Live data from Hacker News

TikTok will not introduce end-to-end encryption, saying it makes users less safe

bbc.com

431–440 of 458 posts

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#431
post #416
post #378

Earlier quoted context omitted.

You should probably stop pretending you know what myID is, and what it does. Its a sovereign identity verification service. That is not limited to above PL2 verifications. There are age-only accredited entities in the registry. Its one of the approved verification tools for the Online Safety Act 2021 . It was renamed as part of the passage of the law. You're just not forced to use it, for verification. And yes, it do…

> No, uploading identity documents is never a safe process. You should probably stop pretending you understand verifiable credentials then. Because if you did, you'd understand that they don't need to involve uploading identity documents anywhere. The idea is to defer to service providers such as banks that have already performed such verification, often physically. And if you want to argue that banks should stop ver…

KYC rules require the banks collect those, and keep them on an online portal. This information is held by the ABA - hence why they were falsely accused because of the infostealer breach last year.

I have absolutely not said banks should stop collecting ID. Collecting it in person is a fantastic idea. Holding it on an isolated network is difficult, but a good compromise, and banks are better suited to doing that than most.

Uploading it to a S3 bucket in Sydney, as the ABA do, is a moronic decision. That myID upload it to a Azure Blob in Sydney, is worse than I feel the need to explain.

If you think you can succeed, where literally no one else in the world has, good luck to you. But I expect the same result as Forticode.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#432

Earlier quoted context omitted.

Not answering my question! > Police cannot access your E2EE DMs with a warrant. They can and do, regularly. What they can't do is prevent you from deleting your DMs if you know you're under investigation and likely to be caught. But refusing to give up encryption keys and supiciously empty chat histories with a valid warrant is very good evidence of a crime in itself. They also can't prevent you from flushing drugs d…

> But refusing to give up encryption keys and supiciously empty chat histories with a valid warrant is very good evidence of a crime in itself. Uh, it absolutely isn't? WTF dystopian idea is this?

It certainly can be - destruction of evidence is a crime. If they can prove you destroyed evidence, even if they can't prove that the destroyed evidence incriminates you, that's criminal behaviour. For instance if it's known by some other means you have a conversation history with person X, but not whether that conversation history is incriminating, and then when your phone is searched the conversation history is completely missing, that is strong evidence of a crime.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#433

Earlier quoted context omitted.

> I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? People are paranoid about this sort of thing not because they think law enforcement is more effective when it is constrained. But how easil…

> Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? This is a false equivalency. I don't have to use TikTok DMs if I want E2EE. I don't have a choice about laws that allow the police to violate my rights. I'm not claiming that all E2EE apps should be banned. > Right, but this is worlds apart from "sharing the encryption key with a…

> This is a false equivalency.

I'm not making an equivalency. I'm just trying to get you to think how something that is at surface level true is not necessarily a "fair argument".

> I don't have to use TikTok DMs if I want E2EE.

I don't know why you think this is a convincing argument. It is currently illegal to tap people's phone lines, but when phones were invented it obviously was not illegal. It became illegal in part because people had a reasonable expectation of privacy when using the phone. They also have a reasonable expectation of privacy when using TikTok DMs - that's why people call them "private messages" so often!

> Exactly why I suggested that as a possible alternative.

My point is that you are offering these as alternatives when they are profoundly different proposals. It is like me saying I am pro forced sterilization and then offering as an alternative "we could just only allow it when people ask for it". That's a completely different thing! Having autonomy over your online life as a family rather than necessarily as an individual is totally ok. Surrendering that autonomy is not.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#434

Earlier quoted context omitted.

I don't think you confused anything, except for the terminology the platform uses. There is an obvious expectation of privacy when sending direct messages!

Hasn't been true ANYTIME IN HISTORY. Hell it was well understood even by children that no conversation you had on the telephone was truly private. That's why cyphers were invented.

What are you talking about? It is illegal to tap people's phone lines or to interfere with mail. Are you saying people don't have a reasonable expectation of privacy even when it's illegal to be spied on?

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#435
post #256

Earlier quoted context omitted.

> I think it's a fair argument in this scenario to say that a platform has a better opportunity to protect minors if messages aren't encrypted Would it be a fair argument to say the police have a better opportunity to prevent crimes if they can enter your house without a warrant? People are paranoid about this sort of thing not because they think law enforcement is more effective when it is constrained. But how easil…

Yes, that is a fair argument and most countries allow the use of surveillance cameras in public for this reason.

in public is the operative word (and surveillance cameras in public are extremely recent and very controversial, so not as strong an argument as you might be thinking)

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#436
post #321
post #193

Earlier quoted context omitted.

> They should just have no DM feature at all, then; make all messages publicly visible. This makes no sense. I can discuss something in a bar which is not a very private conversation, I wouldn't care if someone else hear what I'm saying. But I also don't want someone to record it and post it on the internet to be seen by the whole world. Privacy is not just boolean you toggle somewhere.

In a bar you're not speaking directly into a microphone that is permanently saving everything you say for later instant access by every government and advertising agency that wants to prosecute you or invade your privacy to sell you something

Exactly.

You didn't mention the fact that my mom cannot access the recording of my microphone.

That's what ThoAppelsin is proposing.

It should be fairly implicit that if you are using a free product from a private company you are the products.

However it's definitely not implicit that every I do on the platform will get publicly known by everyone else. If it does I would probably not use it and find alternatives.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#437

I think this is... fine? Am I just totally naive. I think it's fine to say "You don't really have privacy on this app" - as long as there are relatively good options of apps that do have privacy (and I think there are). TikTok is really a public by default type of social media, there's not much idea of mutual following or closed groups. So sure, you don't have privacy on tiktok, if you want it you can move to snapcha…

Tiktok has private messaging, and it is used by hundreds of millions of people. IMO no consumer service should have private 1:1 messaging without e2e. Either only do public messaging (ie. Like a forum), or implement e2e.

I don't disagree with providing people with more privacy, but what you present is a false dichotomy.

For a long time we lived with private messages over SMS that were easily readable by third parties.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#438

Earlier quoted context omitted.

If you are a grown adult and dont do research on “messaging apps” (which Tik Tok is not) then thats really on you.

This viewpoint isn't a slippery slope, it's a runaway train. "You moved into a neighborhood with lead pipes? That's on you, should have done more research" "Your vitamins contained undisclosed allergens? You're an adult, and it didn't say it DIDN'T contain those" "Passwords stolen because your provider stored them in plaintext? They never claimed to store them securely, so it's really on you"

I once publicly stated it's understandable that someone would post an ad that says "No YouTubers" because people don't want to be content for others. The reply I got was "but you're being recorded all the time anyway", as if those are remotely related.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#439

Earlier quoted context omitted.

> We delete these messages after X time They never had the plaintext of the messages in the first place, so they don't need to delete them. That's what end-to-end encrypted means.

Whether Facebook/Meta can read the plain text of the messages or not depends on whether that encryption is "zero knowledge" or not, aka: does Facebook generate and retain the private encryption key, or does it stay on the users' devices only, never visible to Facebook or stored on Facebook servers? In the former case, Facebook can decrypt the messages at will, and the e2ee only protects against hackers, not Facebook…

They use the Signal protocol. The keys are not generated by Facebook, and are never on their servers. They are generated on the devices themselves.

Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe

#440

Earlier quoted context omitted.

And I think because of all the handholding we are left worse off.

Most people couldn't tell you how their car works, at least not enough to fix it. Is that handholding, too? People can't be knowledgable about everything. There's just too much information in the world, and too many different skills that could be learned, and not enough time. A carpenter can rely on power tools without understanding fully how the tools work, and it's fine, as long as the tools are made to safe standa…

And I never said that people should be knowledgeable about everything...

... and this is not what I was referring to either.

Less handholding -> more learning... but even then, what I meant is that you do not have to be knowledgeable to know that your "private messages" are not really encrypted and can be read by the admin (in case of forums, for one), and so forth.

Post reply on HN