Live data from Hacker News

TikTok will not introduce end-to-end encryption, saying it makes users less safe

bbc.com

411–420 of 458 posts

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#411
post #360

Earlier quoted context omitted.

>I'm not aware of any news of them Yet. Until they say "We delete these messages after X time and they are gone gone, and we're not reading them" Assume they are reading them, or will read them and the information just hasn't got out yet. I mean we keep finding more and more cases where companies like FB and Google were reading messages years ago and it wasn't till now we found out.

> We delete these messages after X time They never had the plaintext of the messages in the first place, so they don't need to delete them. That's what end-to-end encrypted means.

They don't need the plaintext if they have your key. Since they wrote the application you have zero clue if they do or not.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#413

Earlier quoted context omitted.

Yes, but this leaves the only way to identify this behavior as by reporting from a minor. I'm not saying I trust TikTok to only do good things with access to DMs, but I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted. I'm not saying no E2E messaging apps should exist, but maybe it doesn't need to for minors in social media apps…

Are you suggesting all messaged photos should be scanned, and potentially viewed by humans, in case it depicts a nude minor? Because no matter how you do that, that would result in false positives, and either unfair auto-bans and erroneous reports to law enforcement (so no human views the images), or human employees viewing other adults' consensual nudes that were meant to be private. Or it would result in adult empl…

> Are you suggesting all messaged photos should be scanned, and potentially viewed by humans, in case it depicts a nude minor?

No, I was not suggesting that.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#414

Earlier quoted context omitted.

Yes, but this leaves the only way to identify this behavior as by reporting from a minor. I'm not saying I trust TikTok to only do good things with access to DMs, but I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted. I'm not saying no E2E messaging apps should exist, but maybe it doesn't need to for minors in social media apps…

> I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? People are paranoid about this sort of thing not because they think law enforcement is more effective when it is constrained. But how easil…

> Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant?

This is a false equivalency. I don't have to use TikTok DMs if I want E2EE. I don't have a choice about laws that allow the police to violate my rights. I'm not claiming that all E2EE apps should be banned.

> Right, but this is worlds apart from "sharing the encryption key with a private company", is it not?

Exactly why I suggested that as a possible alternative.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#415
post #211

I don’t really understand how we are supposed to believe in e2ee in closed proprietary apps. Even if some trusted auditor confirms they have plumbed in libsignal correctly, we have no way of knowing that their rendering code is free of content scanning hooks. We know the technology exists. Apple had it all polished and ready to go for image scanning. I suppose the only thing in which we can place our faith is that it…

I've been making this argument for a long time, and it's never popular. People want to believe in E2EE, it's almost like religion at this point. Protecting people is synonymous with E2EE, even if you cant verify it, and it can be potentially broken. I was even more controversial and singled out Signal as an example: https://blog.dijit.sh/i-don-t-trust-signal/

There are good reasons to not trust signal. The very first line of their privacy & terms page says "Signal is designed to never collect or store any sensitive information" but then they started collecting and permanently storing sensitive user data in the cloud and never updated that page. Much more recently they started collected and storing message content in the cloud for some users, but they still refuse to update that page. I'm pretty sure it's big fat dead canary warning users away from Signal. Any service that markets itself to whistleblowers and activists then also outright lies to them about the risks they take when using it can't be trusted for anything.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#416
post #378
post #274

Earlier quoted context omitted.

> The successor after the rebrand, is called myID [0], and advertised as: It's an identity scheme and SSO solution for accessing government services. As said at [0] in the "What is myID" section. I sincerely hope that they're using something standard and well tested like OIDC behind the scenes this time, because otherwise it's ripe for another fuckup like the one you linked. If it is also used for age verification th…

You should probably stop pretending you know what myID is, and what it does. Its a sovereign identity verification service. That is not limited to above PL2 verifications. There are age-only accredited entities in the registry. Its one of the approved verification tools for the Online Safety Act 2021 . It was renamed as part of the passage of the law. You're just not forced to use it, for verification. And yes, it do…

> No, uploading identity documents is never a safe process.

You should probably stop pretending you understand verifiable credentials then.

Because if you did, you'd understand that they don't need to involve uploading identity documents anywhere.

The idea is to defer to service providers such as banks that have already performed such verification, often physically. And if you want to argue that banks should stop verifying who people are when they open accounts... well that's going to be an interesting conversation.

Without doxxing myself too much, I'm going to say that I know intimately the details of a project within Australia to build a standards-based non-government VC system that won't touch a single piece of ID at any stage, as an additional capability on a commercial identity system that's already active and in use.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#417
post #208

Earlier quoted context omitted.

The receiver has a proven and signed bundle, that they can upload to the abuse report. So the evidence has even stronger weight. They can already decrypt the message, they can still report it.

Yes, but this leaves the only way to identify this behavior as by reporting from a minor. I'm not saying I trust TikTok to only do good things with access to DMs, but I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted. I'm not saying no E2E messaging apps should exist, but maybe it doesn't need to for minors in social media apps…

> I'm not saying no E2E messaging apps should exist, but maybe it doesn't need to for minors in social media apps. However, an alternative could be allowing the sharing of the encryption key with a parent so that there is the ability for someone to monitor messages.

The problem with that idea, that you are implying E2E should require age verification. Everyone should have access to secure end to end encryption.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#419
post #201

I think this is... fine? Am I just totally naive. I think it's fine to say "You don't really have privacy on this app" - as long as there are relatively good options of apps that do have privacy (and I think there are). TikTok is really a public by default type of social media, there's not much idea of mutual following or closed groups. So sure, you don't have privacy on tiktok, if you want it you can move to snapcha…

No, saying that e2e encryption makes users _less_ safe is completely dishonest, nothing is fine about this. The logic of "anything is better than before" is also fallacious.

It's a kind of Trojan horse propaganda in my opinion.

Users get used to the argument with TikTok and then apply it to other platforms.

Put it this way: why wouldn't those same arguments apply to any platform (if you believed them)?

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#420
post #185

Earlier quoted context omitted.

> If there's no particular problem with schemes that are like that then we don't necessarily need a blanket ban on age verification. There is a problem with schemes like that. The way computer security works is, attacks always get better, they never get worse. A scheme that nobody has found any privacy holes in when it's enacted will have one found a week after. The way governments work is, the compromise bill passes…

> There is a problem with schemes like that. /goes on to discuss how government legislation of specific schemes is the issue, not the schemes themselves. Then we don't legislate specific schemes? The GDPR doesn't do that, for instance, it spells out responsibilities and penalties but doesn't say "Though shalt use this specific algorithm". Remember, this discussion started with a call to ban all age checks , which its…

> Then we don't legislate specific schemes?

Except that you have to in this case because IDs are issued by the government and then it's the government having to provide some privacy-protecting means of using them, which is the thing they're incapable of in practice.

> There are ways that private entities can implement age checks both securely and without leaking much other information

I have yet to see a single one implemented in real life. People point to attempts and then you look at the implementation and it's full of dubious choices and unforced errors, before you even start looking for bugs.

Moreover, private entities have the perverse incentive to do the opposite of implementing it securely, because they find it profitable to track people, or find it unprofitable to spend the resources necessary to prevent themselves from being infiltrated by foreign governments when their business is the sort which is useful to them as these are.

Post reply on HN