Live data from Hacker News

Meta Shuts Down End-to-End Encryption for Instagram Messaging

pcmag.com

41–50 of 235 posts

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#41

Earlier quoted context omitted.

This is awful. They are doing this so they can literally advertise to kids. I bet their dbs aren't encrypted at rest either. Complete foolishnes

Can you steelman TikTok's argument?

No, because it's terrible. There's no need to break encryption to allow you to report a user. You'd just report via a copy of an excerpt of the conversation and leave the rest of your communication private. If the user can't tamper with the extraction of that excerpt, you can trust it is correct. You could even extract hashes from both the reporting party and the reported party and compare them with zero knowledge of the actual conversation.

More sophisticated HNers can chime in with zero-knowledge proofs and whatnot to show that their argument is DOA.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#42
post #36

Earlier quoted context omitted.

The answer to most everyone question you’re asking is just, “public key cryptography”. It’s kind of disheartening to me that such basic 1990s tech as implemented by Phil Zimmerman is now obscure enough to merit questions like this. Both parties exchange public keys through the central service. Only the possessor of the respective (on device, Secure Enclave ideally) private keys can decrypt the messages encrypted to t…

And how does one verify that the public key received belongs to the intended party, rather than a mitm? If the answer is blind trust in a third party that runs the messaging service then I suspect that you can guess what the people asking those questions are really asking.

https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exc...

If Meta are turning it off then I guess it's reasonable to assume that there is something to turn off.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#43

Earlier quoted context omitted.

The answer to most everyone question you’re asking is just, “public key cryptography”. It’s kind of disheartening to me that such basic 1990s tech as implemented by Phil Zimmerman is now obscure enough to merit questions like this. Both parties exchange public keys through the central service. Only the possessor of the respective (on device, Secure Enclave ideally) private keys can decrypt the messages encrypted to t…

The fly in the ointment is that they control the software and updates to that closed software so can short circuit that with appropriate pressure.

Throwing this on the "brainstorm if we had an ideal legislative world" pile: Stealing a user's private key should be a felony, even if it hasn't (yet) been abused for anything.

The tricky part is keeping it from being "permitted" by a crappy contract of adhesion. Banning it entirely would make it very difficult to buy/sell backup services...

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#44
post #36

Earlier quoted context omitted.

The answer to most everyone question you’re asking is just, “public key cryptography”. It’s kind of disheartening to me that such basic 1990s tech as implemented by Phil Zimmerman is now obscure enough to merit questions like this. Both parties exchange public keys through the central service. Only the possessor of the respective (on device, Secure Enclave ideally) private keys can decrypt the messages encrypted to t…

And how does one verify that the public key received belongs to the intended party, rather than a mitm? If the answer is blind trust in a third party that runs the messaging service then I suspect that you can guess what the people asking those questions are really asking.

> And how does one verify that the public key received belongs to the intended party, rather than a mitm?

Fingerprints. Again, this is like Crypto 101. Not saying that as a personal attack of any kind, I just remain incredulous that what used to be entry level knowledge in “our thing” has evidently become so obscure.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#45

Put simply: I’ve talked to Apple engineers. Siri fell behind due to how good Apple’s privacy is. Everyone made fun of them for protecting them. This is exactly the opposite of that, where Mark is throwing you and your children under the bus again because he’s unoriginal and doesn’t know how to make money any other way than by getting all up in your business, statistically.

Apple feels like the only big tech company that remotely cares about its users. Thank god they make the best computer and OS too. I’m sure this will not be a popular take on HN however.

"Best" is subjective. But "caring about their users"? Their response to RtR alone shows they care about their margins more than their users.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#46

Earlier quoted context omitted.

The answer to most everyone question you’re asking is just, “public key cryptography”. It’s kind of disheartening to me that such basic 1990s tech as implemented by Phil Zimmerman is now obscure enough to merit questions like this. Both parties exchange public keys through the central service. Only the possessor of the respective (on device, Secure Enclave ideally) private keys can decrypt the messages encrypted to t…

The fly in the ointment is that they control the software and updates to that closed software so can short circuit that with appropriate pressure.

That would seem to constitute Honest Services Fraud under federal law, if they promised E2E then sabotaged it intentionally…

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#47
post #36

Earlier quoted context omitted.

And how does one verify that the public key received belongs to the intended party, rather than a mitm? If the answer is blind trust in a third party that runs the messaging service then I suspect that you can guess what the people asking those questions are really asking.

https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exc... If Meta are turning it off then I guess it's reasonable to assume that there is something to turn off.

How would the keys get stored in the user's private browsing window? Do they lose all chat history when they log in on a private browsing window and then close it?

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#48
I worked at Instagram during this (not at the EeE, but saw enough of it, to see that it was a mess).

I think the reason for dropping it, is more of a technical issue and user experience, rather than a 'desire' issue or company will. From my understanding, Zuck wanted this. The implementation was a mess, and folks have different expectations about messages to appear at every platform. Having messages disappear between devices/web, or having to back up encryption, keys, etc... it was just a terrible user experience. Even employees, disliked this feature.

This was not something actually asked by users, but more of a feature done in order to thwart all the types of legal issues created when folks use the platform.

At some point, I counted, there were 64 'leads', just to make this happen. Each lead, had a certain area, or surface/views, which means we are talking about hundreds of folks involved to make this happen (across fb and ig).

It was a boodongle, and it was something that users didn't ask.

Ps. I know, many here at HN really care about this, but the average user was not willing to put up with the degradation of the user experience in order to make this happen. All workarounds, require weakening E2E, which made it pointless.

Ultimately, If you want a truly E2E, you will have to use a platform specifically made for it. IG/FB are just not it.

Even Telegram, doesn't have it enabled by default, unless you specifiy it.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#49

Earlier quoted context omitted.

I usually defend Siri, because I’m perfectly fine trading a little functionality for security. I prefer it that way.

Same. The fact they're shoving AI into it and expanding it to providers who don't have privacy as a guiding principle is a key reason I'm sitting on a 14 Pro still, and why I'm exploring local alternatives with Home Assistant. Besides, we just need to set verbal timers and control music. We don't need a full-blown verbal Oracle.

By disabling Apple "Intelligence" you bypass the risk of your prompts going to OpenAI.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#50

Earlier quoted context omitted.

> The authority holds Meta responsible anyway What form of accountability are you suggesting is even being leveraged, here? No law could force Meta to backdoor its encryption, afaik. Public pressure would be unlikely to work. Is Meta afraid of anything real, or is this just blame shifting via ungrounded speculation?

They can because Meta has chosen to implement e2e encryption. They could have chosen not to implement e2e encryption. All within their controls. Australia already has this law in place where a company must hand over user's conversation. A company cannot make an excuse that they themselves implement e2e to prevent themselves from reading user's messages. Source: https://www.bbc.com/news/world-australia-46463029 UK has…

> Public pressure works to a certain degree. Do you think a product manager at Meta would want to be labeled as "protecting pedos"?

I think that Meta can afford as much PR as they would need to out-message this sort of BS, again if they were inclined to protect user privacy in the first place. Look at Apple.

Post reply on HN