Message appeared in the Facebook page as "encrypted message".
I guess you hardly can get better than this.
261–270 of 312 posts
Message appeared in the Facebook page as "encrypted message".
I guess you hardly can get better than this.
Earlier quoted context omitted.
> It looks as if PGP's days are numbered. This seems gratuitously hostile (and, even worse, is irrelevant). PGP is a very useful piece of software, and it does something completely different from Signal, and I'm glad both exist.
>> It looks as if PGP's days are numbered Comments like this are inevitable and represent Facebook's attempts to induce us to route all of our communications though its platform. For the quoted commenter, it's probably too late.
Earlier quoted context omitted.
I replied above, but there are few communication tools with such a wide userbase that have forward-secrecy and similar strong E2E crypto built in and available. People die because of what they post to Facebook or what they send in Messenger, I know this for a fact. With E2E security locked to devices it means that in the few seconds it takes me to wipe my phone while someone is knocking on the door with a gun then th…
A totally satisfying explanation! I apologize, you had every right to invoke the risking of lives. However, I hope your hopefully hypothetical dissident who is saying the things that cause armed men to knock knows to avoid Facebook altogether (you know, that company predicated on watching the things that you do and turning that knowledge into actionable data in exchange for money). Failing to do that is indeed an exi…
I've read the whole thread and I'm surprised that nobody mentionned how easy it would be for Facebook to store the secret keys. Page 10 of the white paper mentions that there is a remote key stored on Facebook servers which can be used to decrypt the local key. If Facebook still is to be trusted, I don't see what's the deal here. I think that as soon as you put the words "end-to-end" encryption on a marketing materia…
Earlier quoted context omitted.
Over here in the real world, Facebook does not need to worry about "[losing] customers to these other message apps that tout their encryption" because the latter are not even in the game. There are only a few messaging apps that matter, because the value of the app is in its network and who it can connect you to rather than some feature checklist for the HN crowd. Dropping secure E2E encryption into an app that is de…
If barely anyone uses it then how is it a game changer? Please update us in a few months with usage statistics.
I've read the whole thread and I'm surprised that nobody mentionned how easy it would be for Facebook to store the secret keys. Page 10 of the white paper mentions that there is a remote key stored on Facebook servers which can be used to decrypt the local key. If Facebook still is to be trusted, I don't see what's the deal here. I think that as soon as you put the words "end-to-end" encryption on a marketing materia…
Not quite.
It means nobody is going to be able to read your data other than:
A) A nefarious Facebook staffer who has hacked their internal systems
B) A government entity with a court order
It's a step up from no encryption
Earlier quoted context omitted.
You can totally run your own server for yourself and your friends: https://github.com/WhisperSystems/TextSecure-Server (you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy) What you won't be able to do is federate with the official servers. Oh, and there's also a WebSocket transport (used by the Desktop client) that doesn't involve Google. That just do…
> you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy I'm sorry, but is this a joke? "To not use a centralized server that you can neither audit nor trust, you have to recompile the client, but that's easy ?" This smacks of "oh, PGP for email is fiiiiiine." To say nothing of the silliness of the inability to federate.
Earlier quoted context omitted.
A totally satisfying explanation! I apologize, you had every right to invoke the risking of lives. However, I hope your hopefully hypothetical dissident who is saying the things that cause armed men to knock knows to avoid Facebook altogether (you know, that company predicated on watching the things that you do and turning that knowledge into actionable data in exchange for money). Failing to do that is indeed an exi…
As a former FB employee I can empathize with the desire to avoid the mass data trawling that is involved in using the product, but having seen things from the inside I also know that people working there really, honestly do have users best interests at heart. During my tenure I worked on the effort to create Tor hidden nodes so that people could use FB via secure channels and watched the E2E effort go from Alec's wil…
Oh shit, sorry dude D:
>I understand why you would have absolutely no reason to believe any of this
Well, it's not really that. Most serious tech-folk have realistic conceptions of privacy issues (he said in a comment on HN, but whatever), and your response above shows that you likely do, too. The controlling suits, however, typically have different priorities. Thanks for your response!
Earlier quoted context omitted.
Yeah, so instead of being in Whisper Systems' walled garden, I can set up my own and ask people to install Rvense's Magical Messenger App. Sit there in my treehouse with a bucket on my head and a NO DUMMIES sign or something.
Seems like you want the advantages of both centralization and federation without any of the disadvantages.
From what is written, I understand this to mean that users can select this feature for specific conversations. That not all messages are subject to this encryption. I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? This feature is a massive boost for intelligence services dealing with unsophisticated actors. This reduces the haystack s…