Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

211–220 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#211

Earlier quoted context omitted.

Never heard "cult compound" in this context so far and by thinking about it I really think it better fits then "walled garden". "Walled garden" sounds like you go there because of its beauty or for getting the best crops while in reality you go there because it's the most crowded place.

> "Walled garden" sounds like you go there because of its beauty or for getting the best crops Which is exactly why people go to them. > while in reality you go there because it's the most crowded place. Directly true of social networks (where the "crop" is "people you can interact with through the network"), perhaps less directly true of some other walled gardens (though network effects are a thing.) But also direct…

> "But also directly opposite of what you'd expect from a "cult compound", which people go more to escape what is most popular, than to experience what is most popular."

Agreed, I thought of this point while sending my comment but wasn't sure how to put that in words. So maybe it's the "most crowded garden party".

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#212
post #170

Earlier quoted context omitted.

Reasons from @alexstamos (CSO @ Facebook): - FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it - Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc - Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routi…

Signal Protocol already supports multi-device. We've encouraged them to enable that for Secret Conversations. Voice/video etc are obviously straightforward; hopefully they'll continue to iterate towards support for e2e by default.

"Signal Protocol already supports multi-device"

This is what I thought. If one were starting a new messaging platform, how would you implement the Signal protocol from scratch I wonder? I'm assuming for people who don't have strong security backgrounds, this means dissecting the Signal source code from Github.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#213

Earlier quoted context omitted.

Never heard "cult compound" in this context so far and by thinking about it I really think it better fits then "walled garden". "Walled garden" sounds like you go there because of its beauty or for getting the best crops while in reality you go there because it's the most crowded place.

It's also one hell of a loaded term with things like Heavens Gate and Jim Jones having existed. To my knowledge, Facebook has yet to cause a mass suicide by people worshiping Zuckerberg.

Facebook has convinced millions of people to give up vast amounts of private information to an apparatus that would make the Stasi or KGB drool.

Part of cult indoctrination is giving up personal and private information, documents, secrets and property to participate and become part of the whole. Meanwhile, leaders profit from the property and information given up and use secrets to blackmail or breakdown an individual's identity so they become dependent on the group.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#214
I've been wondering about this for a while.

Now both whatsapp and Facebook have this, but surely they have the encryption keys too, or how else would they seamlessly fetch your messages and decrypt them when you get a new phone?

If they do, then what's the point?

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#215
post #214

I've been wondering about this for a while. Now both whatsapp and Facebook have this, but surely they have the encryption keys too, or how else would they seamlessly fetch your messages and decrypt them when you get a new phone? If they do, then what's the point?

I don't know about either anything factual, but I believe it was said that WhatsApp crux in the e2e is the iCloud backup. I believe that's where your old message get restored from.

I believe you can also disable that iCloud backup and thus the ability to retrieve those messages with a new phone.

End-to-End means encrypted in transport and not saved (in any form that is decryptable) on their servers. To that, I believe whatsapp fulfills their end of the bargain.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#216
post #214

I've been wondering about this for a while. Now both whatsapp and Facebook have this, but surely they have the encryption keys too, or how else would they seamlessly fetch your messages and decrypt them when you get a new phone? If they do, then what's the point?

[deleted]

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#217

Earlier quoted context omitted.

Reasons from @alexstamos (CSO @ Facebook): - FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it - Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc - Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routi…

> "We don't want to disrupt people's current experience." Hahaha. Sounded plausible until I saw that line. When did FB suddenly start caring about that?

Doesn't ring true after how they ripped all messaging functions out of the main Facebook app and forced me to download Messenger.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#218
post #198
post #161

Earlier quoted context omitted.

As moxie has stated elsehwere in the comments here, they have confirmed that Messenger is using their open-source libs and I am sure that other people will do a bit of disassembly on the on-device binaries to confirm this fact.

It makes no difference what moxie said or seen. Facebook may have an offshore account set up for moxie, they may simply be showing alternative source, they may have a rigged build system that builds from the patched source, etc. Seeing the source is the first necessary step to establishing any sort of real trust in a compiled binary. You are also gravely mistaken in thinking that other people will take apart the bina…

While I agree that we cannot simply take anyone at their word, your example of how the alternative could be pulled off is nothing short of Reynold's wrapped goodness.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#219
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

n excellent point, however I will add to your thinking that we want our government to be able to eavesdrop on conversation provided it's done constitutionally, with probably cause, in an open court and with a warrant. If we can't get those things then it's pointless to fight back with encryption. We must have our constitutional protections.

I'm sad I'm being downvoted. Our generation needs to learn it can't solve all of its problems with a screen in front of its face all of the time.

A lot of this technology is enslaving us. Piling it higher and deeper isn't the solution.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#220
post #72

Earlier quoted context omitted.

We've verified that FBM is using the unmodified open source Signal Protocol libraries we distribute at open whisper systems. Hopefully others will verify the same!

OK, I'll wait for independent verification, thanks!

I'd pretty much call the creator of the Signal protocol an independent verification. It's not like he's employed by Facebook.
Post reply on HN