Live data from Hacker News

Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

buzzfeednews.com

61–70 of 592 posts

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#61

If they don't do E2E, users will abandon Facebook for platforms that do support it (and already are). And they aren't doing this to commit crimes, but to prevent advertisements from targeting every conversation they've ever had.

Honest question: We all know FB won't give up their targeting data, but if it's done locally on-device and we have access to see & modify it, would you support it as a better business model?

I'm not going to answer this in regard to Facebook specifically, because I can't imagine a circumstance where I would be willing to use a Facebook product.

But since this idea has been brought up by a number of ad companies (Google, most notably), I can answer in the more general sense.

I would not support ad targeting done that way. It is a bit less objectionable, but it doesn't really address my objections to the entire practice.

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#62

Sometimes I can understand the willingness to reduce the privacy of self and others in order to ensure that the law is able to prosecute those involved in heinous crimes. Our current political environment though involved a president openly calling on foreign governments to investigate his political opponents. What is to stop them from going after the private communications of those same opponents in the name of targe…

"president openly calling on foreign governments to investigate his political opponents." We're just going to completely ignore the last administration spying on their political opponents?

Politifact seems to think that "Obama tapped Trump" thing was a myth [0]. Are you referring to a different thing that I'm not aware of?

[0] https://www.politifact.com/truth-o-meter/article/2017/mar/21...

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#64
post #34

"We are writing to request that Facebook does not proceed with its plan to implement end-to-end encryption across its messaging services without ensuring that there is no reduction to user safety." I don’t get it. How could end-to-end encryption reduce user safety?

This is the authoritarian argument that it makes everyone less safe if they're not allowed to spy on everyone.

It's even a poor version of that argument. The victims of whatever crimes this would allegedly prevent aren't necessarily users of the platform. In that type of scenario, the perpetrators are the users.

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#65

If they don't do E2E, users will abandon Facebook for platforms that do support it (and already are). And they aren't doing this to commit crimes, but to prevent advertisements from targeting every conversation they've ever had.

I wonder how many WhatsApp users are aware that their messages are encrypted end-to-end.

I also wonder how many users are aware of the imperfections in the end to end encryption in WhatsApp.

https://keybase.io/blog/chat-apps-softer-than-tofu

(I have no affiliation with Keybase, I just appreciate their very thorough and public analysis.)

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#67

> We are writing to request that Facebook does not proceed with its plan to implement end-to-end encryption across its messaging services without ensuring that there is no reduction to user safety. Oh, so you’re asking for more end-to-end encryption? > While the letter acknowledges that Facebook, which owns Facebook Messenger, WhatsApp, and Instagram, captures 99% of child exploitation and terrorism-related content t…

How can they know they capture 99% of such content given that WhatsApp is (if I understand correctly) encrypted fully end to end such that Facebook cannot access the messages passing through it?

Testing?

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#68

Earlier quoted context omitted.

Honest question: We all know FB won't give up their targeting data, but if it's done locally on-device and we have access to see & modify it, would you support it as a better business model?

Framing it in terms of business models and inevitability dodges the question of whether they should be doing it in the first place.

You mean, should free advertising-subsidized services even exist?

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#69
post #50

Detecting child abuse pictures is not incompatible with end-to-end encryption if the detection is done locally. Facebook (or other messenger app owners) could train a good classification model to detect child abuse pictures on large servers and provide the model to smartphones locally. Before sending pictures, the app would run the trained model (which is cheap computationally). If if detects pictures of abuse with a…

don't trust the client. How easy it would be for a motivated community to create a binary patch that skipped the local abuse checks?

If we're positing users clever enough to modify the client, then such users could also just modify the client to scramble all CP images so that they would not be detectable via fingerprinting and can only be descrambled by a patched client.

People sending CP through whatsapp/FBM are not clever. If they were clever, they wouldn't be doing that. The justice department is not primarily interested in catching clever criminals, at least not via this particular mechanism.

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#70
post #50

Detecting child abuse pictures is not incompatible with end-to-end encryption if the detection is done locally. Facebook (or other messenger app owners) could train a good classification model to detect child abuse pictures on large servers and provide the model to smartphones locally. Before sending pictures, the app would run the trained model (which is cheap computationally). If if detects pictures of abuse with a…

don't trust the client. How easy it would be for a motivated community to create a binary patch that skipped the local abuse checks?

There are ways to run trusted code on a client using remote enclaves (provided it is supported by the local CPU)

https://signal.org/blog/private-contact-discovery/

Post reply on HN