Live data from Hacker News

TikTok will not introduce end-to-end encryption, saying it makes users less safe

bbc.com

221–230 of 458 posts

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#221
The actual headline is currently

> TikTok won't protect DMs with controversial privacy tech, saying it would put users at risk

Not sure if this was changed since first posting, I don't mind updates, but unless it'd redacting for legal purposes (which should then itself be clearly mentioned), the BBC should provide a public changelog like wikipedia

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#223

TikTok is a front for government surveillance, so it's not really surprising that this is their position.

The government are able to access your conversations, data and connections with e2ee in place already. I don't see how not having e2ee would have an effect on that ability in any way.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#224
post #20

This might be off-topic but on-topic about child safety... but I'm surprised people are being myopic about age verification. Age verification should be banned, but people ignore that nowadays most widely used online services already ask for your age and act accordingly: twitter, youtube, google in general, any online marketplace. They already got so much data on their users and optimize their algorithms for those gro…

Monitoring children's DMs is the responsibility of the parents, not megacorps. If a parent wants to install a keylogger or screen recorder on their child's PC, that's their decision. But Google should not be able to. Neither should... literally anyone else except maybe an employer on a work-provided device.

I'm all for helping parents to do this. Any site requiring age verification should indicate this as a http header or whatever, and the browser I allow my child to use should respect that and the parental controls should be easy for me to engage with

Many parental controls are massive pains to get working. Apple does fairly well (although I don't get a parental pin number to unlock the phone, which is normally fine as my child will tell me, but in some circumstances it wouldn't be), but does require the parent to be on the apple ecosystem too.

EA and Microsoft however are terrible, especially as it's likely the child will be playing fortnite/minecraft and the parent won't have ever touched it. I think with minecraft we had to make something like 5 or 6 accounts across three different sites to allow online minecraft play from a nintendo switch.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#225
post #43
post #40

Earlier quoted context omitted.

> Monitoring children's DMs is the responsibility of the parents, not megacorps Absolutely. But what responsibilities do megacorps have? Right now, everyone seems to avoid this question, and make do with megacorps not being responsible. This means: "we'll allow megacorps to be as they are and not take any responsibilities for the effects they cause to society". Instead of them taking responsibilities, we're collectin…

> But what responsibilities do megacorps have? Right now, everyone seems to avoid this question Clear, simple, direct: Whatever was required of The Bell Telephone Company and nothing more.

Whatever was required of the new york times and nothing more.

If the NYT publishes and advert or editorial, it's held accountable for the contents.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#226
post #208

Earlier quoted context omitted.

The receiver has a proven and signed bundle, that they can upload to the abuse report. So the evidence has even stronger weight. They can already decrypt the message, they can still report it.

Yes, but this leaves the only way to identify this behavior as by reporting from a minor. I'm not saying I trust TikTok to only do good things with access to DMs, but I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted. I'm not saying no E2E messaging apps should exist, but maybe it doesn't need to for minors in social media apps…

> I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted

Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? People are paranoid about this sort of thing not because they think law enforcement is more effective when it is constrained. But how easily crimes can be prosecuted is only one dimension of safety.

> However, an alternative could be allowing the sharing of the encryption key with a parent

Right, but this is worlds apart from "sharing the encryption key with a private company", is it not?

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#227

Earlier quoted context omitted.

It's never been controversial, it's the BBC. doing it's usual job of laundering the arguments the establishment want you to hear for domestic consumption.

The thing is, it _is_ controversial. At least amongst the general public. Obviously not in somewhere like Hacker News where there’s a clear consensus, but if you asked a random sample of the UK population “should law enforcement be allowed to compel tech companies to hand over all DMs of confirmed paedophiles?”, I’d bet very good money the majority would say “yes”. The notion that “Big Tech” can absolve themselves of…

Sure, but it comes down to framing.

If you asked 'Would you support weakening encryption in messaging apps if it helped catch some criminals, even though it could make it easier for hackers to read your messages and steal your passwords, bank details, or personal photos?' I'd bet a large proportion of the general population would say no.

But that side never gets explored, or there's an assumption that there's some way of only letting the good guys access the information.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#228

I don’t really understand how we are supposed to believe in e2ee in closed proprietary apps. Even if some trusted auditor confirms they have plumbed in libsignal correctly, we have no way of knowing that their rendering code is free of content scanning hooks. We know the technology exists. Apple had it all polished and ready to go for image scanning. I suppose the only thing in which we can place our faith is that it…

With e2ee please remember that it is important to define who are the ends.

Perhaps your e2ee is only securing your data in travel if their servers are considered the other end.

Also one thing people seem to misunderstand is that for most applications the conversation itself is not very interesting, the metadata (who to who, when, how many messages etc.) is 100x more valuable.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#229

I think this is... fine? Am I just totally naive. I think it's fine to say "You don't really have privacy on this app" - as long as there are relatively good options of apps that do have privacy (and I think there are). TikTok is really a public by default type of social media, there's not much idea of mutual following or closed groups. So sure, you don't have privacy on tiktok, if you want it you can move to snapcha…

Tiktok has private messaging, and it is used by hundreds of millions of people. IMO no consumer service should have private 1:1 messaging without e2e. Either only do public messaging (ie. Like a forum), or implement e2e.

Tiktok has direct messages, they don't even call them private.

It's better that they're honest about this, nobody should believe for a second that WhatsApp or FB messages are truly E2EE.

DM on social media shouldn't be used for anything remotely private. It's a convenience feature, nothing more.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#230
post #209
post #200

Earlier quoted context omitted.

> You don't exactly get to dictate how the government implements it! Who was talking about the government implementing it? I wasn't. And also "This has been done poorly in the past so we should never attempt to do it again, better" seems an odd way to go about things. There are well put together schemes by international standards bodies in this area now. Neither of the above links followed them.

If neither follow them, why do you have such faith that anybody would...?

I mean, your example of the ATO there isn't even an age verification thing, it's a defective clone of OIDC, so by that logic we should ban all SSO or identity delegation solutions?

Because we don't believe anyone will ever use the standards in this area, despite loads of companies and government bodies actually using OIDC already?

I'm not really sure what you're driving at.

Post reply on HN