Live data from Hacker News

Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

arstechnica.com

141–150 of 226 posts

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#141

"Meta said it rolled out end-to-end encryption "for all personal chats and calls on Messenger and Facebook" in December. And in 2018, Facebook told Vox that it doesn't use private messages for ad targeting.1 But a few months later, The New York Times, citing "hundreds of pages of Facebook documents," reported that Facebook "gave Netflix and Spotify the ability to read Facebook users' private messages."" 1. "Does Face…

My guess is that FB stores the keys to reverse the encryption. The point of e2e is to block any third party to to see your conversations by sniffing packets. Not to stop Meta themselves.

The OpenWhisper protocol, which is supposedly implemented by Messages and WhatsApp, was designed specifically to enable anonymous key agreement between the two or more parties sending messages, and no one else, including the service provider.

Whether or not Facebook actually implements it this way is a great question.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#142

"Meta said it rolled out end-to-end encryption "for all personal chats and calls on Messenger and Facebook" in December. And in 2018, Facebook told Vox that it doesn't use private messages for ad targeting.1 But a few months later, The New York Times, citing "hundreds of pages of Facebook documents," reported that Facebook "gave Netflix and Spotify the ability to read Facebook users' private messages."" 1. "Does Face…

My guess is that FB stores the keys to reverse the encryption. The point of e2e is to block any third party to to see your conversations by sniffing packets. Not to stop Meta themselves.

Packet sniffing is mitigated by TLS/HTTPS.

The point of end to end is to to ensure that only me and the person I'm sending a message to can read it and that none of the systems in-between us can read the plain text of it.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#143

"Meta said it rolled out end-to-end encryption "for all personal chats and calls on Messenger and Facebook" in December. And in 2018, Facebook told Vox that it doesn't use private messages for ad targeting.1 But a few months later, The New York Times, citing "hundreds of pages of Facebook documents," reported that Facebook "gave Netflix and Spotify the ability to read Facebook users' private messages."" 1. "Does Face…

My guess is that FB stores the keys to reverse the encryption. The point of e2e is to block any third party to to see your conversations by sniffing packets. Not to stop Meta themselves.

Uh nope, that's a huge move of the goal posts. The point of E2E is to ensure that nobody besides the two endpoints can read the messages, including all hops along the way, notably including the service provider themselves.

The problem is that this requires users to do things like use one device to authenticate another or restart key exchange with all of their peers. If a user loses their phone, then they will need to redo their security exchange process, which nobody wants to do or even understands. Thus companies often store key material in an insecure way to allow new devices to be silently added to the account.

Plus, even if E2E is well implemented, there are still problems when the endpoint software can be remotely updated to a version that exfiltrates keys or messages.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#144

Earlier quoted context omitted.

My guess is that FB stores the keys to reverse the encryption. The point of e2e is to block any third party to to see your conversations by sniffing packets. Not to stop Meta themselves.

The OpenWhisper protocol, which is supposedly implemented by Messages and WhatsApp, was designed specifically to enable anonymous key agreement between the two or more parties sending messages, and no one else, including the service provider. Whether or not Facebook actually implements it this way is a great question.

> two or more parties

When you’re having a 1:1 conversation with someone at a party, and then crack a joke and some weird dude 10 feet away laughs at you and says “good one”.

The obvious answer here would be for meta to consider itself party to your conversation.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#145
post #104

Earlier quoted context omitted.

I hope you’re being sarcastic? Or is that actually your stance on people’s privacy rights?

Lots of comments here look like some sort of astroturfing made by a PR agency

"Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data." - https://news.ycombinator.com/newsguidelines.html

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#146

"Meta said it rolled out end-to-end encryption "for all personal chats and calls on Messenger and Facebook" in December. And in 2018, Facebook told Vox that it doesn't use private messages for ad targeting.1 But a few months later, The New York Times, citing "hundreds of pages of Facebook documents," reported that Facebook "gave Netflix and Spotify the ability to read Facebook users' private messages."" 1. "Does Face…

My guess is that FB stores the keys to reverse the encryption. The point of e2e is to block any third party to to see your conversations by sniffing packets. Not to stop Meta themselves.

Although the frank meaning of "E2E encryption" is that a message is encrypted on the sender's device and only decrypted on the intended recipient's device, that is never ever what big tech companies mean when they use this term.

For one, this would remove companies' ability to support lawful interception, which puts them afoul of American law.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#147

"Meta said it rolled out end-to-end encryption "for all personal chats and calls on Messenger and Facebook" in December. And in 2018, Facebook told Vox that it doesn't use private messages for ad targeting.1 But a few months later, The New York Times, citing "hundreds of pages of Facebook documents," reported that Facebook "gave Netflix and Spotify the ability to read Facebook users' private messages."" 1. "Does Face…

My guess is that FB stores the keys to reverse the encryption. The point of e2e is to block any third party to to see your conversations by sniffing packets. Not to stop Meta themselves.

[deleted]

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#148
post #38

The article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages. Specific user would need to purposefully log in to the Netflix app with their Facebook account in order to grant Netflix access to the chat functionality (intended to send movie recommendations to Facebook friends inside the Netflix app). https://about.fb.com/…

And if a user consented to Netflix-based chat, Facebook overshared all chat data, instead of only the Netflix chat data, because they couldn't be bothered to build a properly isolated API? That's like asking permission to read and write your entire phone, just to provide the ability to write and read back a file.

That is how permissions work on android. I hate it.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#149

Earlier quoted context omitted.

It's both true and false. They don't do advertising with msg, and it's e2e encrypted. But they can use the metadata

It is end to end encrypted but facebook controls both ends so... ?

That's not how it works. They won't be able to see the messages themselves if it's e2e encrypted. You can say they are lying of course

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#150
post #83
post #38

Earlier quoted context omitted.

And if a user consented to Netflix-based chat, Facebook overshared all chat data, instead of only the Netflix chat data, because they couldn't be bothered to build a properly isolated API? That's like asking permission to read and write your entire phone, just to provide the ability to write and read back a file.

What incentive does FB have to limit that access? Feels like MBAs would just see that as a cost/burden? We know FB does give a fuck about privacy, so that’s never gonna be a reason.

If you believe FB is in the business of selling user data, then giving out user data for free is not an optimal move.
Post reply on HN