Live data from Hacker News

Meta Shuts Down End-to-End Encryption for Instagram Messaging

pcmag.com

61–70 of 235 posts

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#61

Put simply: I’ve talked to Apple engineers. Siri fell behind due to how good Apple’s privacy is. Everyone made fun of them for protecting them. This is exactly the opposite of that, where Mark is throwing you and your children under the bus again because he’s unoriginal and doesn’t know how to make money any other way than by getting all up in your business, statistically.

building new features on top of E2EE is genuinely hard, and I've seen many companies struggle to keep innovating while staying strictly E2EE.

Having seen multiple leading messaging/VoIP stacks from inside, the amount of engineering spent to work around various limitations of E2EE in real prod scenarios is insane, and even for simple every-day-use features metrics don't compare to the metrics of the same feature running without E2EE.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#62

I'm not sure if this meets the bar for substantive and thoughtful discussion, but this kind of corporate cowardice, enforced by unelected bureaucrats standing at the bully pulpit is only going to get worse as the noose tightens on the open web. The combination of hardware attestation and walled garden "app stores" is the end goal of most policymakers in this area, and it happens to suit the monopolists in Google and…

Do people expect that Instagram can't read their Instagram private messages? I don't think people expect that. And E2EE is not nearly as cheap as the HN crowd likes to pretend—how do those devices get those keys if not through a central service? Especially if one of them is a web browser?

>Do people expect that Instagram can't read their Instagram private messages? I don't think people expect that.

A deeper question is why we reached a point where people can't reasonably expect their communication to not be spied on.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#63

Earlier quoted context omitted.

I usually defend Siri, because I’m perfectly fine trading a little functionality for security. I prefer it that way.

No. "You have to unlock your iphone first" is such a hindrance to using Siri for anything more than setting timers and alarms. If you're doing anything that involves gloves or a mask or getting your hands messy, like in a kitchen or something, it is just so frustrating. How about making a toggle so I can choose to be slightly less locked down for Siri, and I take full responsibility if I get hacked because of it.

Settings > Apple Intelligence & Siri > Allow Siri When Locked

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#64

So don’t use Meta products if you care about privacy?

I think people feel this is the begining of the end.

Meta is part of the reason Signals E2EE spread and E2EE became ubiquitous in general.

Many governments have also turned against E2EE and I suspect it's gone from a shield where you can say we can't really help you get that data, to a constant pressure.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#65

Earlier quoted context omitted.

How would the keys get stored in the user's private browsing window? Do they lose all chat history when they log in on a private browsing window and then close it?

I don't know the technical details of that for sure, but I think the answer is that keys and chat history are stored on-device only; for example you lose your WhatsApp history if you don't restore a backup when moving to a new phone. If a messaging app is showing you message history in a private browsing window then perhaps the encryption key for that history is derived from your password or something like that; that…

If you log in to the app on one phone and then in a web browser should you still be able to see your messages in the web browser?

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#66

Earlier quoted context omitted.

No, because it's terrible. There's no need to break encryption to allow you to report a user. You'd just report via a copy of an excerpt of the conversation and leave the rest of your communication private. If the user can't tamper with the extraction of that excerpt, you can trust it is correct. You could even extract hashes from both the reporting party and the reported party and compare them with zero knowledge of…

You have you contrive a complex system involving zero knowledge proofs and a lot more work, rather than just being able to see on the server the message asking for a child to dance in their underwear directly makes their argument DoA?

Hashing a handful of strings and comparing them is incredibly simple. Not sure where you think the complexity lies. It is in fact so trivial I'm confident Claude Code can one-shot this.

But I'll humor the notion and say that, yes, I'd rather not let them see me dancing in my underwear unless I've explicitly decided to share it.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#67

Earlier quoted context omitted.

Apple feels like the only big tech company that remotely cares about its users. Thank god they make the best computer and OS too. I’m sure this will not be a popular take on HN however.

"Best" is subjective. But "caring about their users"? Their response to RtR alone shows they care about their margins more than their users.

Apple care about their users like a farmer cares about a herd of dairy cows.

Whereas Microsoft and Google care about their users like a farmer cares about a herd of pigs.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#68

Put simply: I’ve talked to Apple engineers. Siri fell behind due to how good Apple’s privacy is. Everyone made fun of them for protecting them. This is exactly the opposite of that, where Mark is throwing you and your children under the bus again because he’s unoriginal and doesn’t know how to make money any other way than by getting all up in your business, statistically.

[dead]

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#69

Put simply: I’ve talked to Apple engineers. Siri fell behind due to how good Apple’s privacy is. Everyone made fun of them for protecting them. This is exactly the opposite of that, where Mark is throwing you and your children under the bus again because he’s unoriginal and doesn’t know how to make money any other way than by getting all up in your business, statistically.

Do you know what Zuckerberg said in an interview? I think it was to Lex Fridman but I could be wrong "Apple hasn't come up with anything new in 20 years" Very likely in response to Apple's granularity. Poor Zuck can't steal people's credentials

I’m less impressed with Zuck every time I hear something new about him.

Apple has made incredible progress in the last 20 years, but almost none of that has been a brand new product. It has all been evolving the existing products and on building the world’s best supply chain and rearing incredible market share from Windows. To be clear, AirPods are a much bigger market than Nike shoes. Those, plus Apple Watch, iPad and Vision Pro are new in the last 20 years.

In the past 20 years, the Facebook website has evolved, but all of the other major investments by the company have been acquisitions. Instagram, WhatsApp, Oculus. Diem (or whatever that proprietary cryptocurrency was called) and the Metaverse were massive failures. I don’t know what to credit Meta for in the AI era except some of the LLAMA tooling and some open weights LLMs. CZI is doing cool things, but that’s Zuck’s private science company, not part of Meta.

Re: Meta Shuts Down End-to-End Encryption for Instagram Messaging

#70

Earlier quoted context omitted.

I don't know the technical details of that for sure, but I think the answer is that keys and chat history are stored on-device only; for example you lose your WhatsApp history if you don't restore a backup when moving to a new phone. If a messaging app is showing you message history in a private browsing window then perhaps the encryption key for that history is derived from your password or something like that; that…

If you log in to the app on one phone and then in a web browser should you still be able to see your messages in the web browser?

Sorry do you mean, that's how it works now, or, that's how you think it should work? Are you talking about Instagram or WA or something else?

edit: misread your message; if you have two sessions active at the same time, then yes I would expect both sessions to receive the same messages.

Post reply on HN