Live data from Hacker News

TikTok will not introduce end-to-end encryption, saying it makes users less safe

bbc.com

311–320 of 458 posts

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#311
post #154

Earlier quoted context omitted.

I actually think this would be easier to implement than many of the current ID verification methods I've seen being pushed. We already have the infrastructure for selling age restricted goods, this is nothing new. Manufacturers that are unable to restrict their hardware in a "child" mode don't have to do anything and could simply continue selling to adults only. It's obvious we're moving in a direction where we are g…

Would the parents comply though? Many of the restrictions work because most adults agree is OK. For example for alcohol, children could drink as much as they want at home, if adults would permit it. If most adults would be convinced there is an issue, one probably has enough lock-down modes even nowadays, not sure it is a "technical" problem.

At that point it's on the parents. We can't stop parents from giving their kids alcohol or drugs either. (Not saying internet access is necessarily on the same level as that but you get the point.)

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#312

Earlier quoted context omitted.

>Keeping children safe and prosecuting are too different concepts, only vaguely related. See also: That time the FBI took over a CSAM site and kept it running so they could nab a bunch of users.

Not necessarily saying what they did was right, but I think there's a strong utilitarian argument to be made that what they did in that case was, in fact, the best way to keep children safe. What's more dangerous? CSAM on the internet? Or actual child predators running loose?

That stuff spreads and re-spreads just like anything else people download off the internet. There's a pretty strong argument for shutting it down right away. IIRC most users were outside jurisdiction.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#313
post #207

> the controversial privacy feature used by nearly all its rivals "controversial" according to who? The NSA / GCHQ?

Listed in the article are the National Society for the Prevention of Cruelty to Children and the Internet Watch Foundation, which monitors and removes child sexual abuse material from the internet. The recent Meta lawsuits also mention opposition from the National Center for Missing and Exploited Children and Meta's own executives: Monika Bickert (head of content policy) and Antigone Davis (global head of safety). Bo…

Good to see this called out. The HN echo chamber has this really terrible habit of attributing any disagreement with the prevailing opinion here to big, shadowy forces with evil motives (billionaires, corporations, three letter agencies, politicians, etc) instead of facing the reality that sometimes well meaning people just have different values and priorities than us. Very rarely does that narrative get challenged directly.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#314
post #286
post #237

Earlier quoted context omitted.

You can bring your own encryption to that, and bring your own client to automate it.

you can encrypt the content but not the metadata, not even the subject unless you use a customized client that encodes it (like deltachat which doesn't use a subject at all), but then you still have your email address exposed. for all intents and purposes email is not e2ee.

Email encryption for most people is sufficient even if the metadata is exposed. One can simply state in their email encryption "Bing Bing Bong" or "Why did you not put the trash out?" which might mean to the recipient :: "check the second SFTP server" or "let the cat outside" or "Jump on my private Mumble chat server" or "Get on my private self hosted IRC server". The email message need not be encrypted for that matter.

The intended payload can be in an header-less encrypted file on a throw-away SFTP server in the tmpfs ram disk.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#315

I think this is... fine? Am I just totally naive. I think it's fine to say "You don't really have privacy on this app" - as long as there are relatively good options of apps that do have privacy (and I think there are). TikTok is really a public by default type of social media, there's not much idea of mutual following or closed groups. So sure, you don't have privacy on tiktok, if you want it you can move to snapcha…

Tiktok has private messaging, and it is used by hundreds of millions of people. IMO no consumer service should have private 1:1 messaging without e2e. Either only do public messaging (ie. Like a forum), or implement e2e.

Adding that private self hosted forums can permit uploads of encrypted files, encrypted with a pre-shared secret or a secret shared over a private self hosted Mumble voice chat server.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#316

Earlier quoted context omitted.

Not necessarily saying what they did was right, but I think there's a strong utilitarian argument to be made that what they did in that case was, in fact, the best way to keep children safe. What's more dangerous? CSAM on the internet? Or actual child predators running loose?

That stuff spreads and re-spreads just like anything else people download off the internet. There's a pretty strong argument for shutting it down right away. IIRC most users were outside jurisdiction.

Even if one more person was prosecuted it was worth it. If you shut down an illegal website a new one will show up a month later, with the same people involved, and you achieved nothing.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#317

Earlier quoted context omitted.

> Tiktok has direct messages, they don't even call them private. It may not be called that, but what are users expecting? Some folks may later be surprised when a warrant gets issued (e.g., from a divorce judge).

If you are a grown adult and dont do research on “messaging apps” (which Tik Tok is not) then thats really on you.

This viewpoint isn't a slippery slope, it's a runaway train.

"You moved into a neighborhood with lead pipes? That's on you, should have done more research" "Your vitamins contained undisclosed allergens? You're an adult, and it didn't say it DIDN'T contain those" "Passwords stolen because your provider stored them in plaintext? They never claimed to store them securely, so it's really on you"

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#318

Earlier quoted context omitted.

> WhatsApp iPhone syncs to iCloud unencrypted by default[1]. Not true. You must choose to enable it or not when you set up new phone. On mine it does not back up

If you must "choose to enable" encryption, that implies it's off by default. If so, GP's statement is accurate.

No, I mean you must select yes or no. can't use WhatsApp until you make a choice yourself.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#319

Earlier quoted context omitted.

>I think it's fine to say "You don't really have privacy on this app" Disagree. To analogize why: privacy isn't heated seats, *its seat belts*. Comfort features and preferences are fine to tailor to your customers and your business model. Jaguar targets a different market than Ford, and that's just fine. Safety features should be non-negotiable for all. Both Jaguar and Ford drivers merit the utmost protection against…

Tesla doesn't have parking sensors. They're a safety feature. There's lots of safety features in cars that are optional, we've got an entire rating system for the safety of cars. We're talking about an app that's controlled by the CCP, I do expect them to take a principled stance - stances like Taiwan is a part of China and you can't be openly critical of the leader of the party. They don't have the same principles a…

>We're talking about an app that's controlled by the CCP, I do expect them to take a principled stance

In the area of large scale internet service providers, who do you expect to take a principled stance, and why do you expect them to take it?

If the answer is, "nobody", then why keep singling out China? And if the answer isn't "nobody", then how do we apply the same pressures and principles to TikTok and other platforms that offer messaging?

This isn't some abstract concern. We know that WESTERN journalists, activists, and others have been murdered in acts of transnational repression that either began or were focused and abetted by communications surveillance aimed toward political dissidence. It seems incredibly naive to believe that current Western political and military leadership could ever be dissuaded from taking effective action (and such surveillance and repression campaigns certainly are effective) by moral qualms unsupported by strong checks and balances of accountability. In other words - this sort of repression most likely continues happening to journalists, activists, human rights lawyers, and other political dissidents, in our society, today. Enabled by the refusal of our service providers to protect us, their users.

It seems incredibly naive - civilization threateningly so - to write a pass to anyone, let alone Larry Ellison, for opting to deliberately expose "his" users to this risk. Nothing is OK about this dereliction of responsibility towards them.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#320
post #207

> the controversial privacy feature used by nearly all its rivals "controversial" according to who? The NSA / GCHQ?

Listed in the article are the National Society for the Prevention of Cruelty to Children and the Internet Watch Foundation, which monitors and removes child sexual abuse material from the internet. The recent Meta lawsuits also mention opposition from the National Center for Missing and Exploited Children and Meta's own executives: Monika Bickert (head of content policy) and Antigone Davis (global head of safety). Bo…

> Both executives mention the danger end-to-end encryption poses to children when attached to a social media graph

So the fact that we welded a messaging platform onto a global-child-discovery-service is bad? Sure. Not encrypting that messaging platform is sort of closing the barn door after the horse has gone walkabout

Post reply on HN