Live data from Hacker News

Meta Shuts Down End-to-End Encryption for Instagram Messaging

pcmag.com

31–40 of 235 posts

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#31
post #9

Instagram should be shut down. Not using encryption for social media and places where users expect any level of privacy is insanity.

[flagged]

Users generally do not believe Instagram is reading their chats. Source: I have had this conversation many, many times.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#32

Earlier quoted context omitted.

Actually, by doing e2e encryption, Meta can say to the authorities that Meta doesn't see any message and cannot be blamed for anything. We cannot snoop user's conversation, and that's generally a good thing. The authority holds Meta responsible anyway; they don't care about the implementation detail. They want to catch a pedo, and Meta is unable to produce evidence that helps them. Everyone else will yell at Meta for…

> The authority holds Meta responsible anyway What form of accountability are you suggesting is even being leveraged, here? No law could force Meta to backdoor its encryption, afaik. Public pressure would be unlikely to work. Is Meta afraid of anything real, or is this just blame shifting via ungrounded speculation?

They can because Meta has chosen to implement e2e encryption. They could have chosen not to implement e2e encryption. All within their controls.

Australia already has this law in place where a company must hand over user's conversation. A company cannot make an excuse that they themselves implement e2e to prevent themselves from reading user's messages. Source: https://www.bbc.com/news/world-australia-46463029

UK has a proposal to ban encryption this year. It is still being discussed.

> Public pressure would be unlikely to work

Public pressure works to a certain degree. Do you think a product manager at Meta would want to be labeled as "protecting pedos"?

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#33

I'm not sure the value of end to end encryption for proprietary application chats. For emails and SMS messages, your messages are being sent between different multiple servers on the open internet and it opens you up to spying, but end to end encryption on instagram is only protecting your chats from Meta. I find the end to end encryption on Facebook to be detrimental to ease of use, because you always have to use a…

> but end to end encryption on instagram is only protecting your chats from Meta.

No. It protects your chats from Meta and all governments of the countries where Meta operates.

In fact, I expect Instagram to be more reachable globally now because these relaxed communication standards would be welcomed by oppressive governments as they can now retrieve messages as they please for whatever purpose they deem.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#34

Put simply: I’ve talked to Apple engineers. Siri fell behind due to how good Apple’s privacy is. Everyone made fun of them for protecting them. This is exactly the opposite of that, where Mark is throwing you and your children under the bus again because he’s unoriginal and doesn’t know how to make money any other way than by getting all up in your business, statistically.

Do you know what Zuckerberg said in an interview? I think it was to Lex Fridman but I could be wrong

"Apple hasn't come up with anything new in 20 years"

Very likely in response to Apple's granularity. Poor Zuck can't steal people's credentials

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#35

Earlier quoted context omitted.

I usually defend Siri, because I’m perfectly fine trading a little functionality for security. I prefer it that way.

Same. The fact they're shoving AI into it and expanding it to providers who don't have privacy as a guiding principle is a key reason I'm sitting on a 14 Pro still, and why I'm exploring local alternatives with Home Assistant. Besides, we just need to set verbal timers and control music. We don't need a full-blown verbal Oracle.

Home Assistant is indeed quite nice and relatively simple to set up with the Docker images provided by the team. Device setup on iOS was a little inconsistent, but has been rock solid for over a year. Check out Homebridge as well. I run both.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#36

Earlier quoted context omitted.

Do people expect that Instagram can't read their Instagram private messages? I don't think people expect that. And E2EE is not nearly as cheap as the HN crowd likes to pretend—how do those devices get those keys if not through a central service? Especially if one of them is a web browser?

The answer to most everyone question you’re asking is just, “public key cryptography”. It’s kind of disheartening to me that such basic 1990s tech as implemented by Phil Zimmerman is now obscure enough to merit questions like this. Both parties exchange public keys through the central service. Only the possessor of the respective (on device, Secure Enclave ideally) private keys can decrypt the messages encrypted to t…

And how does one verify that the public key received belongs to the intended party, rather than a mitm?

If the answer is blind trust in a third party that runs the messaging service then I suspect that you can guess what the people asking those questions are really asking.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#37

I'm not sure the value of end to end encryption for proprietary application chats. For emails and SMS messages, your messages are being sent between different multiple servers on the open internet and it opens you up to spying, but end to end encryption on instagram is only protecting your chats from Meta. I find the end to end encryption on Facebook to be detrimental to ease of use, because you always have to use a…

the entire point of encryption is that you don't trust the channel you communicate through, that's what it was invented for, communication across adversarial channels. Distrust is the only condition under which you need encryption. In addition from a practical POV it's if anything the reverse is the case. Email encryption is larp security because plain text is the default, leaks metadata and its interfaces make it tr…

It's a governance.

The executives don't want anyone else to be able to use the messages in a malicious way, so they decide to cut it at the sources of the messages i.e. e2e encryption.

This is like: corporate emails being deleted after 6 months. When an authority asks for emails from the last year, they can say they don't have it.

Now the authority can ask for the emails not to be deleted at all but then that will be a different battle the authority has to fight.

Corporate emails often don't involve pedos/terrorism, so there's much less push to retain corporate emails forever.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#38

Earlier quoted context omitted.

Do people expect that Instagram can't read their Instagram private messages? I don't think people expect that. And E2EE is not nearly as cheap as the HN crowd likes to pretend—how do those devices get those keys if not through a central service? Especially if one of them is a web browser?

The answer to most everyone question you’re asking is just, “public key cryptography”. It’s kind of disheartening to me that such basic 1990s tech as implemented by Phil Zimmerman is now obscure enough to merit questions like this. Both parties exchange public keys through the central service. Only the possessor of the respective (on device, Secure Enclave ideally) private keys can decrypt the messages encrypted to t…

The fly in the ointment is that they control the software and updates to that closed software so can short circuit that with appropriate pressure.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#39

Earlier quoted context omitted.

I usually defend Siri, because I’m perfectly fine trading a little functionality for security. I prefer it that way.

Same. The fact they're shoving AI into it and expanding it to providers who don't have privacy as a guiding principle is a key reason I'm sitting on a 14 Pro still, and why I'm exploring local alternatives with Home Assistant. Besides, we just need to set verbal timers and control music. We don't need a full-blown verbal Oracle.

Im curious what the threat model is that you're protecting against

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#40

Earlier quoted context omitted.

I usually defend Siri, because I’m perfectly fine trading a little functionality for security. I prefer it that way.

Same. The fact they're shoving AI into it and expanding it to providers who don't have privacy as a guiding principle is a key reason I'm sitting on a 14 Pro still, and why I'm exploring local alternatives with Home Assistant. Besides, we just need to set verbal timers and control music. We don't need a full-blown verbal Oracle.

They’re hosting their own Gemini, so they aren’t sacrificing to Google’s standards even if using their technology.
Post reply on HN