Live data from Hacker News

TikTok will not introduce end-to-end encryption, saying it makes users less safe

bbc.com

381–390 of 458 posts

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#381

I don’t really understand how we are supposed to believe in e2ee in closed proprietary apps. Even if some trusted auditor confirms they have plumbed in libsignal correctly, we have no way of knowing that their rendering code is free of content scanning hooks. We know the technology exists. Apple had it all polished and ready to go for image scanning. I suppose the only thing in which we can place our faith is that it…

We don't even know if the passwords aren't stored in plain text.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#382
post #314

Earlier quoted context omitted.

Email encryption for most people is sufficient even if the metadata is exposed. One can simply state in their email encryption "Bing Bing Bong" or "Why did you not put the trash out?" which might mean to the recipient :: "check the second SFTP server" or "let the cat outside" or "Jump on my private Mumble chat server" or "Get on my private self hosted IRC server" . The email message need not be encrypted for that mat…

yeah bro genius, that sounds like a totally actionable thing people will do all the time with email. Be sure to drink your ovaltine

yeah bro genius

I know, right? I admit that is mostly for people on Linux desktops. People on smart phones are 100% monitored regardless of encryption or fake E2EE that platforms pinky promise is really E2EE like Signal. Shame on Moxie, he knows better.

Ovaltine has a crapload of sugar. Don't drink that horse piss.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#383
post #314

Earlier quoted context omitted.

Email encryption for most people is sufficient even if the metadata is exposed. One can simply state in their email encryption "Bing Bing Bong" or "Why did you not put the trash out?" which might mean to the recipient :: "check the second SFTP server" or "let the cat outside" or "Jump on my private Mumble chat server" or "Get on my private self hosted IRC server" . The email message need not be encrypted for that mat…

So it's end to end encrypted except that third parties can see who you communicated with and when? Sure.

Exactly.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#385

Earlier quoted context omitted.

Ok, and? Presenting your ID at a number of IRL estamblishments also heavily reduces anonymity

The difference is that IRL establishments don't sell off that data to anyone else, nor do they have the ability to collate that data with data from other establishments to make a profile of you. (at least not yet)

If you think the nightclub that scans your driver's license magstripe isn't selling your data off, when they could be making money off of it? Between PatronScan,Intellicheck, Scantek, and TokenWorks, yeah a dingy bar where it's a dude visually checking isn't it, but a nightclub and quick swipe totally is.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#387
post #85
post #82

Earlier quoted context omitted.

It's a slippery slope. This is the next two steps into 1984. Once you start mandating this, there's no going back. The next generation will start associating wrongthink with government IDs. (Wait, we already do that, right?)

The Party doesn't care about the Proles, only the members of the Outer Party. I think that it's rather funny that people like to appeal to 1984 as if the only point of Mr. Orwell was that surveillance is bad, missing the entire point about stuff like the control of the language or the idea that the only self-justification of the (Inner) Party is power for the sake of power (see also: The Theory and Practice of Oligar…

Unfortunately, having totally missed the point, they still get the same number of votes as you do.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#388

Earlier quoted context omitted.

> Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? Police can access your home with a warrant. Police cannot access your E2EE DMs with a warrant.

Not answering my question! > Police cannot access your E2EE DMs with a warrant. They can and do, regularly. What they can't do is prevent you from deleting your DMs if you know you're under investigation and likely to be caught. But refusing to give up encryption keys and supiciously empty chat histories with a valid warrant is very good evidence of a crime in itself. They also can't prevent you from flushing drugs d…

> But refusing to give up encryption keys and supiciously empty chat histories with a valid warrant is very good evidence of a crime in itself.

Uh, it absolutely isn't? WTF dystopian idea is this?

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#389

Earlier quoted context omitted.

Tiktok has private messaging, and it is used by hundreds of millions of people. IMO no consumer service should have private 1:1 messaging without e2e. Either only do public messaging (ie. Like a forum), or implement e2e.

Tiktok has direct messages, they don't even call them private. It's better that they're honest about this, nobody should believe for a second that WhatsApp or FB messages are truly E2EE. DM on social media shouldn't be used for anything remotely private. It's a convenience feature, nothing more.

Way to dunk on OP I guess but nobody is playing semantics here, it's just whether people think this is a messaging channel with one intended recipient

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#390

Earlier quoted context omitted.

If you are a grown adult and dont do research on “messaging apps” (which Tik Tok is not) then thats really on you.

This viewpoint isn't a slippery slope, it's a runaway train. "You moved into a neighborhood with lead pipes? That's on you, should have done more research" "Your vitamins contained undisclosed allergens? You're an adult, and it didn't say it DIDN'T contain those" "Passwords stolen because your provider stored them in plaintext? They never claimed to store them securely, so it's really on you"

Legislating that everyone must always be safe regardless of what app they use is a one-way ticket to walled gardens for everything. This kind of safety is the rationale behind things like secure boot, Apple's App Store, and remote attestation.

Also consider what this means for open source. No hobbyist can ship an IM app if they don't go all the way and E2E encrypt (and security audit) the damn thing. The barriers of entry this creates are huge and very beneficial for the already powerful since they can afford to deal with this stuff from day one.

Post reply on HN