4 ms·
Reasons from not enabling it by default by @alexstamos (CSO @ Facebook): - FBM is multi-device, and we'd like to see E2E usability improve to support this. For
by Techbrunch 10y ago
Reasons from not enabling it by default by @alexstamos (CSO @ Facebook):
- FBM is multi-device, and we'd like to see E2E usability improve to support this. For now, pick one device and keys never leave it
- Secret conversations don't currently support popular features like searching message history, switching devices, voice/video, etc
- Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routing through mobile.
"We don't want to disrupt people's current experience."
Source: https://twitter.com/alexstamos https://twitter.com/alexstamos
- microcolonel 10y agoGiven that I don't have a smartphone, and use messenger.com; yeah, I wouldn't want it to require a mobile.
- lorenzhs 10y agoDownvotes for not owning a smartphone? I think we can agree that not requiring a mobile phone to use a messenger is a nice feature.
- lorenzhs 10y agoSome notes: - Signal does have some multi-device support (the Android and Desktop clients, iOS not yet). I still sometimes have minor issues but overall it works very well. - Signal does include end-to-end encrypted voice calls (what used to be called RedPhone) that also work quite well. It's my go-to "call from Wifi abroad" solution to avoid roaming charges, and also works very well with a good 4G/3G signal - The browser issue seems unsolved as of now, WhatsApp's web thingy (routing through the phone) seems to work quite well but obviously only if the phone is on, and WhatsApp requires a phone while FB messenger doesn't so this isn't an option for them.
- moxie 10y agoSignal Protocol already supports multi-device. We've encouraged them to enable that for Secret Conversations, and hopefully they'll continue to iterate towards support for e2e by default.
- nileshtrivedi 10y agoThat's nice! :) What did the OP mean by "No secure way to verify code or store keys (in web browser) without routing through mobile" ?
- pilif 10y agoThere's no way for a site to securely store keys in the browser. The server can't put them there because then the server would have them too. A client-side script could generate them, but it can't store them without extensions (or the server via some JS it sends) also having access to them. This is why Signal and WhatsApp require the client to run on the phone - the phones are doing the decryption for the web apps. This is flaky, consumes a lot of battery and generally is somewhat error-prone - probably not something FB wants to deal with.
- nileshtrivedi 10y agoServer would have the keys _because_ the client-side code can send it to the server. That's also possible in the native app, isn't it?
- pilif 10y agoYes. But let's assume FB doesn't want the keys (because if they have them, then it's no longer E2E encryption), then client-side generated keys in a browser are still exposed to XSS attacks and extensions. Installing a malicious extension, tricking users into typing commands in the developer tools, XSSing FB, all of these are much easier to do than attacking a native app on a phone.
- aianus 10y agoHow is the possibility of XSS worse than the status quo (plaintext)? Thats like saying SSL is useless on desktop because root kits and keyloggers exist on desktop.
- deleted 10y ago[deleted]