6 ms·
Facebook Messenger already has Secret Conversations, which is end-to-end encrypted mode based on the Signal protocol. Here's the technical whitepaper: https:/
by sweis 6y ago
Facebook Messenger already has Secret Conversations, which is end-to-end encrypted mode based on the Signal protocol.
Here's the technical whitepaper:
https://about.fb.com/wp-content/uploads/2016/07/messenger-secret-conversations-technical-whitepaper.pdf https://about.fb.com/wp-content/uploads/2016/07/messenger-se...
Here's some of the academic work on messaging franking that it has driven: https://eprint.iacr.org/2017/664.pdf https://eprint.iacr.org/2017/664.pdf
Here's the instructions how to use it:
https://www.facebook.com/help/messenger-app/1084673321594605 https://www.facebook.com/help/messenger-app/1084673321594605
Of course, you need to trust that the client from the app store and no, the implementation is not open source.
- sweis 6y agoAlso, ZuccNet is using RSA-2048-OAEP to encrypt each message: https://github.com/tomquirk/zuccnet/blob/master/src/util/crypto.js#L57 https://github.com/tomquirk/zuccnet/blob/master/src/util/cry... This is not forward secure. It will also only work for messages under 256 bytes. I don't know what happens in this code if you exceed that message length. You want to use ephemeral session keys here. Read the Secret Conversations whitepaper as an example.
- stiray 6y agoIf you are trusting facebook in any matter, you are misunderstanding something. Whatever they say, they have the keys to decrypt it. It is like trusting the thief to guard your house. I dislike this "ZuccNet" as the real goal should be abandoning facebook ecosystem but I still think that anything for naive people is better than nothing, so thumbs up.
- sweis 6y agoYour assertion is false. Please read the whitepaper. Facebook does not have the key to decrypt messages sent with Secret Conversations. It is generated on-device. You can confirm that using simple reverse engineering tools on, say, the Android APK. Yes, Facebook could subvert the binary by pushing an update. That is the risk you are accepting.
- stiray 6y agoThis is whitepaper, it is not implementation of closed source application. Let me explain how this works in PR world. You publish (with all the bells and whistles) that you have end to end encryption and explain protocol that uses asymmetric cryptography (just for the sake of simplicity I will simplify - you have public and private key, you send public key to all chatters with you, they will encrypt randomly generated symmetric key with it (asymmetric crypto is slow, you don't want to use it directly) and send it back (where you decrypt it) and vice versa. Then you use symmetric key that you have safely exchanged for use in block cypher, lets say Rijndael 265635238 bits (as big numbers mean more safety(tm) /s). You publish white papers of protocol, get all the cryptographers on your side. Fanboys are screaming, public is applauding, girls wants to sleep with you and president is thankful. What you don't tell is that you also encrypt symmetric key with YOUR public key that is embedded into application and send it along as a "status_check" field. And everyone is happy forever after. /s > Your speculation is not interesting to me. This works in both directions. But bottom line, whitepaper is not the application (and even if it would be, have fun reading http://www.underhanded-c.org/ http://www.underhanded-c.org/ or https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG and who has more motive as the corporation that profits from spying on everyone and everything). It is just as the name says. Whitepaper. "Timeo Danaos et dona ferentes" or maybe you will like this one more: "Trust is built in drops and lost in buckets" And you dont trust someone as Facebook or Google any more. They have lost trust in ship containers not buckets.
- sweis 6y agoYour speculation is not interesting to me. What is interesting to me are actual bugs and vulnerabilities that credible people have found and gotten fixed: https://link.springer.com/chapter/10.1007/978-3-319-63697-9_3 https://link.springer.com/chapter/10.1007/978-3-319-63697-9_...
- 52-6F-62 6y agoWith respect, I don't think the other commenter is deferring to Facebook's abilities and openness to resolve bugs in the cryptographic process, but pointing out ways they can continue to act that align with open questions from their past. e.g. https://www.cnet.com/news/facebook-bug-has-camera-activated-while-people-are-using-the-app/ https://www.cnet.com/news/facebook-bug-has-camera-activated-... Where the question arises: was it a bug that the camera was on, or that it was revealed inadvertently? Hence the discussion of trust in the client. That is an instance where Facebook lost some of that trust "in buckets". It's true that "shit happens", but when it "happens" reptitively the questions begin to emerge. I don't think that's unfair. I mean, I'm sure few people would use a stock Ford Pinto as their regular driver, regardless of Ford's intentions or engineering capabilities.
- Moodles 6y ago> Whatever they say, they have the keys to decrypt it. This is a baseless assertion.
- arrosenberg 6y agoTrust is earned.
- seniorivn 6y agobut it is a safe assumption
- sweis 6y agoIt's a falsifiable assumption. Audit the binaries if you want to convince yourself. You will see code to generate and use keys locally, with no mechanism to fetch or share keys from a server. If you want to go beyond generic concerns, there are plenty of academic papers that have looked at Facebook Secret Conversations, found actual issues, and helped get them fixed: https://link.springer.com/article/10.1007/s00145-020-09360-1 https://link.springer.com/article/10.1007/s00145-020-09360-1 https://link.springer.com/chapter/10.1007/978-3-319-63697-9_3 https://link.springer.com/chapter/10.1007/978-3-319-63697-9_... https://link.springer.com/chapter/10.1007/978-3-319-96884-1_6 https://link.springer.com/chapter/10.1007/978-3-319-96884-1_...
- na85 6y agoWhy are you so eager to trust an organization that has so often demonstrated it's not worthy of trust? This is Facebook, for pete's sake. The same company that conducted psychological experiments with zero clinical/ethical oversight by manipulating its users' feeds to see if it could cause depression/anxiety (or the opposite). Facebook is evil and you should not trust them even a little bit.
- dmt0 6y agoHe is so eager, because he was a software engineer at Facebook. His site is in his profile.
- ballenf 6y agoThe metadata of our conversations is really more important than the content most of the time. Especially if FB is tracking the conversation participants before and after the chat. If we chat and then shortly there after you search for some fringe political group, it's pretty safe to see that as a strong indication that I'm involved with that group. Or if my geolocation places me at some political event and we chat during or just after it, you're implicated. FB doesn't need the contents of messages, they need the metadata plus all the other user tracking.
- matmann2001 6y agoFrom Facebook Secret Conversations FAQ: > If you think a message you've received in a secret conversation goes against our Community Standards, you can report it. Learn more about what a secret conversation is. When you report a secret conversation, recent messages from that conversation will be decrypted and sent securely from your device to our Help Team for review. We won't tell the person you're talking to that you reported it. Since Facebook's software is managing the keys, they have the ability to decrypt Secret Conversations. You have to trust Facebook not to snoop. Whereas w/ ZuccNet, the public keys can be exchanged via a separate channel from Facebook, thus rendering Facebook unable to snoop.