Live data from Hacker News

Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

buzzfeednews.com

481–490 of 592 posts

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#481
post #299

Earlier quoted context omitted.

>Specifically Apple-related and North American examples? That's an oddly narrow goalpost. Apple shares user encryption keys with the Chinese government, for example, giving the Chinese government access to all iCloud pictures, messages, documents, videos, etc.

Do they? Shit, I thought that they’d set things up that sharing the key was extremely difficult if not impossible without access to the device? That’s disappointing if true, is there a good article on this?

AFAIK this is only true for Chinese citizens or people who bought their phone in China or something but it is still scary.

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#483
post #194

Earlier quoted context omitted.

Got any sources to cite for that watching and listening? Specifically Apple-related and North American examples?

>Specifically Apple-related and North American examples? That's an oddly narrow goalpost. Apple shares user encryption keys with the Chinese government, for example, giving the Chinese government access to all iCloud pictures, messages, documents, videos, etc.

That’s not accurate at all.

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#485

Earlier quoted context omitted.

It's like when the Republicans said in the 90s that you don't solve problems by throwing money at them. But that's exactly how many problems are solved.

Which is why US healthcare is the standard of the world. Because it’s so profitable. /s

Government solves problems with money. The US government spends little on healthcare, which causes citizens to spend more.

Perhaps I should clarify that the only way we are going to solve he healthcare issue in the US is by the government spending money on it.

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#486
post #389

Earlier quoted context omitted.

Terrorists can and will use steganography, which even the most advanced automated systems cannot detect. They want to surveil the public.

They don't even need to... You can have a correct implementation of RSA in like 20 lines of code. The cat was out of the bag 20 years ago.

Totally agree with the sentiment of your statement, but RSA is probably a terrible choice, especially if you want to get it done in 20 lines of code. This article explains it pretty well: https://blog.trailofbits.com/2019/07/08/fuck-rsa/

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#487
post #110

Earlier quoted context omitted.

> Facebook can read the messages at both ends This is why I believe that end-to-end encryption is not truly useful unless the source code of the clients is public, or the protocol is open. Any closed source client can read messages at the ends, or be forced to do so by an evil government. At the very least, they could open up XMPP compatibility again so that people could write their own open source clients for it. Au…

I've been bouncing around the idea of a fully decentralized end-to-end encrypted chat protocol for exactly this reason, but I've been afraid to work on it for precisely the reason this thread is being discussed. I know that if my name were attached to the project, I'd be facing all kinds of unwelcome scrutiny from the government and news agencies. I'd lose the very privacy I want to maintain by designing privacy-prot…

XMPP with OTR is exactly this. Facebook messager used to be compatible with XMPP.

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#488
post #110

Earlier quoted context omitted.

> Facebook can read the messages at both ends This is why I believe that end-to-end encryption is not truly useful unless the source code of the clients is public, or the protocol is open. Any closed source client can read messages at the ends, or be forced to do so by an evil government. At the very least, they could open up XMPP compatibility again so that people could write their own open source clients for it. Au…

It should be easier to detect if they're reading it at the ends because they'd then have to retransmit the data to Facebook with a different key.

I tried to read data transmitted between the facebook messenger app (on iOS) and facebook server but it's encrypted and if you set up a mitm proxy it refuses to transmit. Even if you trust the mitm proxy certificate in the OS settings.

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#489

Earlier quoted context omitted.

With respect to facebook in particular, they have had the means of reading the messages on either side for ages, even before it was required by law. iOS and Android both have "leaky sandboxing", where certain apps from the same publisher can read each other's data and memory, and Facebook added WhatsApp to its sandbox almost immediately after acquiring it, allowing the main Facebook and Messenger apps to read all the…

Any more reading on this?

I found that article: https://medium.com/@gzanon/no-end-to-end-encryption-does-not...

Re: Attorney General will ask Zuckerberg to halt plans for end-to-end encryption

#490

Earlier quoted context omitted.

"Facebook, which owns Facebook Messenger, WhatsApp, and Instagram, captures 99% of child exploitation" Reminds me of this story: "Back during World War II, the RAF lost a lot of planes to German anti-aircraft fire. So they decided to armor them up. But where to put the armor? The obvious answer was to look at planes that returned from missions, count up all the bullet holes in various places, and then put extra armor…

Imagine being able to design a plane, but not immediately recognizing that.

It was probably not the engineers doing this, but the politicians, officers and committees.
Post reply on HN