3 ms·
Your assertion is false. Please read the whitepaper. Facebook does not have the key to decrypt messages sent with Secret Conversations. It is generated on-devi
by sweis 6y ago
Your assertion is false. Please read the whitepaper.
Facebook does not have the key to decrypt messages sent with Secret Conversations. It is generated on-device. You can confirm that using simple reverse engineering tools on, say, the Android APK.
Yes, Facebook could subvert the binary by pushing an update. That is the risk you are accepting.
- stiray 6y agoThis is whitepaper, it is not implementation of closed source application. Let me explain how this works in PR world. You publish (with all the bells and whistles) that you have end to end encryption and explain protocol that uses asymmetric cryptography (just for the sake of simplicity I will simplify - you have public and private key, you send public key to all chatters with you, they will encrypt randomly generated symmetric key with it (asymmetric crypto is slow, you don't want to use it directly) and send it back (where you decrypt it) and vice versa. Then you use symmetric key that you have safely exchanged for use in block cypher, lets say Rijndael 265635238 bits (as big numbers mean more safety(tm) /s). You publish white papers of protocol, get all the cryptographers on your side. Fanboys are screaming, public is applauding, girls wants to sleep with you and president is thankful. What you don't tell is that you also encrypt symmetric key with YOUR public key that is embedded into application and send it along as a "status_check" field. And everyone is happy forever after. /s > Your speculation is not interesting to me. This works in both directions. But bottom line, whitepaper is not the application (and even if it would be, have fun reading http://www.underhanded-c.org/ http://www.underhanded-c.org/ or https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG and who has more motive as the corporation that profits from spying on everyone and everything). It is just as the name says. Whitepaper. "Timeo Danaos et dona ferentes" or maybe you will like this one more: "Trust is built in drops and lost in buckets" And you dont trust someone as Facebook or Google any more. They have lost trust in ship containers not buckets.
- sweis 6y agoYour speculation is not interesting to me. What is interesting to me are actual bugs and vulnerabilities that credible people have found and gotten fixed: https://link.springer.com/chapter/10.1007/978-3-319-63697-9_3 https://link.springer.com/chapter/10.1007/978-3-319-63697-9_...
- 52-6F-62 6y agoWith respect, I don't think the other commenter is deferring to Facebook's abilities and openness to resolve bugs in the cryptographic process, but pointing out ways they can continue to act that align with open questions from their past. e.g. https://www.cnet.com/news/facebook-bug-has-camera-activated-while-people-are-using-the-app/ https://www.cnet.com/news/facebook-bug-has-camera-activated-... Where the question arises: was it a bug that the camera was on, or that it was revealed inadvertently? Hence the discussion of trust in the client. That is an instance where Facebook lost some of that trust "in buckets". It's true that "shit happens", but when it "happens" reptitively the questions begin to emerge. I don't think that's unfair. I mean, I'm sure few people would use a stock Ford Pinto as their regular driver, regardless of Ford's intentions or engineering capabilities.
- HenryBemis 6y agoWhy we should never trust Facebook: 1) well.. their CEO is a scumbag. 2) not only the CEO is a scumbag, apparently there are plenty more where he came from (scumbagland??)of them in there: https://www.forbes.com/sites/davidphelan/2019/02/01/apple-blocks-google-and-facebook-ios-enterprise-certificates-now-restored/ https://www.forbes.com/sites/davidphelan/2019/02/01/apple-bl... That second point didn't "just" happen. It was organized. It was planned. It was tested. It was approved. It was rolled out. And I didn't read about 10-50-100 people quitting/getting fired after this fallout. So.. another day at work. This time they got busted. So with CA. So with experimenting on our psychology by manipulating order of showing posts (effectively cancelling out the chronological order). PS: and right when I thought I would only post positive messages on HN from now one.. a FB post comes up..!! PS2: I guess FB is useful to some. I wish them the best!! (there is a positive note!)
- sweis 6y agoThe original statement I had disputed was "[Facebook has] the keys to decrypt [Secret Conversations messages]", which is false. If you think the contrary, then the evidence is in the client.
- 6y ago
- Grustaf 6y ago> Yes, Facebook could subvert the binary by pushing an update. That is the risk you are accepting. That's exactly the kind of risk you should never accept when it comes to Facebook.
- mr_gibbins 6y agoSays the ex-Facebook engineer.