Live data from Hacker News

Facebook and PGP

cs.columbia.edu

31–40 of 60 posts

Re: Facebook and PGP

#31
post #2

Another possibility is one of their programmers thought "It would be good if there was more encrypted e-mail going around in general, I wonder if I can get it into facebook somehow" and coded this feature in their free time. Then convinced his managers to integrate it with that argument plus "and it's already coded we just need to merge it in"

This is by far the most likely reason. When you hire top developers, those developers want to work on interesting stuff. If retaining those people is a priority, the middle manager's only option is to smile and nod when they tell him something they'd like to do, or he'll soon find himself without employees, and shortly after without a job.

Just look at all the shit that comes out of Google, not as part of some grand overarching scheme, but because someone thought it would be fun, and more often than not forgotten about a year later.

Re: Facebook and PGP

#32
post #11
post #2

Another possibility is one of their programmers thought "It would be good if there was more encrypted e-mail going around in general, I wonder if I can get it into facebook somehow" and coded this feature in their free time. Then convinced his managers to integrate it with that argument plus "and it's already coded we just need to merge it in"

Well, from what I know there are some seriously privacy minded people in there. As oxymoronic as that sounds. But I could certainly see some benefits both for FB and for world at large from this. One of the big problems with PGP is how to bootstrap web of trust. "Does this key really belong to this particular person?" But what if the otherwise loathed real name policy could be turned to service this particular need?…

Zuckerberg actually cares a lot about his privacy. Yours? Maybe not as much.

http://www.slate.com/blogs/business_insider/2015/05/18/tech_...

http://www.theguardian.com/technology/shortcuts/2015/may/19/...

But isn't the PGP move a sign that Facebook cares about our privacy? Not really. The profile thing makes it easy to discover people who use PGP and email them with encrypted messages, but that has nothing to do with Facebook's content.

As for the encrypted notifications, Facebook can obviously still read those, and it can be useful to protect the data from Google. Also, if more people use PGP for email, that means less data for Google, so I could actually see this being a strategic move, too. Maybe not a huge one, but it doesn't cost Facebook too much to implement this, so why not?

I'll start thinking Facebook actually cares about my privacy when the Messenger uses Axolotl or OTR as well as ZRTP. Until then, I'll remain skeptical of Facebook's privacy intentions.

Re: Facebook and PGP

#33
post #19

Earlier quoted context omitted.

Despite his German sounding name, I can assure you that Phil Zimmermann, the creator of PGP, is very much an American.

He meant Werner Koch, the guy who is maintaining gnupg A few months ago, he asked again for donation, this time he got "good media exposure" and got funded. cf https://news.ycombinator.com/item?id=9011138 Facebook pledged to donate $50,000 a year to Koch’s project.

Uuups, my bad.

Thanks for corrections.

Re: Facebook and PGP

#34
post #25

Earlier quoted context omitted.

I agree with the demographics, but I've never understood this connection. With Facebook, the intrusion of privacy happens completely out in the open and you can work with that. By now pretty much everyone concerned knows that they collect and potentially use everything they can. With email interception, on the other hand, that's something you don't have any control over without encryption. So in my mind, I can be a h…

> With Facebook, the intrusion of privacy happens completely out in the open and you can work with that. I'm not following. Once I hand over my data I have no real control over how they end up using it behind the scenes. Furthermore, even if I never sign up with Facebook or at some point delete my account thinking my data has been flushed, a "shadow profile" still exists that I have no control over. [1] [1] http://mo…

I'm not following either.

If such interactions happen in the "open", facebook is then encrypting information relating to such "open" interactions, so that people already familiar with things like pgp/gpg (of which, I assume who also know what email headers are) can know that such "open" interactions came from facebook and that such information regarding "open" interactions was not modified in transit?

I guess "completely out in the open" means different things to different people…

Re: Facebook and PGP

#35
post #6
post #4

What if Google validated PGP signatures for you from trusted, popular certs? They'd have Facebook's pubkey on file, and -- transparent to you -- would create something analogous to my browser's lock icon in their email browser. Any time you got an email from Facebook, it'd say "Verified Sender". Heck, couldn't we tie mail from Facebook back to their domain cert given to them by their CA? If it says @facebook.com, and…

This has been done for some time already via DKIM and DMARC, which anyone can configure. https://support.google.com/a/answer/174124 https://support.google.com/a/answer/2466580

Thanks for noting this. A lot of discussion about email encryption and security is clearly from the consumer POV, and most people seem to be unaware of things enterprises already do (using commonly available tools & settings) to secure email. Not that it replaces message encryption via S/MIME or PGP, but companies like https://www.mailvelope.com/ and https://www.virtru.com are trying to help with that.

Re: Facebook and PGP

#36
post #30
post #20

Earlier quoted context omitted.

S/MIME has very little adoption - the kind of people who care about encrypting their email are usually the same kind of people who don't trust the CA system.

That's not true: https://gist.github.com/rmoriz/5945400

Also US medical data exchange is built on S/MIME: http://www.directtrust.org/

Re: Facebook and PGP

#37
post #7

The last paragraph of the linked post describes more or less what keybase [1] is. [1] https://keybase.io/

A little of topic, but if someone would like a invite to keybase let me know :-)

Hijacking: tweet at me if you can't seem to get the invite from any of the other kind people.

https://keybase.io/justinas

Re: Facebook and PGP

#38

The easy answer is that they knew Apple was going to come out strong for encryption in the past few days and wanted to do a "me too."

I'm totally OK with companies "me too"ing this particular feature.

Re: Facebook and PGP

#40

The easy answer is that they knew Apple was going to come out strong for encryption in the past few days and wanted to do a "me too."

Now if Apple does announce PGP/GPG support built into Mail in OS X and iOS, that would make this much more interesting.

I wonder if MS has made GPG support any easier in Outlook. Last I looked into it a year or two ago, it was hard to integrate unless you paid for the official PGP plug-in.

Post reply on HN