Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

201–210 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#201
A user complained that the title was misleading compared to https://newsroom.fb.com/news/2016/07/messenger-starts-testin..., so we replaced "deploys" with "begins testing" above. If someone suggests a better (i.e. more accurate and neutral) title, we can change it again.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#202
post #143
post #17

Earlier quoted context omitted.

> The same reason Gmail can't work with end-to-end encryption--they want to advertise at you based on message content. I wonder how they'd do if they were more open about it. "You're getting Gmail for free because we read your email and advertise to you. However, if you want to pay for a premium account (or Google Apps for Work) then we won't advertise to you, won't read your email and we'll even make end-to-end encr…

It would be a (financially) bad choice for corpo. And answer why, is the same in many similar questions 'why can't corpo do this-and-that'. Here it is (google as an example only, simplified) the answer: * Put two googles side by side. competing. * one is a current one, earning money from ads on you being product, and keeping it under the radar (although in fine print etc etc) * second is the one devised: premium acco…

[deleted]

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#203
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

[deleted]

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#204
post #186

Earlier quoted context omitted.

You can't run your own signal server. All accounts use phone numbers in the same namespace as ID, and all messages go from the phone to opensystems.org, further on to google, and from google to the destination phone (with lots of encryption being added and removed at various points). This has advantages (it's difficult for the Man distinguish a received signal message from other android notifications) but also disadv…

You can totally run your own server for yourself and your friends: https://github.com/WhisperSystems/TextSecure-Server (you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy) What you won't be able to do is federate with the official servers. Oh, and there's also a WebSocket transport (used by the Desktop client) that doesn't involve Google. That just do…

Yeah, so instead of being in Whisper Systems' walled garden, I can set up my own and ask people to install Rvense's Magical Messenger App. Sit there in my treehouse with a bucket on my head and a NO DUMMIES sign or something.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#205
post #165

Earlier quoted context omitted.

"Cult compound" is probably how I would describe it. Sure, you can leave, but there is immense social pressure to continue in what has become the norm, despite there clearly being something not okay with what is going on. And good luck convincing others to leave when you do.

Never heard "cult compound" in this context so far and by thinking about it I really think it better fits then "walled garden". "Walled garden" sounds like you go there because of its beauty or for getting the best crops while in reality you go there because it's the most crowded place.

It's also one hell of a loaded term with things like Heavens Gate and Jim Jones having existed. To my knowledge, Facebook has yet to cause a mass suicide by people worshiping Zuckerberg.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#207

Earlier quoted context omitted.

Reasons from @alexstamos (CSO @ Facebook): - FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it - Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc - Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routi…

Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routing through mobile. I wouldn't use the web version if they had not disabled Jabber access... and then I could use OTR. This trend makes me very sad... IM networks are getting more centralized as ever. I don't feel thankful for this kind of development. End-to-end encryption should not be a feature of the serv…

Enabling interoperable chat to non-nerdy friends is basically Matrix's raison d'être. We're not there yet (see https://matrix.org/blog/2016/07/04/the-matrix-summer-special... for the current status), but if we don't provide it we will have failed in the whole mission to defragment these silos, letting users choose which service to trust without losing interoperability.

The good news is that the Olm end-to-end cryptographic ratchet that Matrix is in the process of deploying (https://matrix.org/git/olm) is built using the same algorithms as Signal Protocol's ratchet (although it's an independent implementation) - so we're hopeful that at least technically the window is open in future for using Matrix to defragment all the services who have adopted Signal Protocol (WhatsApp, Google Allo, FB Messenger, Signal itself etc) without compromising the E2E privacy. Right now this is total sci-fi, and won't likely happen (whilst preserving E2E crypto) without cooperation from FB, Google etc.

However, we hope to get Matrix to the point where they see that the longer term benefits of participating in a healthy open ecosystem outweigh the short term benefits of trying to lock users into a silo - just as email eventually interoperated over the early internet. That's a while off, but this is still the goal.

The best way to make sure this happens is to play with Matrix in its current form, and help us write bridges (e.g. https://github.com/matrix-org/matrix-appservice-bridge/blob/...) to interface as many silos as possible into Matrix. The more bridges, the more useful Matrix is, and the higher the chance of building an ecosystem which eventually Google, FB and friends will find attractive.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#208
post #165

Earlier quoted context omitted.

"Cult compound" is probably how I would describe it. Sure, you can leave, but there is immense social pressure to continue in what has become the norm, despite there clearly being something not okay with what is going on. And good luck convincing others to leave when you do.

Never heard "cult compound" in this context so far and by thinking about it I really think it better fits then "walled garden". "Walled garden" sounds like you go there because of its beauty or for getting the best crops while in reality you go there because it's the most crowded place.

> "Walled garden" sounds like you go there because of its beauty or for getting the best crops

Which is exactly why people go to them.

> while in reality you go there because it's the most crowded place.

Directly true of social networks (where the "crop" is "people you can interact with through the network"), perhaps less directly true of some other walled gardens (though network effects are a thing.)

But also directly opposite of what you'd expect from a "cult compound", which people go more to escape what is most popular, than to experience what is most popular.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#209

Telegram needs you to opt in too, I though?

Kind of, but you can only "opt-in" by using so called "secure chats". From their FAQ at https://telegram.org/faq#q-so-how-do-you-encrypt-data:

"We support two layers of secure encryption. Server-client encryption is used in Cloud Chats (private and group chats), Secret Chats use an additional layer of client-client encryption."

It seems like many people (especially users/advocates of telegram) are confused by this, since telegrams marketing sounds like it's fully end-to-end encrypted.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#210
post #163
post #98

One thing I don't understand how Signal implemented by platform providers is supposed to work with lawful interception? Either it doesn't work, in which case we expect law enforcement to just give up the right to wiretap things with a warrant (which seems unlikely) or it does work and is less private than one would expect.

It does not support interception, and LEOs are going to have to learn to live with just metadata or use targetted attacks to compromise endpoints.

I find that very unlikely in the long run. As long as you there's a company to put pressure on it will happen sooner or later.
Post reply on HN