Live data from Hacker News

TikTok will not introduce end-to-end encryption, saying it makes users less safe

bbc.com

271–280 of 458 posts

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#271
post #29
post #13

Earlier quoted context omitted.

What do you use for messaging?

I have been using simpleX for some time now.

Are you aware of the creator's political beliefs and the E2EE leak baked into the app?

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#274
post #240
post #230

Earlier quoted context omitted.

I mean, your example of the ATO there isn't even an age verification thing, it's a defective clone of OIDC, so by that logic we should ban all SSO or identity delegation solutions? Because we don't believe anyone will ever use the standards in this area, despite loads of companies and government bodies actually using OIDC already? I'm not really sure what you're driving at.

> I mean, your example of the ATO there isn't even an age verification thing, it's a defective clone of OIDC, so by that logic we should ban all SSO or identity delegation solutions? MyGovID _is_ an age verifier. Sorry. The successor after the rebrand, is called myID [0], and advertised as: > myID is a secure way to prove who you are online. --- > I'm not really sure what you're driving at. Clearly. You seem to think…

> The successor after the rebrand, is called myID [0], and advertised as:

It's an identity scheme and SSO solution for accessing government services. As said at [0] in the "What is myID" section.

I sincerely hope that they're using something standard and well tested like OIDC behind the scenes this time, because otherwise it's ripe for another fuckup like the one you linked. If it is also used for age verification that appears to be secondary.

> You cannot enforce these real groups, to actually follow good practices. Thus, in practice, everyone gets fucked when you bring in these laws. Because it will always be done the wrong way, by someone.

So we need to stop the Australian government from ever using an SSO/identity solution again because it can't be trusted to do it properly, having messed up in the past, and the rest of us have had to live with the consequences. And as they aren't the only ones to have messed up, companies do it all the time too, we should also ban all identity and SSO solutions (because that's what we're talking about in this thread, banning of age verification, not mandating it).

I don't think you get to call out age validation as a uniquely hard problem that cannot possibly be made safe, but allow other identity-style services a pass. There are many areas in which we (through the government) can and do mandate good practice, both by government and private entities.

[0] https://my.gov.au/en/about/help/digital-id

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#275

Earlier quoted context omitted.

I forget if its WhatsApp that technically lets you sync chats in unencrypted form to iCloud which is the “loophole” around this, though you can lockdown your iCloud even tighter, not sure it Apple can do much if you fully lock down your iCloud, not sure if this has been legally tested? Its not a very advertised feature its just a setting.

WhatsApp iPhone syncs to iCloud unencrypted by default[1]. iMessage also syncs to iCloud unencrypted by default[2]. [1] Depends on you paying for iCloud storage, so that you have space for a full phone backup to occur. [2] Might be "free" with "iMessage in iCloud", an option to enable separately.

> WhatsApp iPhone syncs to iCloud unencrypted by default[1].

Not true. You must choose to enable it or not when you set up new phone. On mine it does not back up

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#276

Earlier quoted context omitted.

> I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? People are paranoid about this sort of thing not because they think law enforcement is more effective when it is constrained. But how easil…

> Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? Police can access your home with a warrant. Police cannot access your E2EE DMs with a warrant.

And they shouldn't be able to. Police accessing DMs is more like "listening to every conversation you ever had in your house (and outside)" than "entering your house".

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#277

Earlier quoted context omitted.

> I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? People are paranoid about this sort of thing not because they think law enforcement is more effective when it is constrained. But how easil…

> Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? Police can access your home with a warrant. Police cannot access your E2EE DMs with a warrant.

>Police cannot access your E2EE DMs with a warrant.

Well the kind of can if they nab your cell phone or other device that has a valid access token.

I think it's kind of analogous to the police getting at one's safe. You might have removed the contents before they got there but that's your prerogative.

I think this results in acceptable tradeoffs.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#278
post #239

Earlier quoted context omitted.

I fail to see the link between private conversations/DM and E2EE. To quote a comment I made some time ago: - You can call your service e2e encrypted even if every client has the same key bundled into the binary, and rotate it from time to time when it's reversed. - You can call your service e2e encrypted even if you have a server that stores and pushes client keys. That is how you could access your message history on…

no you couldn't. that wouldn't be considered end-to-end encrypted in any modern sense

What I described is essentially how the vast majority of E2EE messaging platforms work. And I say that having worked for one of them.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#279
post #212

Earlier quoted context omitted.

Depends on your definition of "safe". Imagine an adult DMs a nude photo to a minor (or other kinds of predation). If it's E2EE, no one except the sender and receiver know about this conversation. You want an MITM in this case to detect/block such things or at least keep record of what's going on for a subpoena. I agree that every messaging platform in the world shouldn't be MITM'd, but every messaging platform doesn'…

Keeping children safe and prosecuting are too different concepts, only vaguely related. So no, being able to track pdfs doesn't make children safer. What keeps them safe is teaching them safe communication habits and keeping them away from things like Tiktok. We shouldn't make the world a worse place for every one because some parents can't take care of their children.

>Keeping children safe and prosecuting are too different concepts, only vaguely related.

See also: That time the FBI took over a CSAM site and kept it running so they could nab a bunch of users.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#280
post #210

Earlier quoted context omitted.

Tiktok has private messaging, and it is used by hundreds of millions of people. IMO no consumer service should have private 1:1 messaging without e2e. Either only do public messaging (ie. Like a forum), or implement e2e.

In my experience most forums have private messaging. Additionally I think it is fine to say "we don't support e2ee". I prefer honesty to a bad (leaky) e2ee implementation, at least the user can make an informed choice.

>In my experience most forums have private messaging.

Yeah but it's kind of accepted that the forum owner could read it all if they so chose. Maybe this is a hold over from back in the old days when encryption was nowhere near default during which forums arose.

Post reply on HN