7 ms·
How I wish this article's title was "Facebook Tells Barr it Can't Open up Encrypted Messages".
by plicense 7y ago
How I wish this article's title was "Facebook Tells Barr it Can't Open up Encrypted Messages".
- bonestamp2 7y agoFrom the content of the article it also seems like it maybe should have that title. In the body they say they won't open their messaging product to law enforcement. Nowhere does it suggest (or deny) they can open messages. Some clarity on this would be nice.
- ImminentFate 7y agoIf you read the article, it’s talking about not putting in a backdoor, and not Facebook saying “we have access to all encrypted messages, we’re just not giving them to you”. As it stands, they’re end-to-end encrypted so not even Facebook can’t see your messages, and that’s what Barr doesn’t like
- SilasX 7y agoWhy is everyone so confident Facebook hasn’t already backdoored it?
- bytematic 7y agoNot sure the fallout of the public finding out would be worth it over the value add of reading messages, maybe I'm wrong but that's how I would look at it.
- excalibur 7y agoThey have in a manner of speaking. The communication channel is still encrypted, they just run their surveillance algorithms directly on your device. https://www.forbes.com/sites/kalevleetaru/2019/05/05/facebook-just-gave-repressive-regimes-the-ultimate-surveillance-blueprint/ https://www.forbes.com/sites/kalevleetaru/2019/05/05/faceboo...
- throwaway824721 7y agoThat Forbes article was wrong: https://news.ycombinator.com/item?id=20587643 https://news.ycombinator.com/item?id=20587643
- driminicus 7y agoFacebook says in a hn post that the article is wrong, but I have no real reason to trust Facebook, given their track record.
- mentat 7y ago> if we ever did it would be quite obvious and detectable that we had done it. It's running in your device, you don't have to trust them if you have technical skill.
- driminicus 7y agoI have little desire to decompile every update and/or constantly analyse what their app is doing. They've proven to be untrustworthy on multiple occasions, and haven't given me much reason to think they've changed. They might convince me if they open their client and server code, but even then they're yet another walled garden only interested in keeping their monopoly by building inferior products and using regularly capture to prevent any competition from doing the same thing they did to MySpace.
- bduerst 7y agoYou can't read encrypted packages being sent by the app. The message telemetry could be bundled by the app with other telemetry and you wouldn't know despite your technical skill.
- badrequest 7y agoonly if you choose to believe Facebook it was
- SilasX 7y ago
- likpok 7y agoPeople regularly reverse engineer the Facebook apps to see what’s inside. (For example: Jane Wong)
- nighthawk24 7y agoDon't trust closed source software for encryption.
- tantalor 7y ago> they’re end-to-end encrypted so not even Facebook can’t see your messages Not quite. Facebook still controls the endpoints, so when you see the message so can they. This is obvious: you use their app to view the encrypted message, hence the app has access to the cleartext. https://en.wikipedia.org/wiki/Endpoint_security https://en.wikipedia.org/wiki/Endpoint_security
- fooker 7y agoThis seems like a extreme argument. If the app is not phoning home with the cleartext, this seems okay. You need some software to retrieve/read text anyway, so this becomes an exercise about trusting trust, etc.
- TimTheTinker 7y ago> This seems like a extreme argument. Not at all. Good security often involves some black-and-white thinking, which not everyone is accustomed to. If Facebook controls the endpoint, then they have the power to access the plaintext, full stop. Using their product (hopefully) implies a choice to trust them not to abuse such access.
- gimmeThaBeet 7y ago> Using their product (hopefully) implies a choice to trust them not to abuse such access. Which is what...they said?
- ip26 7y agoAlthough I argue the black-and-white "everyone is a potential adversary" thinking is misguided. Your threat model determines requisite security measures, and you usually have to trust someone. (Although Facebook should probably not be that someone)
- fooker 7y agoOk, what about the closed source hardware in the phones? Would you argue against all encryption because clearly the CPU maker has a similar access to all decrypted content?
- csunbird 7y agoAgreed. "Can't" implies they are unable to do it at all, which means they will not give the information to random LEO requests, because they simply can't. "Won't" implies they select who they want to give the data to, which mean they probably give that data to other actors, without users even knowing about it.
- pjkundert 7y agoIt's surprising to me that so many people give the benefit of the doubt to enterprises, when they (at huge effort and expense) emit "mealy-mouthed" rebuttals that leave open the possibility that they actually are doing evil. These people aren't stupid, and their legal and PR teams understand the fine details of the English language. It says what they mean to say, not what we wish it would say. They "Won't". Not that they "Can't".
- dsfyu404ed 7y ago>It surprising to me that so many people give the benefit of the doubt to enterprises, when they (at huge effort and expense) emit "mealy-mouthed" rebuttals that leave open the possibility that they actually are doing evil. And the alternative is an organization which has an absolutely stellar track record at not doing evil (obvious sarcasm should hopefully be obvious). Neither party is can be taken at at face value here.
- daveFNbuck 7y agoHow would a can't be possible here? They're being asked to modify the client code to enable surveillance. A client can't be secure against changes to its own code, and a protocol can't be secure against the client sharing the data it receives.
- brink 7y agoIt sounds like you're asking for a clickbait title.
- fareesh 7y agoIf I login to Facebook.com from any random device+browser, I seem to be able to read my "Facebook Messenger" history - maybe this is different if I use the Messenger app, but it seems like there's no E2EE here since I get the plaintext from anywhere. On WhatsApp there seems to be E2EE enabled but I have no idea what the keys are. A layperson definitely has no idea what the keys are. Could Facebook build an "NSA mode" where the old keys (K1) are quietly replaced with some known keys (K2) for a particular user at a particular timestamp T? This means that all messages before T are to be parsed by using K1 and all messages after T are to be parsed by using K2. As a WhatsApp user, would I even know if "NSA mode" has been enabled for my account? This would enable courts to allow surveillance for all future messages, but the old messages would still be E2EE. What if you involve Apple+Google into the mix and have them silently deploy a rogue update to a particular user's WhatsApp program - couldn't you just ask a court to write some kind of surveillance warrant which orders the 3 companies to work together to give the alphabet agency a way to remotely take the keys?
- ehnto 7y agoThat's exactly what the Assistance and Access Act of 2018 in Australia was for. It allows law enforcement to compel third parties to subvert encryption. This doesn't necessarily mean break the encryption itself, but could mean deploying a malicious update to a target device that keylogs or screen captures, or otherwise allows eavesdropping. Keep an eye out for similar bills in your respective governments, it passed without struggle in Australia despite the seemingly negative opinion the public and media had on the issue. https://www.homeaffairs.gov.au/about-us/our-portfolios/national-security/lawful-access-telecommunications/data-encryption https://www.homeaffairs.gov.au/about-us/our-portfolios/natio...
- jaywalk 7y agoFacebook Messenger conversations are not E2EE by default. When you start one, you have to choose "Secret" in order for E2EE to be applied. This is only available from the Messenger app on mobile devices.
- BelleOfTheBall 7y ago
- blackboxlogic 7y agoOr even "Barr Tells Facebook it Can't Open up Encrypted Messages"?