Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

261–270 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#261
When it was still possible to use the Facebook chat via XMPP I used to use Pidgin as client, and chat securely using the Pidgin OTR plugin.

Message appeared in the Facebook page as "encrypted message".

I guess you hardly can get better than this.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#262

Earlier quoted context omitted.

> It looks as if PGP's days are numbered. This seems gratuitously hostile (and, even worse, is irrelevant). PGP is a very useful piece of software, and it does something completely different from Signal, and I'm glad both exist.

>> It looks as if PGP's days are numbered Comments like this are inevitable and represent Facebook's attempts to induce us to route all of our communications though its platform. For the quoted commenter, it's probably too late.

PGP has failed to provide "encryption for the masses".

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#263
post #157

Earlier quoted context omitted.

I replied above, but there are few communication tools with such a wide userbase that have forward-secrecy and similar strong E2E crypto built in and available. People die because of what they post to Facebook or what they send in Messenger, I know this for a fact. With E2E security locked to devices it means that in the few seconds it takes me to wipe my phone while someone is knocking on the door with a gun then th…

A totally satisfying explanation! I apologize, you had every right to invoke the risking of lives. However, I hope your hopefully hypothetical dissident who is saying the things that cause armed men to knock knows to avoid Facebook altogether (you know, that company predicated on watching the things that you do and turning that knowledge into actionable data in exchange for money). Failing to do that is indeed an exi…

As a former FB employee I can empathize with the desire to avoid the mass data trawling that is involved in using the product, but having seen things from the inside I also know that people working there really, honestly do have users best interests at heart. During my tenure I worked on the effort to create Tor hidden nodes so that people could use FB via secure channels and watched the E2E effort go from Alec's wild idea to an actual product ready to ship. There are risks in using any centralized service, but having also poured almost a decade of money and sweat into an actual secure service only to see it wither because most people really didn't care I have finally come around to the idea that the efforts which will have the most long-term impact are the ones that subvert a popular service into providing the sort of security and privacy from government agencies that we all hope to eventually see. At some point you have to decide who is a greater threat, and FB doesn't have an army and really does try to do their best to resist overly-broad efforts by LEOs to gain access to user data. I understand why you would have absolutely no reason to believe any of this, but those of us who spent a bit of time toiling away inside will still keep trying to fight the good fight to deliver what people really need even if we have to put it in a sometime unpleasant wrapper.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#264
post #120

I've read the whole thread and I'm surprised that nobody mentionned how easy it would be for Facebook to store the secret keys. Page 10 of the white paper mentions that there is a remote key stored on Facebook servers which can be used to decrypt the local key. If Facebook still is to be trusted, I don't see what's the deal here. I think that as soon as you put the words "end-to-end" encryption on a marketing materia…

You've read it wrong. The local key is encrypted with the remote key. It means if someone steals your phone, they still have to pass facebook's authentication (e.g. 2fa) before being able to read your messages.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#265
post #46

Earlier quoted context omitted.

Over here in the real world, Facebook does not need to worry about "[losing] customers to these other message apps that tout their encryption" because the latter are not even in the game. There are only a few messaging apps that matter, because the value of the app is in its network and who it can connect you to rather than some feature checklist for the HN crowd. Dropping secure E2E encryption into an app that is de…

If barely anyone uses it then how is it a game changer? Please update us in a few months with usage statistics.

I can't tell if you've deliberately misinterpreted evgen's comment or not. But this feature is being deployed to hundreds of millions of phones. Even if only 1% of people use this, that's millions more people using E2E secured communication. Hardly "barely anyone".

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#266
post #120

I've read the whole thread and I'm surprised that nobody mentionned how easy it would be for Facebook to store the secret keys. Page 10 of the white paper mentions that there is a remote key stored on Facebook servers which can be used to decrypt the local key. If Facebook still is to be trusted, I don't see what's the deal here. I think that as soon as you put the words "end-to-end" encryption on a marketing materia…

"End-to-end encryption without open-source has no value. "

Not quite.

It means nobody is going to be able to read your data other than:

A) A nefarious Facebook staffer who has hacked their internal systems

B) A government entity with a court order

It's a step up from no encryption

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#267

Earlier quoted context omitted.

You can totally run your own server for yourself and your friends: https://github.com/WhisperSystems/TextSecure-Server (you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy) What you won't be able to do is federate with the official servers. Oh, and there's also a WebSocket transport (used by the Desktop client) that doesn't involve Google. That just do…

> you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy I'm sorry, but is this a joke? "To not use a centralized server that you can neither audit nor trust, you have to recompile the client, but that's easy ?" This smacks of "oh, PGP for email is fiiiiiine." To say nothing of the silliness of the inability to federate.

Compiling the client is much less daunting than running your own server, so "easy" seems like a fair description in this context. I don't think there's a large intersection between "People who can't easily compile the client" and "People who would run or audit a secure messaging server."

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#268
post #263

Earlier quoted context omitted.

A totally satisfying explanation! I apologize, you had every right to invoke the risking of lives. However, I hope your hopefully hypothetical dissident who is saying the things that cause armed men to knock knows to avoid Facebook altogether (you know, that company predicated on watching the things that you do and turning that knowledge into actionable data in exchange for money). Failing to do that is indeed an exi…

As a former FB employee I can empathize with the desire to avoid the mass data trawling that is involved in using the product, but having seen things from the inside I also know that people working there really, honestly do have users best interests at heart. During my tenure I worked on the effort to create Tor hidden nodes so that people could use FB via secure channels and watched the E2E effort go from Alec's wil…

>As a former FB employee

Oh shit, sorry dude D:

>I understand why you would have absolutely no reason to believe any of this

Well, it's not really that. Most serious tech-folk have realistic conceptions of privacy issues (he said in a comment on HN, but whatever), and your response above shows that you likely do, too. The controlling suits, however, typically have different priorities. Thanks for your response!

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#269
post #204

Earlier quoted context omitted.

Yeah, so instead of being in Whisper Systems' walled garden, I can set up my own and ask people to install Rvense's Magical Messenger App. Sit there in my treehouse with a bucket on my head and a NO DUMMIES sign or something.

Seems like you want the advantages of both centralization and federation without any of the disadvantages.

Being able to set up your own server is not federation unless your users can communicate with users on other servers.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#270
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

You answered your own question. No, serious threats do not use Facebook Messenger. The reason it's limited deploy is technical (for now) not caging. Metadata is more important than content. They will always have the metadata.
Post reply on HN