Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

301–310 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#301
post #119

Earlier quoted context omitted.

Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routing through mobile. I wouldn't use the web version if they had not disabled Jabber access... and then I could use OTR. This trend makes me very sad... IM networks are getting more centralized as ever. I don't feel thankful for this kind of development. End-to-end encryption should not be a feature of the serv…

I honestly find this centralization as worrying as mass surveillance itself. I'm as afraid of the Facebooks of this world as I am of any government, and I don't want all my communication locked in with one company. This is why I will not use or recommend Signal. Moxie's anti-federation stance is unacceptable to me. It's replacing one problem with another.

I don't like this either. My long time wishes have been to have federated systems for instant messaging and for social networks. Neither seem to be getting any traction with the big and rich corporations actively working against any kind of interoperability. All the pro-privacy solutions depend on getting all your contacts into another walled garden, albeit a nicer one than the likes of Facebook and Google.

Beyond federation, I would also like the solutions to have good features and usability. Right now I'm bouncing between a few walled systems:

1. Telegram - really fast development pace, poor crypto, E2E encryption is only for chosen chats and single device.

2. Signal - slow to deliver messages, not multi-device and has usability bugs and issues. I update it somewhat regularly and try using it, but still go back to Telegram because basic expectations aren't met.

3. Wire - I discovered this recently and like the feature set (it's a lot richer than Signal). It claims to use the Signal protocol and has support for voice and video too. All chats are E2E encrypted (unlike Telegram where non-secret chats are by default not encrypted on the device or on Telegram's servers), and it has multi-device support with message sync (only from the time the device is joined to the account). Clients are available for different mobile and desktop platforms. But this one also has poor usability in getting started with it and has simple things missing - like no message delivered or message read indicators (the latter could at least be present as a user selectable option for privacy). I don't know how slow this is to deliver messages, but it's definitely not as fast as Telegram is. Not knowing if a message reached or not is unacceptable in this era.

I'm still waiting for some more strong solutions to appear in this space. Seeing that more platforms are adopting the Signal protocol, it would be great to have some standardization in user identification and federation. I actually do not want any of these solutions to be completely free and wish they would provide some way to help them monetarily (at least for the people who do want to help them). I feel repelled by the "free forever" and "we'll sell premium things later, like stickers" parts. That also brings suspicions about the motives of the company/developers and the future viability of the application or platform. At least allow people to donate to you so that you feel some kind of return obligation for all users!

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#302

Earlier quoted context omitted.

Reasons from @alexstamos (CSO @ Facebook): - FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it - Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc - Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routi…

Alex Stamos should check out https://wire.com (full disclosure: I work there) • E2EE by default, in groups too • Has solved the multi device, sync problem • Has webapp • Fingerprinting of all devices • Does not sacrifice features for security - voice, video, media • Crypto and comms protocols open source https://github.com/wireapp • Privacy and security whitepaper https://wire.com/privacy

I recently started using Wire and liked the richer feature set. But I'd say it still has some way to go on usability, features and speed. I hope you look at Telegram as an inspiration on those (not on crypto though, where you seem to have the one commonly accepted as the best).

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#303
post #12
post #3

From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…

While it might be disappointing, I firmly believe this is a technical and business decision, not a conspiracy. If you look at the features Messenger offers, and the direction the product has been moving, it relies heavily on server-side technology. Facebook have added contextual ride-share ordering, person-to-person payments, bots, etc. Unlike WhatsApp or Signal, Messenger also still works over the Web without an app…

> Unlike WhatsApp or Signal, Messenger also still works over the Web without an app or a smartphone-based login: how do you implement credible E2E over the Web, without using the phone as a crutch? How do you allow multi-device support, with a message history, and do E2E on all conversations?

Wire [1] does multi-device E2E encryption, sync of message history and allows users to use phone numbers and email addresses as identifiers. It also uses the Signal protocol.

Note: I do not work for Wire nor am I associated with it in any way, except as a user. I discovered it only recently and am trying it out, in addition to using Telegram as my most frequent client and Signal.

[1]: wire.com

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#304

Earlier quoted context omitted.

> you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy I'm sorry, but is this a joke? "To not use a centralized server that you can neither audit nor trust, you have to recompile the client, but that's easy ?" This smacks of "oh, PGP for email is fiiiiiine." To say nothing of the silliness of the inability to federate.

I didn't say this was a good way for normal users. Normal users don't care about federation and don't want to run their own server. But for people on HN it should be easy, and if you and your hacker friends don't trust moxie you can do it. I never said you should, just that's it's possible and not hard.

I don't think end users should have to trust him, either.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#305

Earlier quoted context omitted.

It's like the entire world forgot about PRISM.

Because the whole story was bs? Zuckerberg himself commented on that https://www.facebook.com/zuck/posts/10100828955847631

I agree. I hate how everyone trusted the Snowden story without question. It's pretty much US sponsored propaganda. I doubt Snowden is even in Russia.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#306
post #147
post #2

Last I heard, didn't their messenger app pull a ton of not required permissions on Android?

The Messenger app has Android M permissions model now. you can say no to all of the prompts if you want. I have all of Camera, Contacts, Location, Microphone, Phone, SMS, and Storage permissions disabled.

Except my phone does not have the update yet (note 3). I really need to root this sucker.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#307

Earlier quoted context omitted.

> What if he's scored as a threat and reported to the FBI? Then he'll be referred to a human, who may or may not understand sarcasm, jokes, or hyperbole?

'May not' seems likely, we are talking about the FBI after all ;)

[deleted]

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#308

Earlier quoted context omitted.

That is not the point. Money is just a mean. Read http://www.artificialbrains.com/google http://bigdata-madesimple.com/12-famous-quotes-on-artificial... http://mashable.com/2015/05/12/elon-musk-fears-larry-page/#1... http://www.pcmag.com/article2/0,2817,2460571,00.asp .

Because of people like you, I am able to strengthen my bullshit filter.

live in your own illusions

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#309

Earlier quoted context omitted.

That is not the point. Money is just a mean. Read http://www.artificialbrains.com/google http://bigdata-madesimple.com/12-famous-quotes-on-artificial... http://mashable.com/2015/05/12/elon-musk-fears-larry-page/#1... http://www.pcmag.com/article2/0,2817,2460571,00.asp .

Money is absolutely not a mean. Google is a public company. Money is its ultimate end.

There is a legal obligation to serve shareholders’ “best interests”. It is not exactly the same thing as either maximizing profits, or maximizing shareholder value. See http://www.nytimes.com/roomfordebate/2015/04/16/what-are-cor...

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#310
post #249
post #179

Earlier quoted context omitted.

It could work but as I said it would be dishonest. If a bot can read your messages then you have to trust a third party to not leak/store them. I believe that he goal of E2E encryption is to remove the need to trust somebody. (Of course you still have to trust FB that they do not backdoor or hinder the encryption but you do not have to trust the third parties)

With a chatbot you are chatting with the bot. All the bot needs to is be able to use the Signal E2E protocol to establish key & message exchanges. Nothing dishonest about this and nothing different than existing bots other than one uses E2E and one does not.

I do not speak of chatbots such as Cleverbot. For example your bot will listen to your messages and provide contextual information, such as theatres airing a movie you are currently talking about. The bot also probably needs to keep track of the context, which probably means keeping the chat history for some time. In order to learn the chatbot needs to keep the history forever and scan it for ML purposes. All of these mean that the bot has to keep the history somewhere unencrypted, basically nullifying the benefit of E2E.
Post reply on HN