Live data from Hacker News

Chat Control is already live on Facebook Messenger

news.ycombinator.com

11–20 of 24 posts

Re: Chat Control is already live on Facebook Messenger

#11
post #8
post #6

Earlier quoted context omitted.

> First, Chat Control refers to a proposition in the EU, which has not been accepted at this point. So no, it's not Chat Control. The EU proposition of Chat Control is the proposition to make it mandatory. Facebook has already been performing it voluntarily (as I've discovered today). > The problem I see is that you disagree with how Meta handles Messenger, but still use it. Chat Control or not, there is no law preve…

> Meta isn't just some random company who's decisions don't have wide and far reaching societal effects. So what? There is no law saying that messages should always be e2ee, period. If you want such a law, you need to convince politicians to think about it. But that is orthogonal to Chat Control.

It is technically impossible for a large platform to implement E2EE without having a way to target one person to bypass it. True E2EE will always have to be a program external to the chat platform that handles keys out of band like OTR.

Legally it will never truly happen. Any platform saying they have E2EE is outright lying. Lavabit was an example of what happens when a large platform makes lawful intercept impossible. People keep telling me that Proton and Signal are E2EE and I will always offer them a tropical island for sale on the dark side of the moon, heavily discounted. Moxie of all people should know better.

Re: Chat Control is already live on Facebook Messenger

#12
I thought that Facebook Messenger was end-to-end encrypted for personal one-on-one chats? That's also the reason why Facebook asks you to set a PIN to retrieve your chats on other devices. Only group chats are not E2EE. So yes, this looks like a chat control-like feature where the scanning is done on the client and not on Facebook's servers.

Re: Chat Control is already live on Facebook Messenger

#13
post #10
post #7

Earlier quoted context omitted.

Didn't we go through this before with PGP-encrypted emails? 90+% of users are not technically competent enough to even understand, in the vaguest of terms, what you are saying. Even fewer have the time, ability and resources to do so.

Long ago this was an issue. Now with Thunderbird people can trivially PGP encrypt the body of their emails. With IRC this is done with OTR e.g. irssi-otr . I've manage to get lawyers and family members to use PGP so it can't be that hard.

Ask a teenager what a folder is. There's a good chance they'll not know what you are talking about. They can use apps and that's about it. Thunderbird? Good luck with that.

Re: Chat Control is already live on Facebook Messenger

#14
post #13
post #10

Earlier quoted context omitted.

Long ago this was an issue. Now with Thunderbird people can trivially PGP encrypt the body of their emails. With IRC this is done with OTR e.g. irssi-otr . I've manage to get lawyers and family members to use PGP so it can't be that hard.

Ask a teenager what a folder is. There's a good chance they'll not know what you are talking about. They can use apps and that's about it. Thunderbird? Good luck with that.

I hear you. It's about incentives. Any time a teenager can learn a method to get around content restrictions will will become a tool in their toolbox. They might reach for the Discord tool by default but when that is compromised such as recent events and governments start looking into all the DM's and voice-to-text transcripts they may reach for that old tool to prove they can not be censored or monitored. I would not expect teenagers to use it otherwise.

Re: Chat Control is already live on Facebook Messenger

#15
post #11
post #8

Earlier quoted context omitted.

> Meta isn't just some random company who's decisions don't have wide and far reaching societal effects. So what? There is no law saying that messages should always be e2ee, period. If you want such a law, you need to convince politicians to think about it. But that is orthogonal to Chat Control.

It is technically impossible for a large platform to implement E2EE without having a way to target one person to bypass it. True E2EE will always have to be a program external to the chat platform that handles keys out of band like OTR. Legally it will never truly happen. Any platform saying they have E2EE is outright lying. Lavabit was an example of what happens when a large platform makes lawful intercept impossibl…

> It is technically impossible for a large platform to implement E2EE without having a way to target one person to bypass it.

You'd have to explain what you mean here. If you mean that it's impossible to have encryption that is resistant to someone putting a gun on your face and asking for the password, then... well duh.

Re: Chat Control is already live on Facebook Messenger

#16
post #15
post #11

Earlier quoted context omitted.

It is technically impossible for a large platform to implement E2EE without having a way to target one person to bypass it. True E2EE will always have to be a program external to the chat platform that handles keys out of band like OTR. Legally it will never truly happen. Any platform saying they have E2EE is outright lying. Lavabit was an example of what happens when a large platform makes lawful intercept impossibl…

> It is technically impossible for a large platform to implement E2EE without having a way to target one person to bypass it. You'd have to explain what you mean here. If you mean that it's impossible to have encryption that is resistant to someone putting a gun on your face and asking for the password, then... well duh .

If someone or something else is managing keys for you, even the javascript in your client, then it can be altered by the server just for you. It's really just that simple. If you are creating and managing key trusts outside of the application then they can not tamper with them or add their own keys.

Re: Chat Control is already live on Facebook Messenger

#17
post #16
post #15

Earlier quoted context omitted.

> It is technically impossible for a large platform to implement E2EE without having a way to target one person to bypass it. You'd have to explain what you mean here. If you mean that it's impossible to have encryption that is resistant to someone putting a gun on your face and asking for the password, then... well duh .

If someone or something else is managing keys for you, even the javascript in your client, then it can be altered by the server just for you. It's really just that simple. If you are creating and managing key trusts outside of the application then they can not tamper with them or add their own keys.

I still don't understand what you are saying. You claim that Signal is not E2EE. Please explain.

Signal is an open source mobile app that I can audit and compile myself. How is it "obviously not E2EE"?

Re: Chat Control is already live on Facebook Messenger

#18
post #17
post #16

Earlier quoted context omitted.

If someone or something else is managing keys for you, even the javascript in your client, then it can be altered by the server just for you. It's really just that simple. If you are creating and managing key trusts outside of the application then they can not tamper with them or add their own keys.

I still don't understand what you are saying. You claim that Signal is not E2EE. Please explain. Signal is an open source mobile app that I can audit and compile myself. How is it "obviously not E2EE"?

Open source chat and open source AI just mean that the code you are looking at does not have an obvious back door. That has no bearing on run-time use and monkey-patching. As for Signal not being E2EE I already explained. I don't play the contrarian game so you will have to do your own research.

Re: Chat Control is already live on Facebook Messenger

#19
post #18
post #17

Earlier quoted context omitted.

I still don't understand what you are saying. You claim that Signal is not E2EE. Please explain. Signal is an open source mobile app that I can audit and compile myself. How is it "obviously not E2EE"?

Open source chat and open source AI just mean that the code you are looking at does not have an obvious back door. That has no bearing on run-time use and monkey-patching. As for Signal not being E2EE I already explained. I don't play the contrarian game so you will have to do your own research.

> As for Signal not being E2EE I already explained.

Either you have not, or it was wrong. It's not clear because there were a bunch of mixed up things (JavaScript has nothing to do with Signal, so I assume you were talking about the Proton web pages, and I would agree there).

> I don't play the contrarian game so you will have to do your own research.

That's not how it works: you say Signal is not E2EE, you prove it. I am convinced that it is, so from my point of view, you don't understand how it works. The only way I can help you understand is if you explain what you believe is wrong there. Google won't tell me that.

Re: Chat Control is already live on Facebook Messenger

#20

I thought that Facebook Messenger was end-to-end encrypted for personal one-on-one chats? That's also the reason why Facebook asks you to set a PIN to retrieve your chats on other devices. Only group chats are not E2EE. So yes, this looks like a chat control-like feature where the scanning is done on the client and not on Facebook's servers.

Whatsapp is e2ee with client reporting
Post reply on HN