4 ms·
Because Facebook is known so well for their respect of privacy.
by noahbradley 11y ago
Because Facebook is known so well for their respect of privacy.
- ikeboy 11y agoThey're known for not lying through their teeth about what features they've implemented, like most large companies.
- lunula 11y agoThere are a lot of generalizations there. Do you have example of an audit showing that they have never misguided their users or represented their product and motivations?
- ikeboy 11y agoNo, and the burden of proof would be on you if you're claiming it's likely that they're lying. Edit: my broad claim is basically that companies won't lie about what their products do, if their claims are specific. In this case, they released a whitepaper with technical details. If a company makes a broad unspecific claim, it's possible to be wrong or misleading without the implication of a deliberate lie by the company. In this scenario, it's not possible for it be wrong without a direct decision to lie, and therefore I think the reputational damage would be great if exposed, and it would be easily exposed by analysing network traffic before long. What I'm claiming in the specific here is that "the system implemented matches what the whitepaper says". I wouldn't put it beyond facebook to backdoor it in a way that's hard to figure out (with the backdoor included in the whitepaper ala Dual_EC_DRBG), but I'd consider that to be unlikely (firstly because there are actual humans behind it at the end of the day, and I'd hope that they would feel that "claim to release encryption but put a backdoor in" is morally worse than just not releasing encryption at all, and secondly because Whisper systems is involved). But all of that could arise in an open source system as well. What I have high confidence in is that the system matches the whitepaper. (There's also the possibility of an implementation problem that preserves plausible deniability for them, which I also consider unlikely.) All in all, reducing their grade by 1 point to account for additional risk in closed source seems reasonable to me.