7 ms·
> On one hand, it seems everybody wants more freedom and less surveillance, but they give FB a hard time for not monitoring content better. I don't think these
by lowkey_ 5y ago
> On one hand, it seems everybody wants more freedom and less surveillance, but they give FB a hard time for not monitoring content better.
I don't think these are conflicting views:
(1) Less monitoring on private messages
(2) More monitoring on public posts
- PragmaticPulp 5y ago> 1) Less monitoring on private messages The Facebook leaker is explicitly arguing against this though. She cites Facebook’s push for end-to-end encryption of private messages as a problem.
- ekianjo 5y agoIt's almost as if the leaker was planted by a government.
- JumpCrisscross 5y ago> Facebook leaker is explicitly arguing against this though. She cites Facebook’s push for end-to-end encryption of private messages as a problem. One doesn’t have to agree 100% with an ally.
- PragmaticPulp 5y agoIf someone is going to Congress and lobbying against end-to-end encryption of private communications, how are they an ally?
- JumpCrisscross 5y ago> If someone is going to Congress and lobbying against end-to-end encryption of private communications, how are they an ally? Because they're also lobbying for other things you care about. And those things are more likely to be passed into law than the E2E encryption pieces. Taking a puritanical view on an issue is a high-risk high-reward gambit. Nine out of ten times, it ejects you from the room. One out of ten times, you will organize sufficiently to make it a wedge issue (e.g. the NRA on guns, NIMBYs, et cetera).
- CamperBob2 5y agoThere's a gambler's fallacy at work here, though. Our Fourth Amendment right to encrypted private communications is so important that if we lose it (or give it up), any future wins in areas like corporate transparency, monopoly regulation, and net neutrality won't ultimately matter. We won't have the freedom needed to benefit from them. To the extent Haugen disagrees, she's not on "our side."
- deleted 5y ago[deleted]
- torstenvl 5y agoSorry, what clause in the Fourth Amendment talks about encryption? Thanks in advance.
- CamperBob2 5y agoThe plain text reads, "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated." It's not reasonable to outlaw the tools needed to exercise a fundamental right. Not OK for the 1st, not OK for the 2nd, and not OK for the 4th. Encryption was already an old technology at the time of the Constitution's authorship. If they had wanted to regulate or outlaw it, they were free to say so. They didn't.
- torstenvl 5y ago> Encryption was already an old technology at the time of the Constitution's authorship... ...so if they had wanted to guarantee a right to it, they were free to say so. But they didn't. Despite clearly contemplating privacy.
- adventured 5y ago> One doesn’t have to agree 100% with an ally. Depending on how terrible the bad ideas are that they're pushing, they may not be an ally at all in fact. A multi-purpose trojan horse may be more accurate. In this case, promoting the abolition of end to end encryption is quite heinous. She's providing the authoritarians a potent argument that isn't yet well established in the public mind (we have to be able to see all of your data so we can keep you safe from the Chinese trying to see all of your data).
- mwigdahl 5y agoNor does one have to disagree 100% with an enemy.
- WillPostForFood 5y agoNor do you have to support an ally you agree with a majority of the time if they get some big things wrong.
- lowkey_ 5y agoI'm merely clarifying HN's common opinion. As for the whistleblower, I'm very skeptical of her — to be a tech PM against encryption, and somehow linking e2e encryption to making the platform less safe, is dubious at best. Removing misinformation and calls to violence on the Facebook platform doesn't need to include monitoring private messages. The idea that she's been a PM at large tech companies for 15 years and doesn't understand that Facebook monitoring messages will mean China can monitor those messages is almost too suspicious to believe.
- kolmogorov 5y agoHow do these two align? Why would FB sending messages that are sent encrypted (not e2e) and stored on US servers allow China to read messages? If you allege hacking then why wouldn’t they be able to hack the devices? Re misinformation: why would misinformation not simply happen in e2e group chats like it is already happening in e.g. Brazil or India? What’s the difference between posting to a group of friends on Facebook vs sharing a group message to those friends? I do think messages should be encrypted but the trade off isn’t as straightforward as you make it sound.
- dboreham 5y ago> Why would FB sending messages that are sent encrypted (not e2e) and stored on US servers allow China to read messages? Not parent, but I think the idea is that if BigCo does business in CountryA , then CountryA's government invariably forces BigCo to spy on their users who are residents. Obviously compromising the user's device is a workaround open to governments but hard to achieve in bulk.
- kolmogorov 5y agoFB does not do business in China. This is rather a risk for Apple given they store keys in the cloud and do business there fwiw. I agree it’s a risk for almost all other countries.
- 5y ago
- adventured 5y agoThe obvious solution to #2 is encrypted private social networks that aggressively lock out the monitors. To continue the monitoring it'll require abolishing encryption, that's where the views in question (more freedom + less surveillence and more content monitoring) inevitably are going to end up conflicting and must always end up conflicting.
- hannasanarion 5y agoHow do you ban monitoring of public posts?
- adventured 5y ago> How do you ban monitoring of public posts? I'm not suggesting you should or can in any practical way (how heavily - or not at all - that public posts should be monitored by the government is a different debate from what I was saying). I'm saying that the parent comment claiming the views are not necessarily conflicting, is incorrect. This must always conflict in the end: > I don't think these are conflicting views: (1) Less monitoring on private messages (2) More monitoring on public posts More aggressive public monitoring (along with the follow-on laws to regulate & punish a lot more things said in public) will inevitably result in a drive toward more encrypted private social networks that can't be easily monitored. Those private social networks will rely heavily on encryption. The aggressive public monitors will have to abolish encryption to then regain the high degree of mass content monitoring they used to have. Call it networks going underground, or dark; the authorities will come up with a negative naming scheme for it as they seek to castigate the shift. You can bet on the rise of mass popular encrypted private social networks (likely built around subjects/topics/ideology/x thing in common; more like groups or subreddits than mass social media today, in other words). It's coming this decade. And the response from the government toward that is quite predictable. They'll use it as another argument against encryption.
- tytso 5y agoIf there is a drive towards more end to end private messaging, I'm OK with that. But I wouldn't call that "social networks"; in my mind there is a huge difference between an encrypted end-to-end message between two users, an encrypted message which is sent out to a large group of users, and a public post. You can make an end-to-end message between two users perfectly secure, to the limits of engineering and the security hygine of the two users. No problem there. If you have an encrypted message sent out to a group of users, as the group of users gets larger and larger, it's more likely that one of those users might be an informant to law enforcement, or will be sloppy with their message hygine, so that after they get arrested invading the capitol on January 6th (for example), law enforcement gets access to all of their information on their phone with the pin code 1234. Still no problem as far as I'm concerned. Criminals tend to be stupid, and that's good from a societal point of view. Public posts are a different story altogether, because social networks have an economic incentive to promote "engagement". And if that engagement happens to emphasize messages that incite hate, or anger, or causes people to think that vaccines contain 5G modems, or whatever, hey, that's just good for shareholders, and in the captalist system, shareholder value (especially VC value, for startups) is the highest good, right? Well, I have some real concerns about about that. I think that corporations which are prioritizing engagement uber ales, even if that causes social harm, should be potentially regulated. And that's why it is quite possible for someone (like me) to believe that end to end encryption should be allowed, and promoted, even if it gives the FBI hives --- and at the same time, argue that public posts should be highly monitored from the perpsective of trying to get insight to whether the amplification alogirhtms might be doing something unhealthy for our society's information ecosystem.
- yawnr 5y agoMy question is what constitutes a public post? I feel like that definition is evolving. Is a WhatsApp group with 1k members spreading disinformation still a private message?
- tacitusarc 5y agoYes.
- WillPostForFood 5y agoHow about a WhatsApp group with 20 family members?
- tacitusarc 5y agoThat is also a private message.
- boringg 5y agoYes, that is definitely a public post.
- ryandrake 5y agoThe distinction between "public" and "private" is gray and messy when it comes to corporate social media platforms. Is anything really private? How do you send a message to someone in Messenger? You're not sending the HTTP request to person X. You're sending it to Facebook with metadata that says "please make this visible to person X and consider it private". Then Facebook keeps the message and decides whether or not to publish it onward to person X, and whether or not to display it to anyone else (internally, externally, in logs, etc.). It's not like a package that gets sent over to person X's house. It stays on Facebook's property at all times. When you post something to "your" feed, you're sending it to Facebook with metadata that says "please post this on my wall" or whatever. To strain an analog analogy, this is not like the telephone or even the post office, where you hand them something or send out voice packets and they just look at the recipient and forward it on to the actual person. Everything you send is sent to Facebook and kept at Facebook. Replace "Facebook" above with any social media platform or cloud service. They're fundamentally the same. I don't consider iCloud photos private. You're sending your content to Apple, not putting it in some safe that you alone control.
- ignoramous 5y ago> Less monitoring on private messages As pointed out on The Last Week Tonight show, private messaging apps are a cess pool of misinformation [0] especially in the developing world. But: Facebook can and does monitor private messages whenever any user flags / reports them [1]. The problem is, how effective is the mechanism given not many know it is even there. Of course, e2ee mustn't be compromised but it should also not be used as an excuse to let misinformation run amock. May be homomorphic encryption gets us there, may be UI changes do. I hope Facebook does act swiftly and decisively whatever the case, since e2ee (backdoored or not [2][3]) seems like the scape goat here. [0] https://www.youtube-nocookie.com/embed/l5jtFqWq5iU https://www.youtube-nocookie.com/embed/l5jtFqWq5iU [1] https://news.ycombinator.com/item?id=25211185 https://news.ycombinator.com/item?id=25211185 [2] https://news.ycombinator.com/item?id=13389935 https://news.ycombinator.com/item?id=13389935 [3] https://news.ycombinator.com/item?id=25685446 https://news.ycombinator.com/item?id=25685446
- tboyd47 5y agoThis is probably what would have naturally happened if the CDA were never passed. Instead, we've turned internet companies into geese that lay golden eggs for the government.
- oceanplexian 5y agoHow about (3) Less consolidation of power Personally as someone who doesn't use FB and never will, I couldn't care less if Facebook wants to track and monitor every one of their users, monetize their every movement, and ban any message they want. In a free market you'd have thousands of social networks to provide competition with all sorts of different policies and ToS. The real issue is that one company is in a skewed position of power due to a broken marketplace. Fix that problem and all the other problems are irrelevant.
- Shish2k 5y agoHow would thousands of competing networks deal with a government-enforced “no E2EE; wiretapping API required” law?
- cabalamat 5y agoBadly, and that's the point. I'd like social media to be run by everyone having a social media server linked to their home network (imagine something like a Raspberry Pi), with it being totally decentralised and every user controlling their own server. Then if the government wants to shut it down, they have to raid everyone's home.
- herval 5y agoOr, you know, just work with the ISPs to make it illegal, like with BitTorrent. Also, what you want already exists - you're free to go use Mastodon and run your own node. You can't possibly think that's a reasonable product your grandparents would be able to use.
- cabalamat 5y ago> Or, you know, just work with the ISPs to make it illegal, like with BitTorrent. BitTorrent certainly isn't illegal in the UK; it might be in other jurisdictions. > you're free to go use Mastodon and run your own node Would it work behind a NAT'ed router on a dynamic IP? I suspect it might not. > You can't possibly think that's a reasonable product your grandparents would be able to use. What I envisage is an SD card containing the OS + apps, you put it in the Pi, plug it into your router by ethernet, configure it via its web app, and you're ready to go. I think it ought to be possible to make it easy enough for the average person to install (certainly anyone who could install a router + internet would be able to).
- quotemstr 5y ago> I don't think these are conflicting views: (1) Less monitoring on private messages (2) More monitoring on public posts The same people argue that FB needs to censor more public content and wringing their hands in public over just how awful it is that in places like India, WhatsApp message forwards can spread memes that respectable people like western journalists and tech activists don't like. It's a "who, whom" thing. There's no principled stance differentiating private from public with respect to control and censorship. It's become respectable in western political discourse to demand totalitarian control over the spread of ideas. Today's activists will do or say whatever it takes in the moment to bring the boots closer to human faces forever. Anyone who values human dignity needs to oppose this movement.
- jollybean 5y agoWhile I agree the elites are upset about losing power, there absolutely are issues of principle here. There is such a thing as legitimate authority. For example - there are people who do actual science, and other people who actually can read scientific papers and make assessments, there are people who have legitimate basic understanding of science, relationships with scientists, and consistently communicate reasonable information about that, as it relates to our world. And there are people who make stuff up. And very influential actors who will use a system without information integrity to their advantage. These people wield enormous power and fundamentally shape outcomes for everyone. Both the Truth, and the Public Good matter. While the later is more ambiguous, it's also material. The question the becomes - how do we allow yahoos in their basements to say anything they want publicly (i.e. aliens invented COVID, the vaccine will kill you), how do we allow legitimate detractors to question classical authority (i.e. ivermectin might work), how do we try to unbias information when it's politically contentious (i.e. mask policies), how do we allow politicians to speak their minds, but to not destroy their communities with irrational or completely irresponsible information (i.e. 'the vaccine isn't safe, you don't need masks, just eat healthy )'. I'm afraid we don't have the answers, but maybe some degree of 'proportional oversight' on the most public bits of information might be reasonable i.e. statements about the vaccine, when they reach a certain threshold of popularity, must have references to actual studies, or something along those lines.
- csmoak 5y agoHow do you look at spamming private messages to many recipients, resulting in a similar effect to posting publicly? I know of bullying on FB where the harasser sends the same message to dozens of friends of the harassed. FB makes this easy to do since a list of someone's contacts are often easy to find online and there is no recourse to find or report these messages (as with a public post). To me this presents a particularly tricky double-edged sword. E2E encryption is good in many cases, but tied to an easy way to send many messages and easily-accessible lists of people to target a message to, can result in a similar but more hidden version of public posts. My guess is that this is being used today to disseminate similar content that is being restricted on public posts. As far as I can tell, restrictions to limit the number and speed of private messages have not been effective against this kind of approach, and new accounts can always be created. In some cases, these messages go to a different "inbox" for non-contacts, but not always, and this just delays the receipt of the message since, again, they cannot be found or reported. I don't know a good solution to this problem, but it's not one I've seen talked about.
- mensetmanusman 5y agoThere is no solution. Either you give people e2e and let them choose to do horrible things with the privilege or not. Maybe a middle ground is that every e2e message is hashed and sent once, and if duplicate hashes are detected at scale (of the hashed message) you slow the propagation to 1 user per day.
- Quessked73 5y agoPerhaps our expactation of privacy should depend on what platform we use, no e2e on public platforms (i.e. Facebook) but e2e on other platforms where an username/id/phonenumber is required, that can not be found easily. I think the main problem is users mainly using only one platform for their communication instead of choosing it on a case by case basis.
- fragmede 5y agoThe limits aren't always visible. In particular, its a good idea if new accounts get heavily limited in invisible ways, and it's a moderate challenge to create mass amounts of them that don't start off shadow-banned.
- hammock 5y agoIf someone has their Twitter set on private (only followers can see content), but they accept most/all follow requests, would you consider their content in category 1 (private) or category 2 (public)?