Live data from Hacker News

TikTok will not introduce end-to-end encryption, saying it makes users less safe

bbc.com

231–240 of 458 posts

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#231
post #150

It doesn't matter. Web-based cryptography is always snake oil https://web.archive.org/web/https://www.devever.net/~hl/webc...

Agree, but a significant point missed in the article is that of data vulnerability. with E2EE the company db is useless to an external attacker. For some companies (eg facebook, google, tiktok) i would be mostly worried about the company itself being untrustworthy. For others I would be mostly worried about the company being vulnerable.

> with E2EE the company db is useless to an external attacker.

Depends on who is defined as the other end, it may be that the company db is the other end.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#232

Earlier quoted context omitted.

> you just have intact brain Fixed a bit.

As much as I want to agree with you, the people who like TikTok make up a significant amount of the population, and their opinions do matter--arguably more than yours, due to sheer numbers. Smugly dismissing them doesn't do you any favors except for making you feel good about yourself for a few seconds.

You’d be surprised how many people don’t give a shit about TikTok. It’s just another blip in history like Facebook, Instagram, Vine, MySpace and others before them.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#233
post #48

> Grooming and harassment risks are very real in DMs [direct messages] so TikTok now can credibly argue that it's prioritising 'proactive safety' over 'privacy absolutism' which is a pretty powerful soundbite Means they read every message

Larry needs his kids' menu.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#234

I think this is... fine? Am I just totally naive. I think it's fine to say "You don't really have privacy on this app" - as long as there are relatively good options of apps that do have privacy (and I think there are). TikTok is really a public by default type of social media, there's not much idea of mutual following or closed groups. So sure, you don't have privacy on tiktok, if you want it you can move to snapcha…

Tiktok has private messaging, and it is used by hundreds of millions of people. IMO no consumer service should have private 1:1 messaging without e2e. Either only do public messaging (ie. Like a forum), or implement e2e.

The email protocols would like to have a chat with you.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#235
post #201

I think this is... fine? Am I just totally naive. I think it's fine to say "You don't really have privacy on this app" - as long as there are relatively good options of apps that do have privacy (and I think there are). TikTok is really a public by default type of social media, there's not much idea of mutual following or closed groups. So sure, you don't have privacy on tiktok, if you want it you can move to snapcha…

No, saying that e2e encryption makes users _less_ safe is completely dishonest, nothing is fine about this. The logic of "anything is better than before" is also fallacious.

well having no e2e encryption is safer than having a half-baked e2e encryption that have backdoor and can be decrypted by the provider.

and for tiktok's stance, I think they just don't want to get involved with the Chinese government related with encryption (and give false sense of privacy to user)

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#236
post #9

BBC calling encryption "controversial privacy tech" is deeply disappointing and dangerous.

Calling something controversial is a favorite propaganda technique employed by "news" outlets. It's another form of selective reporting and framing. It carries negative connotations, and has really no objective standard by which it can be wrong since you'll always find somebody against any issue. After you notice it, you'll notice it everywhere.

> It carries negative connotations

Interesting I'm not a native English speaker but in news articles I have always interpreted "controversial" as meaning "under discussion" (perhaps even around a 50/50 divide) hence why they are writing an article about it.

I feel it is the news outlet trying to justify why the topic is important to read about since most people reading it will interpret the issue at hand as having a "common" stance. Usually it is used in topics that are very binary, for or against.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#237

Earlier quoted context omitted.

Tiktok has private messaging, and it is used by hundreds of millions of people. IMO no consumer service should have private 1:1 messaging without e2e. Either only do public messaging (ie. Like a forum), or implement e2e.

The email protocols would like to have a chat with you.

You can bring your own encryption to that, and bring your own client to automate it.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#238

Earlier quoted context omitted.

Yes, but this leaves the only way to identify this behavior as by reporting from a minor. I'm not saying I trust TikTok to only do good things with access to DMs, but I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted. I'm not saying no E2E messaging apps should exist, but maybe it doesn't need to for minors in social media apps…

> I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? People are paranoid about this sort of thing not because they think law enforcement is more effective when it is constrained. But how easil…

> Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant?

Police can access your home with a warrant.

Police cannot access your E2EE DMs with a warrant.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#239

DMs are akin to private conversations in real life. Thus, every DM feature should entail E2EE. It’s ok for a platform to not feature private conversations. They should just have no DM feature at all, then; make all messages publicly visible. Private conversations are indeed not for all ages. Parents should be able to grant access to that on individual basis.

I fail to see the link between private conversations/DM and E2EE. To quote a comment I made some time ago: - You can call your service e2e encrypted even if every client has the same key bundled into the binary, and rotate it from time to time when it's reversed. - You can call your service e2e encrypted even if you have a server that stores and pushes client keys. That is how you could access your message history on…

no you couldn't. that wouldn't be considered end-to-end encrypted in any modern sense

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#240
post #230
post #209

Earlier quoted context omitted.

If neither follow them, why do you have such faith that anybody would...?

I mean, your example of the ATO there isn't even an age verification thing, it's a defective clone of OIDC, so by that logic we should ban all SSO or identity delegation solutions? Because we don't believe anyone will ever use the standards in this area, despite loads of companies and government bodies actually using OIDC already? I'm not really sure what you're driving at.

> I mean, your example of the ATO there isn't even an age verification thing, it's a defective clone of OIDC, so by that logic we should ban all SSO or identity delegation solutions?

MyGovID _is_ an age verifier. Sorry. The successor after the rebrand, is called myID [0], and advertised as:

> myID is a secure way to prove who you are online.

---

> I'm not really sure what you're driving at.

Clearly. You seem to think that because it might one day be done correctly, by one group, the rest of the world is safe. However, over in this reality, we have fuck ups by governments and private corporations, who are the people the rest of the world actually deals with.

You cannot enforce these real groups, to actually follow good practices. Thus, in practice, everyone gets fucked when you bring in these laws. Because it will always be done the wrong way, by someone.

[0] https://www.myid.gov.au/

Post reply on HN