account-specific. I definitely see the challenges there for them.

What would you think about using a user's password to encrypt the browser keys and store them on Facebook's servers? Is that too large a compromise for usability?

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#174
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

It's like the entire world forgot about PRISM.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#175
post #21

Earlier quoted context omitted.

Hi. To move all messages to be E2E encrypted, we need credible solution for web clients and every other platform, including old feature phones. This is easier said than done, but is something we are thinking about. Secret Conversations is a step in the right direction.

I think people underestimate just how ludicrously hard it is to provide an encrypted experience that's as good as plaintext. Even showing a chat on multiple devices becomes a hard problem. I agree with you that it's a step in the right direction, and Viber and Whatsapp have a much easier problem to solve, given that both only support device-to-device messaging. The only app that supports multi-device chats that I kno…

I'm building one. When you start with the idea that it's going to be encrypted and that you won't know what users are sending back and forth you have to make some concessions but functionally I don't think the average person would even know that my application is encrypted from a UX perspective. You need to handle abuse client-side, it requires a bit more thought but I'm sure that's not beyond Facebook.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#176
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

It's like the entire world forgot about PRISM.

Because the whole story was bs? Zuckerberg himself commented on that https://www.facebook.com/zuck/posts/10100828955847631

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#177
post #96
post #80

Earlier quoted context omitted.

What is the difference between compromising a web server that serves js library vs the one that serves device-native app binary? This always s gets brought up when discussing in-browser crypto and could never get a satisfactory answer.

Because the binary is served from a marketplace that works with an app that you trust and that will verify the package signature. Or, the web browser does not behave like a package manager.

So it would need a browser plug-in instead of just a web page? That seems fair enough. Extra kudos if they manage to use a standard plug-in for several websites. Maybe we can even get some kind of standard for this.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#178
post #162

Ill try Facebook messenger on emulated android without a google account. Not a chance that I share all my phone contacts and everything else in permissions, simply so I can talk privately with my friends that are stuck in Facebook.

Can't you use a phone-only google account which you otherwise don't use for anything else? I haven't used Android, but would you be able to use your real email account in K9, while using a dummy account for the device itself?

> Can't you use a phone-only google account which you otherwise don't use for anything else?

Yes, good point!

> I haven't used Android, but would you be able to use your real email account in K9, while using a dummy account for the device itself?

The problem is that would prevent me from utilizing my android's contact list when emailing. When someone texts me, I like to easily click the name and then click on that contact's email address, which routes me to K9.

But your suggested has md thinking that since newer androids support multi-users, I could setup a separate account on my android specifically for Facebook messenger.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#179
post #24
post #4

Earlier quoted context omitted.

They have taken exactly the same approach as Google with the Allo service. This is most probably done because people want to use Chat Bots and services and these do not work with E2E encryption. Well they could work but it would be dishonest branding as the messages would leak.

>> "Chat Bots and services and these do not work with E2E encryption" It might be true that FB adding E2E breaks existing bots, but it's false that it breaks that ability to use bots on FB.

It could work but as I said it would be dishonest. If a bot can read your messages then you have to trust a third party to not leak/store them. I believe that he goal of E2E encryption is to remove the need to trust somebody. (Of course you still have to trust FB that they do not backdoor or hinder the encryption but you do not have to trust the third parties)

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#180

Earlier quoted context omitted.

Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routing through mobile. I wouldn't use the web version if they had not disabled Jabber access... and then I could use OTR. This trend makes me very sad... IM networks are getting more centralized as ever. I don't feel thankful for this kind of development. End-to-end encryption should not be a feature of the serv…

Unfortunately your use case, while valid, is for a very small demographic. In general people want the guaranteed experience that locked in products give them. A lot of people like to sideline complain about that, but tech is no longer its own customer -- there are billions of users who have different preferences than us and they are a lot more lucrative.

People opted into several of these services before they were "locked in", many of whom never noticed the switch of XMPP backplanes in Facebook Messages and GTalk. Some of them haven't even seemed to notice the loss of a few technically minded friends from their messenger windows, changes in branding, and or even really changes in apps. The ambivalence is not a preference or a "want" for a locked in experience. There isn't even a preference for a type of experience: the general human thought process is "I want to talk to my friend Jim" never "I want to use [Facebook Messenger/Google Hangouts/SMS/smoke signals] to talk to my friend Jim".

I've seen people that ritualistically open certain apps to talk to certain friends and networks of friends, but have no idea what apps they are using beyond the background navigation needs of "the one with the fuzzy green icon on my last page" and "the blue one with the annoying notifications".

Locked in platforms are a consequence of network efforts, not a "preference" for some mystical "guaranteed experience": the experience and the platform don't matter if the social interactions aren't there.

The diaspora of communications platforms hasn't hit home to the average consumer yet, and it's currently background inconvenience that people are using five to ten different apps to communicate these days in some cases, but that doesn't mean average consumers are entirely ignorant of the situation either. (To some extent that's why OS-level notification systems have become so important to the average consumer; at least when you have a half-dozen messenging apps all the notifications arrive in the same place.)

Post reply on HN