Earlier quoted context omitted.
And I think because of all the handholding we are left worse off.
Most people couldn't tell you how their car works, at least not enough to fix it. Is that handholding, too? People can't be knowledgable about everything. There's just too much information in the world, and too many different skills that could be learned, and not enough time. A carpenter can rely on power tools without understanding fully how the tools work, and it's fine, as long as the tools are made to safe standa…
TikTok will not introduce end-to-end encryption, saying it makes users less safe
441–450 of 458 posts
Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe
#442Earlier quoted context omitted.
Hasn't been true ANYTIME IN HISTORY. Hell it was well understood even by children that no conversation you had on the telephone was truly private. That's why cyphers were invented.
What are you talking about? It is illegal to tap people's phone lines or to interfere with mail. Are you saying people don't have a reasonable expectation of privacy even when it's illegal to be spied on?
The good thing about e2ee is that it probably makes the list of those with the ability to decrypt things encrypted e2e somewhat smaller. Fact is hacking can get to those keys. (i.e. state actor zero-click exploits your phone they are going to be able to get your private key and the messages in memory)
Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe
#443Earlier quoted context omitted.
What are you talking about? It is illegal to tap people's phone lines or to interfere with mail. Are you saying people don't have a reasonable expectation of privacy even when it's illegal to be spied on?
'Illegal' doesn't really mean anything in this, or any other, day and age when you are talking about the very rich, the very powerful, or the state. The good thing about e2ee is that it probably makes the list of those with the ability to decrypt things encrypted e2e somewhat smaller. Fact is hacking can get to those keys. (i.e. state actor zero-click exploits your phone they are going to be able to get your private…
This is a thread arguing about what the law should be.
> Fact is hacking can get to those keys.
Everything made by humans is fallible.
Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe
#444Earlier quoted context omitted.
Switch to what exactly?
If there is nothing else, then you as a customer has screwed up with it before, right? And then the entire strategy/philosophy is maybe to be reviewed?! Or, in other words: If there is no alternative, this is due to your own faults. Either deal with it, or find ways to undo your mistakes.
Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe
#445Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe
#446Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe
#447Have they stopped a kidnapping? A battery? A murder? Maybe they helped a court case? If we can’t see how the public is benefiting from this, we’re left to assume it’s mostly in TikTok’s benefit. They could be using messaging data to blackmail politicians for all we know!
Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe
#448Earlier quoted context omitted.
> Then we don't legislate specific schemes? Except that you have to in this case because IDs are issued by the government and then it's the government having to provide some privacy-protecting means of using them, which is the thing they're incapable of in practice. > There are ways that private entities can implement age checks both securely and without leaking much other information I have yet to see a single one i…
> it's the government having to provide some privacy-protecting means of using them Nope, not necessarily. > I have yet to see a single one implemented in real life. There are likely to be a lot more coming as the newer standards in this area were finalised last year. Online identity is a continually evolving space. > Moreover, private entities have the perverse incentive to do the opposite of implementing it securel…
Necessarily, in fact, for any system that uses a government ID, because that requires there to be some interface between the government ID and a private bureaucracy that the holder of the ID would be pressured into interacting with. If that interface allows the private party to e.g. learn who you are, instead of just your age, it's only the government that could replace it with one that didn't.
> There are likely to be a lot more coming as the newer standards in this area were finalised last year. Online identity is a continually evolving space.
Evolution is supposed to cause bad ideas to die. The problem with laws, such as the ones surrounding government identity documents, is that they regularly require bad ideas to live. Which is why the use of government ID should be minimized.
> Some do in some circumstances, but far from all.
They all have that incentive, because it leads to money, and money is an incentive.
It's possible to turn someone down who is offering you money, but we're dealing with large scale systems here, and then the incentives determine the averages.
> Others (often financial institutions) have wised up to PII being a liability rather than an opportunity and some are working on frameworks and capabilites in this space that don't involve any more storage or transfer of anyone's ID than already happens in banks.
We really need to get it to stop happening in banks. The fact that every single thing you buy using a digital payment method is tied to your government ID is a preposterously dangerous status quo to leave unchallenged.
Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe
#449Earlier quoted context omitted.
> No, uploading identity documents is never a safe process. You should probably stop pretending you understand verifiable credentials then. Because if you did, you'd understand that they don't need to involve uploading identity documents anywhere. The idea is to defer to service providers such as banks that have already performed such verification, often physically. And if you want to argue that banks should stop ver…
KYC rules require the banks collect those, and keep them on an online portal. This information is held by the ABA - hence why they were falsely accused because of the infostealer breach last year. I have absolutely not said banks should stop collecting ID. Collecting it in person is a fantastic idea. Holding it on an isolated network is difficult, but a good compromise, and banks are better suited to doing that than…
> But I expect the same result as Forticode.
What happened there? I can't find a lot of reference to it on the net other than "we make amazing security products" and then "entering liquidation", so clearly a lot went wrong!
It's always possible for people to make mistakes and do things badly, but I don't see "age verification" as some special case in the identity landscape that presents unique challenges. And the system is already in use without major issue (touch wood). Verifiable Credentials will be an addition to the platform at some point.
Re: TikTok will not introduce end-to-end encryption, saying it makes users less safe
#450Earlier quoted context omitted.
The government are able to access your conversations, data and connections with e2ee in place already. I don't see how not having e2ee would have an effect on that ability in any way.
Please provide proof for these claims.
Myth: End-to-end encryption (E2EE) is the only way to ensure robust cybersecurity.
Reality: E2EE carries its own risks and vulnerabilities. No single, standalone method achieves bulletproof cybersecurity.
Robust cybersecurity requires layering multiple, diligently managed security measures and best practices. Malevolent actors can exploit E2E encryption to avoid critical data security scanning, to allow malware inside a network or onto a device, and to evade law enforcement.
https://www.fbi.gov/how-we-investigate/lawful-access/lawful-...