Live data from Hacker News

TikTok will not introduce end-to-end encryption, saying it makes users less safe

bbc.com

371–380 of 458 posts

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#371

I think this is... fine? Am I just totally naive. I think it's fine to say "You don't really have privacy on this app" - as long as there are relatively good options of apps that do have privacy (and I think there are). TikTok is really a public by default type of social media, there's not much idea of mutual following or closed groups. So sure, you don't have privacy on tiktok, if you want it you can move to snapcha…

> as long as there are relatively good options of apps that do have privacy (and I think there are) Once you have enormous network effect like TikTok has, you don't really have any free selection of alternative apps. You are free to use one, but you will be the only sad user over there. Regulations are needed that would force large platforms like TikTok and Instagram to enable federation, opening them up to actual co…

federation would never work. How would it work here? Either you are forcing tiktok to give pageviews to federations of spam, or you are letting tiktok decide which federations to work with, which essentially results in no federation.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#372
post #237

Earlier quoted context omitted.

The email protocols would like to have a chat with you.

You can bring your own encryption to that, and bring your own client to automate it.

I can bring my own encryption to tiktok as well. Has roughly the same usability and usage.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#373
post #314
post #286

Earlier quoted context omitted.

you can encrypt the content but not the metadata, not even the subject unless you use a customized client that encodes it (like deltachat which doesn't use a subject at all), but then you still have your email address exposed. for all intents and purposes email is not e2ee.

Email encryption for most people is sufficient even if the metadata is exposed. One can simply state in their email encryption "Bing Bing Bong" or "Why did you not put the trash out?" which might mean to the recipient :: "check the second SFTP server" or "let the cat outside" or "Jump on my private Mumble chat server" or "Get on my private self hosted IRC server" . The email message need not be encrypted for that mat…

So it's end to end encrypted except that third parties can see who you communicated with and when? Sure.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#374
post #236

Earlier quoted context omitted.

> It carries negative connotations Interesting I'm not a native English speaker but in news articles I have always interpreted "controversial" as meaning "under discussion" (perhaps even around a 50/50 divide) hence why they are writing an article about it. I feel it is the news outlet trying to justify why the topic is important to read about since most people reading it will interpret the issue at hand as having a…

It does have negative connotations. And it does get used by news corporations to influence opinion. I have rarely if ever seen them feel the need to explain why a topic they report is important or newsworthy, and just stating without evidence that something is controversial really doesn't either. > Usually it is used in topics that are very binary, for or against. It can be for those topics, but very rarely to descri…

[deleted]

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#376
post #314
post #286

Earlier quoted context omitted.

you can encrypt the content but not the metadata, not even the subject unless you use a customized client that encodes it (like deltachat which doesn't use a subject at all), but then you still have your email address exposed. for all intents and purposes email is not e2ee.

Email encryption for most people is sufficient even if the metadata is exposed. One can simply state in their email encryption "Bing Bing Bong" or "Why did you not put the trash out?" which might mean to the recipient :: "check the second SFTP server" or "let the cat outside" or "Jump on my private Mumble chat server" or "Get on my private self hosted IRC server" . The email message need not be encrypted for that mat…

yeah bro genius, that sounds like a totally actionable thing people will do all the time with email. Be sure to drink your ovaltine

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#378
post #274
post #240

Earlier quoted context omitted.

> I mean, your example of the ATO there isn't even an age verification thing, it's a defective clone of OIDC, so by that logic we should ban all SSO or identity delegation solutions? MyGovID _is_ an age verifier. Sorry. The successor after the rebrand, is called myID [0], and advertised as: > myID is a secure way to prove who you are online. --- > I'm not really sure what you're driving at. Clearly. You seem to think…

> The successor after the rebrand, is called myID [0], and advertised as: It's an identity scheme and SSO solution for accessing government services. As said at [0] in the "What is myID" section. I sincerely hope that they're using something standard and well tested like OIDC behind the scenes this time, because otherwise it's ripe for another fuckup like the one you linked. If it is also used for age verification th…

You should probably stop pretending you know what myID is, and what it does.

Its a sovereign identity verification service. That is not limited to above PL2 verifications. There are age-only accredited entities in the registry.

Its one of the approved verification tools for the Online Safety Act 2021 . It was renamed as part of the passage of the law. You're just not forced to use it, for verification.

And yes, it does it poorly, and does not follow a standard. Its using Vanguard's PAS behind the scenes [1], with extras ServiceNow tacked on. Until they rearchitect the entire damn thing.

So... As I might have doxxed myself a little just now... No, uploading identity documents is never a safe process. Its a king's hoard in treasure before nations that never sleep.

Name a provider, and there will be a breach, and it will continue to affect the victims most of their lives.

[1] https://www.sec.gov/enforcement-litigation/administrative-pr...

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#379
post #314

Earlier quoted context omitted.

Email encryption for most people is sufficient even if the metadata is exposed. One can simply state in their email encryption "Bing Bing Bong" or "Why did you not put the trash out?" which might mean to the recipient :: "check the second SFTP server" or "let the cat outside" or "Jump on my private Mumble chat server" or "Get on my private self hosted IRC server" . The email message need not be encrypted for that mat…

So it's end to end encrypted except that third parties can see who you communicated with and when? Sure.

I have never considered metadata a part of the term E2EE. It has always been about the message contents.

I understand that metadata is valuable information for spies/governments and that encrypting or hiding it is valuable for privacy. But if you use that definition, there are almost no E2EE protocols on the planet in use.

First and foremost, any protocol that uses Apple or Google push notifications is giving metadata to those organizations. Even Whatsapp, iMessage, Signal, Telegram private messages, all of that leaks metadata but the contents of messages are hidden from the provider.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#380
post #360

Earlier quoted context omitted.

> nobody should believe for a second that WhatsApp or FB messages are truly E2EE. Meta still tracks analytics which isn't good for privacy, but I'm not aware of any news of them or 3rd parties reading messages without consent of one of the 1st parties? Signal is probably much better though

>I'm not aware of any news of them Yet. Until they say "We delete these messages after X time and they are gone gone, and we're not reading them" Assume they are reading them, or will read them and the information just hasn't got out yet. I mean we keep finding more and more cases where companies like FB and Google were reading messages years ago and it wasn't till now we found out.

> We delete these messages after X time

They never had the plaintext of the messages in the first place, so they don't need to delete them. That's what end-to-end encrypted means.

Post reply on HN