Live data from Hacker News

Google backs off on previously announced Allo privacy feature

theverge.com

11–20 of 133 posts

Re: Google backs off on previously announced Allo privacy feature

#13
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

And that is exactly why open IM protocols and 3rd party clients are so important.

If both you and your correspondents do use 3rd party IM client ([1], [2], etc), then just run OTR2 or OMEMO on top of the protocol, and let google store whatever it pleases - it's not going to be much use for them.

[1] https://pidgin.im/

[2] https://conversations.im/

Re: Google backs off on previously announced Allo privacy feature

#14
post #5
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

So, not meaningfully encrypted at all then? One could also think of it as your private key being with (1) you, (2) Google. It's in safe hands ;-)

[deleted]

Re: Google backs off on previously announced Allo privacy feature

#15
post #3
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

Perhaps it's some kind of homeomorphic encryption scheme. Hey it technically leaves the original message encrypted!

Ifmeaningful homomorphic encryption was an option, then we'd be living in a quite different world.

Re: Google backs off on previously announced Allo privacy feature

#16
post #5
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

So, not meaningfully encrypted at all then? One could also think of it as your private key being with (1) you, (2) Google. It's in safe hands ;-)

ahem Perhaps not https://en.wikipedia.org/wiki/PRISM_(surveillance_program)

Re: Google backs off on previously announced Allo privacy feature

#19
post #3

Earlier quoted context omitted.

Perhaps it's some kind of homeomorphic encryption scheme. Hey it technically leaves the original message encrypted!

Ifmeaningful homomorphic encryption was an option, then we'd be living in a quite different world.

Very true. I was just making a tongue-in-cheek conjecture about the justification/rationalization that might be employed.

Re: Google backs off on previously announced Allo privacy feature

#20
post #5
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

So, not meaningfully encrypted at all then? One could also think of it as your private key being with (1) you, (2) Google. It's in safe hands ;-)

Sure, whatever safe hands mean. Safe in an NSA datacenter. Safe in the hands of the Chinese government. Safe with whatever sysadmin has access to it.

Instead of worrying about what "safe hands" mean, just keep it accessible only to me, and each respective conversation with the people I communicate with.

Post reply on HN