Live data from Hacker News

Facebook and PGP

cs.columbia.edu

41–50 of 60 posts

Re: Facebook and PGP

#42
I think the nicest part of this is that account recovery e-mails are encrypted. I wish we'd see more of this.

While I'm cautious about facebook in general, it is (in essence) a repository for public data. A public key falls into that category, so they gain nothing more than the association of user and key. And in return, the PRISM databank has more superbly useless information to store and eventually 'collect' for 1EF communication.

And I gain immunity from account hijacking unless I mess up Key Management.

Re: Facebook and PGP

#43
post #27

Earlier quoted context omitted.

A little of topic, but if someone would like a invite to keybase let me know :-)

For anyone late, I have 9 invites. My details are on keybase: https://keybase.io/lekevicius

And if there's anyone even later, I've got a few as well: https://keybase.io/oddevan

Re: Facebook and PGP

#44
post #7

The last paragraph of the linked post describes more or less what keybase [1] is. [1] https://keybase.io/

A little of topic, but if someone would like a invite to keybase let me know :-)

And that is why I have no interest in keybase.io

Well that and they don't solve the only really interesting problem with GPG: how to send a secure email to somebody who doesn't yet have a private key.

Re: Facebook and PGP

#45
post #11

Earlier quoted context omitted.

Well, from what I know there are some seriously privacy minded people in there. As oxymoronic as that sounds. But I could certainly see some benefits both for FB and for world at large from this. One of the big problems with PGP is how to bootstrap web of trust. "Does this key really belong to this particular person?" But what if the otherwise loathed real name policy could be turned to service this particular need?…

Zuckerberg actually cares a lot about his privacy . Yours? Maybe not as much. http://www.slate.com/blogs/business_insider/2015/05/18/tech_... http://www.theguardian.com/technology/shortcuts/2015/may/19/... But isn't the PGP move a sign that Facebook cares about our privacy? Not really. The profile thing makes it easy to discover people who use PGP and email them with encrypted messages, but that has nothing to do wit…

If I remember correctly, Open whisper systems, makers of TextSecure app say that Whatsapp[1] uses the text secure protocol[2]. This means that chats are encrypted end to end. It doesn't seem to expose information to Alice when Bob's keys change though. So someone could coerce Whatsapp into changing the keys for Alice and Bob and MITM that way. However, if we are worried about that we should also be worried about a rogue agent just updating the binaries for Whatsapp to remove such privacy-conscious decisions.

I guess the prevailing notion (as the grand parent said) is that while Facebook couldn't give two shits about our privacy, there are people who work there who do care about privacy in general (and not just their own privacy). Of course, no Facebook employee is going to come out publicly and call Mark Zuckerberg for being a self-serving psychopathic douche bag.

[1] (owned by Facebook, I imagine the deal is complete by now)

[2] https://whispersystems.org/blog/whatsapp/

> The most recent WhatsApp Android client release includes support for the TextSecure encryption protocol, and billions of encrypted messages are being exchanged daily. The WhatsApp Android client does not yet support encrypted messaging for group chat or media messages, but we’ll be rolling out support for those next, in addition to support for more client platforms. We’ll also be surfacing options for key verification in clients as the protocol integrations are completed.

> WhatsApp runs on an incredible number of mobile platforms, so full deployment will be an incremental process as we add TextSecure protocol support into each WhatsApp client platform. We have a ways to go until all mobile platforms are fully supported, but we are moving quickly towards a world where all WhatsApp users will get end-to-end encryption by default.

Re: Facebook and PGP

#47

The easy answer is that they knew Apple was going to come out strong for encryption in the past few days and wanted to do a "me too."

Given that one event involves coding, testing, and real deployment while the other is Tim Cook giving a speech where he spins another tale of "in the future..." BS that is in no way supported by anything real yet, I think you have the order backwards here.

Re: Facebook and PGP

#48
post #26
post #11

Earlier quoted context omitted.

Well, from what I know there are some seriously privacy minded people in there. As oxymoronic as that sounds. But I could certainly see some benefits both for FB and for world at large from this. One of the big problems with PGP is how to bootstrap web of trust. "Does this key really belong to this particular person?" But what if the otherwise loathed real name policy could be turned to service this particular need?…

> But what if the otherwise loathed real name policy could > be turned to service this particular need? The link between a real person and a Facebook account isn't secure - I could make an account with your name today without too much stress (no need to provide ID unless Facebook thinks your name isn't a real name).

I think the grandparent chose the wrong end of the stick with relating this to "famous" people, which, in turn, threw you off.

Sure, you can register an account in my name, but there are quite a number of people who will not be fooled: people who actually know me. People who know me in real life can tell whether an account is real or not, because they can tell whether I post about things I do, whether I post pictures that are...well, me.

In that case, they can be reasonably sure that the account in question is, in fact, my account. If I attach my GPG key to this account, they can thus also reasonably assume that the GPG key belongs to the account that belongs to me. This essentially gets you the online equivalent of a key-sharing party.

Re: Facebook and PGP

#49
post #7

The last paragraph of the linked post describes more or less what keybase [1] is. [1] https://keybase.io/

I'm not a fan of Keybase because they encourage a lot of unsafe behaviour:

1. They tell you to trust webpages which claim that their code does not send passwords or private keys to the server – something which would be extremely hard to verify now and even were you to do so now, could silently change in the future:

https://www.dropbox.com/s/teikzwftimeu8nc/Screenshot%202015-...

https://www.dropbox.com/s/1xlvpd8drhix0tj/Screenshot%202015-...

2. They encourage blindly copying and pasting complex commands into a shell:

https://www.dropbox.com/s/5rv7p4mks0qdr7f/Screenshot%202015-...

I have no reason to believe they're doing any of this in malice but it's not good because it encourages people to believe claims which could be made by any phisher and encourages practices which put you at risk if Keybase is ever compromised.

The answer to this, of course, would be a browser-managed crypto API which could provide unspoofable UI indicating that e.g. a private key will never leave the client but in the absence of such an API it feels irresponsible to make similar claims which aren't actually possible.

Re: Facebook and PGP

#50
post #21

Has anyone got an encrypted email from facebook yet? I uploaded my key and ticked the box, but the last notification I got was still in the clear.

Hi. Someone else commented, but you should have received an encrypted verification email with a link. We don't want to start sending you encrypted notifications until we confirm you're actually able to read them.

If you click that verification link, you'll receive a web notification that it's enabled should start receiving encrypted notifications.

Check your spam folder in case your mail provider's or client's spam filter is mislabeling it.

If you don't see it, try unchecking and rechecking the opt-in box, which should trigger a new verification email. (We've had a feature request for a "Resend" button".)

Post reply on HN