Live data from Hacker News

Meta Shuts Down End-to-End Encryption for Instagram Messaging

pcmag.com

171–180 of 235 posts

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#171

Earlier quoted context omitted.

No, because it's terrible. There's no need to break encryption to allow you to report a user. You'd just report via a copy of an excerpt of the conversation and leave the rest of your communication private. If the user can't tamper with the extraction of that excerpt, you can trust it is correct. You could even extract hashes from both the reporting party and the reported party and compare them with zero knowledge of…

You have you contrive a complex system involving zero knowledge proofs and a lot more work, rather than just being able to see on the server the message asking for a child to dance in their underwear directly makes their argument DoA?

It's pretty easy to do tho and it has the benefits of both allowing privacy and being able to check if someone is actually trying to abuse kids.

No e2e is understandable if you're the Chinese government but isn't TikTok now run by a us company (at least in America) ?

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#172
post #78

Earlier quoted context omitted.

Then a more reasonable response is: “we cannot as effectively monetize all of the data in our advertising platform disguised as another tool entirely unless we disable E2EE and we need to be able to allow not only ourselves but others to invade your privacy even more than we already do because it’s technologically difficult to do so when we encrypt your communications.”

it doesn't necessarily have to be tied to monetization & privacy directly. It may just be that ROI doesn't make sense: very few user out there truly care about (or even understand) E2EE, for quite some users it creates an inconvenience & support incidents (harder to move from device to device, forgot your passphrase - lost your history, new joiners to a group chat don't see previous history, etc), it requires a signi…

From talking to people from Meta, they don’t believe in E2EE because “it’s decrypted on the other end” which they take as “becomes insecure in exactly the way we’ve designed the sausage factory”

They’re a bit of a self fulfilling prophecy for why it is a futile effort for trying to secure information near them.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#173
post #170
post #169

Earlier quoted context omitted.

With reproducible builds like Signal does you can be sure the app you've downloaded matches the source code that's been audited: https://github.com/signalapp/Signal-Android/blob/main/reprod...

While I agree reproducible builds are a huge part of the answer, if you get your builds from Google Play or the App Store you have no idea if anyone has reproduced the particular build that was served to your device. A solution to this would be independent reproducible builds like F-Droid does, but Moxie rejected this citing it would cause them to lose control of the platform and install metrics Google and Apple prov…

there's no guarantee, but if the build is mass served - it's at least possible to find out. For closed source apps you may even not know

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#174

People here like it, but end-to-end encryption is an objectively worse user experience for people that don't care about that feature

How is it a worse experience? It's ridiculously simple: The app sends a public key to the person you're talking to. The end user doesn't even need to notice it. What am I missing here?

I honestly can't tell if this is sarcasm

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#175
post #161

Centralized proprietary software on on proprietary platforms can always be opted into a special update that makes all the private keys deterministic making end to end encryption useless for anyone with knowledge of that targeted backdoor. Only FOSS can deliver verifiable E2EE, and all centralized and proprietary solutions like Zoom, Whatsapp, Instagram, etc should end the security theater. I applaud Meta for at least…

Centralized FOSS software can do the same thing and remove encryption. Open source is not a requirement for security.

Unlike the proprietary stuff there isn't a strong built incentive to remove it.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#176
post #170
post #169

Earlier quoted context omitted.

With reproducible builds like Signal does you can be sure the app you've downloaded matches the source code that's been audited: https://github.com/signalapp/Signal-Android/blob/main/reprod...

While I agree reproducible builds are a huge part of the answer, if you get your builds from Google Play or the App Store you have no idea if anyone has reproduced the particular build that was served to your device. A solution to this would be independent reproducible builds like F-Droid does, but Moxie rejected this citing it would cause them to lose control of the platform and install metrics Google and Apple prov…

Personally I would be more concerned about a vulnerability or backdoor in Intel SGX

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#177

Earlier quoted context omitted.

>Do people expect that Instagram can't read their Instagram private messages? I don't think people expect that. A deeper question is why we reached a point where people can't reasonably expect their communication to not be spied on.

People, or at least Americans, didn’t care in 2012 when the Snowden reveal happened. We’ve been at that point for over a decade now.

Considering the average person thinks that opening websites in incognito means no one knows they visited them, I would agree.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#178

Earlier quoted context omitted.

Can you steelman TikTok's argument?

HN isn't a place for serious thought nor internal critique. No one (all bots at this point?) will critically engage past the most surface level reddit tier argument.

I'm sorry but encryption like https has been around since 1995. Every software engineer knows they should use encryption to protect pii.

What am I supposed to be doing on behalf of meta? To prove I am not a bot with a smooth brain? Present their argument? Their argument is they want to sell as much data as possible about adults and children to the department of war. They want to double dip and use all user data as a means to produce advertisements, algorithms, and user experiences that negatively impact children's health so they can profit.

https://www.abc.net.au/news/2026-03-26/meta-and-google-found...

If you want me to argue for meta on their behalf to help them find reasons to forward their goals of exploiting their user base, I won't. The exercise has negative value.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#179
post #169

Earlier quoted context omitted.

Centralized FOSS software can do the same thing and remove encryption. Open source is not a requirement for security.

With reproducible builds like Signal does you can be sure the app you've downloaded matches the source code that's been audited: https://github.com/signalapp/Signal-Android/blob/main/reprod...

So what? The centralized owner owns the code repo too, so such a restriction doesn't stop anything.

Even if Instagram was open source, Meta could remove the E2E chat feature.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#180
post #175

Earlier quoted context omitted.

Centralized FOSS software can do the same thing and remove encryption. Open source is not a requirement for security.

Unlike the proprietary stuff there isn't a strong built incentive to remove it.

One incentive is that it makes for a simpler user experience.
Post reply on HN