Live data from Hacker News

Meta Shuts Down End-to-End Encryption for Instagram Messaging

pcmag.com

51–60 of 235 posts

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#53

Put simply: I’ve talked to Apple engineers. Siri fell behind due to how good Apple’s privacy is. Everyone made fun of them for protecting them. This is exactly the opposite of that, where Mark is throwing you and your children under the bus again because he’s unoriginal and doesn’t know how to make money any other way than by getting all up in your business, statistically.

I usually defend Siri, because I’m perfectly fine trading a little functionality for security. I prefer it that way.

No. "You have to unlock your iphone first" is such a hindrance to using Siri for anything more than setting timers and alarms. If you're doing anything that involves gloves or a mask or getting your hands messy, like in a kitchen or something, it is just so frustrating. How about making a toggle so I can choose to be slightly less locked down for Siri, and I take full responsibility if I get hacked because of it.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#54

Earlier quoted context omitted.

Apple feels like the only big tech company that remotely cares about its users. Thank god they make the best computer and OS too. I’m sure this will not be a popular take on HN however.

“But I want my freedom, I want to install whatever I want, bad Apple for locking down my devices away from me.” They stay rather secure because of all these measures. But they’ll get dismantled, too. Because idiots push idiots in power to weaken Apple’s stance. Useful idiots is the right term.

Being in a prison cell is a great way to avoid traffic accidents, I agree.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#55

Earlier quoted context omitted.

Can you steelman TikTok's argument?

No, because it's terrible. There's no need to break encryption to allow you to report a user. You'd just report via a copy of an excerpt of the conversation and leave the rest of your communication private. If the user can't tamper with the extraction of that excerpt, you can trust it is correct. You could even extract hashes from both the reporting party and the reported party and compare them with zero knowledge of…

You have you contrive a complex system involving zero knowledge proofs and a lot more work, rather than just being able to see on the server the message asking for a child to dance in their underwear directly makes their argument DoA?

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#56

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exc... If Meta are turning it off then I guess it's reasonable to assume that there is something to turn off.

How would the keys get stored in the user's private browsing window? Do they lose all chat history when they log in on a private browsing window and then close it?

I don't know the technical details of that for sure, but I think the answer is that keys and chat history are stored on-device only; for example you lose your WhatsApp history if you don't restore a backup when moving to a new phone.

If a messaging app is showing you message history in a private browsing window then perhaps the encryption key for that history is derived from your password or something like that; that can be done locally so that all the server ever sees is encrypted data.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#57

Earlier quoted context omitted.

The fly in the ointment is that they control the software and updates to that closed software so can short circuit that with appropriate pressure.

That would seem to constitute Honest Services Fraud under federal law, if they promised E2E then sabotaged it intentionally…

Not in the case of mandated back doors and warrants.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#58

Put simply: I’ve talked to Apple engineers. Siri fell behind due to how good Apple’s privacy is. Everyone made fun of them for protecting them. This is exactly the opposite of that, where Mark is throwing you and your children under the bus again because he’s unoriginal and doesn’t know how to make money any other way than by getting all up in your business, statistically.

People are bozos for wanting more from a glorified egg timer. I like Siri myself.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#59
post #36

Earlier quoted context omitted.

And how does one verify that the public key received belongs to the intended party, rather than a mitm? If the answer is blind trust in a third party that runs the messaging service then I suspect that you can guess what the people asking those questions are really asking.

https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exc... If Meta are turning it off then I guess it's reasonable to assume that there is something to turn off.

Diffe-Hellman-Merkel key exchange is vulnerable to attacker-in-the-middle attacks.

Eave could just do key negotiation with Alice and separately do key negotiation with Bob. You have to use a slightly more complicated cryptographic protocol to avoid this issue.

Post reply on HN