Live data from Hacker News

Facebook Scans What You Send Other People on Messenger App

bloomberg.com

121–130 of 192 posts

Re: Facebook Scans What You Send Other People on Messenger App

#121
post #93

So Facebook Messenger has the option of end-to-end encryption of chats when you use "Secret Conversations", which are encrypted using the Signal Protocol [0], [1] Is there any indication that FB doesn't scan the contents of these messages before encrypting them with your own key and sending them across the wire? [0]: https://www.facebook.com/help/messenger-app/1084673321594605... [1]: https://www.wired.com/2016/10/fa…

Have tested this myself with known bad links (ie malware, spam and piracy websites). None were blocked.

Steve Weis was involved in its development (previously PrivateCore, Google Security Engineer where he developed 2FA and the keyczar library) and jumped on the defense after it was initially announced. Earlier versions were reviewed externally by some pretty well-known cryptographers.

That being said, meta-data around use of E2E encryption in Messenger is still an issue since it's not enabled by default.

Re: Facebook Scans What You Send Other People on Messenger App

#122

"You can't watch your kids 24/7," reads one poster, which has a picture of Schumer, Zuckerberg, and a shirtless Anthony Wiener outside Facebook's New York offices. "BUT WE CAN." ... Schumer - who in 2016 railed that "a person's cellphone should not become a James Bond-like personal tracking device for a corporation to gather information" - has stayed relatively silent since Facebook's user data scandal with Cambridge…

I really wish I could find a source that has a picture of this one:

> "You can't watch your kids 24/7," reads one poster, which has a picture of Schumer, Zuckerberg, and a shirtless Anthony Wiener outside Facebook's New York offices. "BUT WE CAN."

Re: Facebook Scans What You Send Other People on Messenger App

#123
post #41
post #31

Earlier quoted context omitted.

stopping "Bad content" is a slippery slope, especially on a network, where most only talk to people they actually know and who are usually using real identities. Keep in mind it's private messaging we're talking about.

It's really not a dangerous slippery slope. If Facebook starts moderating messages too harshly, people will just move to another platform.

I heard the same thing about Facebook and Google invading privacy "people will just move to another platform if they start getting too creepy!".

Still waiting on that...

Re: Facebook Scans What You Send Other People on Messenger App

#124
post #39

Why is this newsworthy? Did people think Facebook somehow didn't have access to what was being sent across its own platform?

Well, we had this thing called phone companies. In the beginning, many places, the switchboard operator would listen in. Then switchboards became mechanical and the industry regulated as a utility. And while it was technically easy for phone companies to listen, it was illegal for them to do so. (and nsa built a closet so it could listen in illegally, and got caught, and faced no consequences beyond an astronomical budget increase, anyhow...).

In The US there seems the trend is if you transport it, you get to data mine it (as long as "it" is digital, and "you" isn't a post service or phone company - not sure about isps). While in Europe the GDPR states that we live in a digital world, detecting that someone made a thousand copies of your data is really hard; but we'll make sure everyone is responsible for helping keep your data safe. Like the mailman and the telephone company.

But yeah, I think a lot of people still assume that a company facilitating private conversations won't have as primary business model to spy on those conversations.

Re: Facebook Scans What You Send Other People on Messenger App

#125
post #122

"You can't watch your kids 24/7," reads one poster, which has a picture of Schumer, Zuckerberg, and a shirtless Anthony Wiener outside Facebook's New York offices. "BUT WE CAN." ... Schumer - who in 2016 railed that "a person's cellphone should not become a James Bond-like personal tracking device for a corporation to gather information" - has stayed relatively silent since Facebook's user data scandal with Cambridge…

I really wish I could find a source that has a picture of this one: > "You can't watch your kids 24/7," reads one poster, which has a picture of Schumer, Zuckerberg, and a shirtless Anthony Wiener outside Facebook's New York offices. "BUT WE CAN."

http://www.dailymail.co.uk/news/article-5573875/Street-artis...

Re: Facebook Scans What You Send Other People on Messenger App

#126

> "For example, on Messenger, when you send a photo, our automated systems scan it using photo matching technology to detect known child exploitation imagery or when you send a link, we scan it for malware or viruses," a Facebook Messenger spokeswoman said in a statement. "A Facebook Messenger spokeswoman" who wouldn't put her name to the statement? Ugh. Child porn is terrible, but very few people produce it or want…

> Child porn is terrible, but very few people produce it or want to look at it.

There are many jurisdictions were people who are legally underage engage in sexting etc. There's hardly any "universal standard". Never mind areas where "gay" sex illegal etc.

Re: Facebook Scans What You Send Other People on Messenger App

#127
post #87

Earlier quoted context omitted.

You're exactly right and I'm not sure why this is being downvoted. Apple can add additional keys to iMessage messages and thus view them in transit - they say this themselves in their own security white paper[0]. [0]: https://www.apple.com/business/docs/iOS_Security_Guide.pdf

> Apple can add additional keys to iMessage messages and thus view them in transit - they say this themselves in their own security white paper I just read the section on iMessage (from around page 49) and I can’t see where this is written. Can you point to the part where they say this?

Page 51:

> The private keys for both key pairs are saved in the device’s Keychain and the public keys are sent to Apple’s directory service (IDS), where they are associated with the user’s phone number or email address, along with the device’s APNs address.

Re: Facebook Scans What You Send Other People on Messenger App

#128
post #93

So Facebook Messenger has the option of end-to-end encryption of chats when you use "Secret Conversations", which are encrypted using the Signal Protocol [0], [1] Is there any indication that FB doesn't scan the contents of these messages before encrypting them with your own key and sending them across the wire? [0]: https://www.facebook.com/help/messenger-app/1084673321594605... [1]: https://www.wired.com/2016/10/fa…

Have tested this myself with known bad links (ie malware, spam and piracy websites). None were blocked. Steve Weis was involved in its development (previously PrivateCore, Google Security Engineer where he developed 2FA and the keyczar library) and jumped on the defense after it was initially announced. Earlier versions were reviewed externally by some pretty well-known cryptographers. That being said, meta-data arou…

Oh nice one. Did the links get blocked when Messenger was in “non-Secret” mode?

Re: Facebook Scans What You Send Other People on Messenger App

#130
post #128

Earlier quoted context omitted.

Have tested this myself with known bad links (ie malware, spam and piracy websites). None were blocked. Steve Weis was involved in its development (previously PrivateCore, Google Security Engineer where he developed 2FA and the keyczar library) and jumped on the defense after it was initially announced. Earlier versions were reviewed externally by some pretty well-known cryptographers. That being said, meta-data arou…

Oh nice one. Did the links get blocked when Messenger was in “non-Secret” mode?

Yep. Same with the Apple crash character bug from a few weeks ago. Also when linking .EXE's and .SCR's, I didn't see any hits on the server. Facebook blocks direct linking to executable files, and usually does a HEAD request against the web server - in this case I didn't see anything when sending via Secret.
Post reply on HN