14 ms·
Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. Meta has control over the app Sue uses.
by FreeHugs 4y ago
Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them.
Meta has control over the app Sue uses. So they could send them to Meta unencrypted in addition to sending them to Joe in an encrypted fashion.
Or they just extract the relevant terms:
Sue->Joe: "Hello Joe, I'm so excited! We are going to have a baby! Let's call it Dingbert. You're not the father! Jim is. I hope you don't mind too much!".
Sue->Meta: "Sue will have a baby"
Insta->Sue: "Check out these cute baby clothes!"
- rreyes1979 4y agoI think they are extracting terms. Some of the messages generated ads that were related to a term but not really about the conversation.
- rreyes1979 4y agoMore so, my wife sent me a picture of my daughter working on a puzzle. Less than 24 hours later, her Instagram was showing ads for a store that was selling the same type of puzzle as the one my daughter was playing with. So it's not just terms but images too.
- planb 4y agoShe probably gave Instagram access to her photo library (not unreasonable for a photo sharing app). That means the Instagram app can scan her latest pictures in the background when it's opened. I think it's more likely that the data was leaked this way.
- wil421 4y agoGlad I deleted my Meta apps and only use online FB when I need to. The other day I noticed the yahoo mail app on iOS was reading my clipboard for no reason. I’m going to start blocking photos on most of my apps.
- pc86 4y ago
- snowwrestler 4y agoIn case folks don’t know this: on an iPhone you do not need to give an app access to all your photos in order to use photos in the app. Under Privacy > Photos, you can set “Selected Photos” instead of “All Photos” on a per-app basis. Then when you go to add a photo to the app, you first go through an iOS prompt to select the photos the app will have access to. Only then do you go through the app’s photo selection dialogue. I have all my apps set this way (or “None”).
- nailer 4y agoI just did this and the UI is weird and confusing - it looks like I need to statically pick photos in the settings app, which obviously won’t work for day to day use every time I take a photo and want to publish it to instagram. Not saying it doesn’t work like you say, just saying it doesn’t look like it does.
- bombcar 4y agoAt least for Telegram each time you go to pick a photo to share, it offers you the chance to "add more photos visible" or you can click Manage. I assume Instagram and friends would do the same. I often just take the photo via Telegram instead, which automatically adds it to your photo roll and gives Telegram access to it. It works relatively well.
- snowwrestler 4y agoYou can just hit “done” in the settings app and it will close (with no photos selected). Then on Instagram (for example) when you go to post, you’ll get a message like “you’ve only let Instagram have partial access to your photos - Manage”. Tapping Manage will let you select photos that Instagram can access.
- paavohtl 4y agoIs this something that actually happens (= can anyone prove this by disassembling the app or MITMing the network traffic), or is it just unfounded paranoia?
- mid-kid 4y agoConsidering how easy it is to implement these things without anyone noticing since it's closed source, you have to assume it is happening in any scenario where you need any decent opsec. Even in scenarios where you don't, there's been enough cases of similar things happening with well-known apps and services to be wary.
- Shish2k 4y ago> Considering how easy it is to implement these things without anyone noticing since it's closed source I see you’ve never heard of Jane Manchun Wong...
- dvtkrlbs 4y agoIt shoukd be easy to test since Ios has a feature called app privacy report that lists networks and permission access and no when you just open the instagram app it does not access photos. Only when you open add to story page or click on the new post icon it does the access.
- planb 4y agoThanks for making me aware of this! You're right!
- titaniczero 4y ago> Considering how easy it is to implement these things without anyone noticing since it's closed source You can reverse engineer those things and analyze your network traffic. You can’t have a client in a device controlled by the user, in this case an app, send anything to a server without anyone noticing it. And frankly, they don’t even need it. Just with your contacts they can link you to your friends and common interests without even you having a facebook account, all you need is friends with a fb/ig account who have linked their accounts to their phones and use whatsapp. The contacts are known to be sent to the server, they are known to be linked to facebook except in the european union where there is a different app from WhatsApp Ireland and a different privacy policy that specifically states (in the version outside of EU) that it shares your contacts with facebook and they are much more valuable and much less risky than reading your messages.
- Melatonic 4y agoInstagram is especially malicious with this - it is the only app that REQUIRES access to my microphone for me to post something. They try to do this by having a camera inside instagram (that you can record with which would obviously require mic access) but even to post stuff I have already taken (even just photos) it wants mic access. I usually temporarily give it what it wants, post, then remove again.
- nerdponx 4y agoBack when deep learning was first hitting "mainstream" for object recognition in images, I recall reading that Facebook was using it to look for brand logos and other signs of using a particular product, in your uploaded photos. Turns out they were also building a database of everyone's face so they could build shadow profiles...
- lm28469 4y ago> my wife sent me a picture of my daughter working on a puzzle. > her Instagram was showing ads for a store that was selling the same type of puzzle How did she take the pic ?
- giarc 4y agoI think that's an important question. Did user take the photo within the app, thereby skipping the camera roll, or did they take the photo, then upload to WhatsApp from camera roll. If the latter than as someone else said, could be that Instagram had access to camera roll and decided to serve ads based upon the puzzle.
- whywhywhywhy 4y agoHow did she buy the puzzle to begin with.
- aaron695 4y ago
- muzani 4y agoYup, I think it's just some form of analytics that profiles the user. I've always suspected them of recording conversations, also why I think Android has gradually tightened permissions and visibilty around speech to text/microphone/camera use.
- baxtr 4y agoThat’s of course because WhatsApp's privacy policy isn’t applicable in the Metaverse. Looking at this from a reality perspective is not very helpful.
- netsharc 4y agoI have a suspicion as well that this is what they're doing: before the message is encrypted and sent, the app (on your phone) does analysis and picks out keywords relevant for advertising. So they can claim and be technically correct that they are not reading your messages. Although if their algorithm is doing it on your phone, is it... reading? Or they can say, technically it wasn't a message before it was sent. The dictionary definition[1] even mentions "send". [1] https://www.oxfordlearnersdictionaries.com/definition/english/message_1 https://www.oxfordlearnersdictionaries.com/definition/englis...
- Melatonic 4y agoThis is definitely the most likely scenario in my opinion
- rhn_mk1 4y ago> Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. I think it does actually no one except them can read them. If someone else can, then by definition it's not end-to-end encryption. From https://www.definitions.net/definition/End-To-End%20Encryption https://www.definitions.net/definition/End-To-End%20Encrypti... > End-to-end encryption (E2EE) is a system of communication where only the communicating users can read the messages.
- xuki 4y agoWhatsapp can't read the message on their servers but they can read it at clients, otherwise they cannot display the messages for users. Likewise, Apple/Google can read them too because they have to in order to render the texts.
- jtbayly 4y agoThis is just redefining terms, then. We know the app decrypts it to display it. But if the app decrypts it to send it to the parent company, then it is by definition not end to end encrypted anymore. If the app decrypts it, analyzes it and sends information about the message to the parent company, then the same thing is happening. The parent company is reading the message, INSTEAD of E2E encrypting it. It doesn't matter whether that reading happens on device or on the company's servers. E2E means the company is not reading it.
- propogandist 4y agothere was a time when “Unlimited” meant without any limits, but US cell carriers have redefined the term to support their business model. It’s possible that this data harvesting ad company has redefined what E2E means (to them) to advance their business interests.
- charcircuit 4y ago>then it is by definition not end to end encrypted anymore. HTTPS is E2E between the client and the server.
- JustSomeNobody 4y agoMy guess is they encrypt the message twice, append it, and split it off at their servers. To anyone observing traffic, it looks like normal encrypted traffic AND they can still, if needed, show that everyone has their own key and can encrypt/decrypt their own messages. I don't think they would be brazen enough to send it to themselves in plain text.
- jtbayly 4y ago> Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. No, that's precisely what End-to-End encryption means.
- neilalexander 4y agoMeta own the proprietary code running at either end of the encrypted pipe. Of course they can.
- omgomgomgomg 4y agoThey can decrypt if someone enables backups, so I see no reason they could not read them indeed. Signal might be the only app unable to read, but even that, I would not trust.
- marcus0x62 4y agoHow would you propose Signal -- or any app for that matter that provides end to end encryption -- encrypt the messages in the first place if they don't have access to the plaintext at some point?
- spoiler 4y agoSo you're nit-picking over the phrasing of the sentence, but should instead focus on the spirit/meaning behind it. It's illustrated in their example below that they if you say you're having a baby, meta can send some type of distilled ad-keywords to its servers (eg `[mother, baby]` if it knows the user is a woman based on their name/profile, but probably more sophisticated than that). The message you sent is still technically end-to-end encrypted, though,
- jtbayly 4y agoI addressed this just below: https://news.ycombinator.com/item?id=32951417 https://news.ycombinator.com/item?id=32951417
- 4y ago
- kome 4y ago> Just because that the messages might be sent end-to-end encrypted from Sue to Joe does not mean Meta cannot read them. so what's the point? just inconvenience. better to use telegram at this point.
- codethief 4y ago…and have no encryption at all? (Unless you manually enable it for a given conversation.)
- kome 4y agoTelegram has encryption (server-client encryption). Whatsapp may have e2e encryption, but then if it sends conversation or part of them to facebook to serve advertising, that's arguably even worse.
- codethief 4y agoWait, so Telegram, which is known for being able to read all your texts, is worse than WhatsApp where people are speculating that it might read your texts? Not that I trust WhatsApp (I use Signal) but that's an odd comparison.
- kome 4y agoyou are also speculating that Telegram read our messages, in transit. For sure, unlike WhatsApp, the Telegram client is FOSS (and you can download it from FDroid).
- codethief 4y agoI'm not speculating at all and I think you're misunderstanding the point I'm trying to make. First of all, transport security (server-client encryption as you called it) like TLS is irrelevant for this discussion. All major platforms on the internet employ transport security these days, so this is a given. The point I'm trying to make is that Telegram does not offer E2E encryption by default: (Non-"secret") Messages on Telegram pass through Telegram's servers unencrypted and are also stored there unencrypted, meaning that Telegram has access to all your messages. This is not speculation – Telegram openly admits to this in their FAQ: https://telegram.org/faq?setln=ru#q-do-i-need-to-trust-telegram-for-this-to-be-secure https://telegram.org/faq?setln=ru#q-do-i-need-to-trust-teleg... (See also the link contained therein.) Meanwhile, the speculations in the present HN discussions aside, WhatsApp does provide E2E encryption, so – from this POV – is orders of magnitude more secure.
- Closi 4y agoIn principle yes, in practice no, as this is a statement from the WhatsApp website: > We limit the information we share with Meta in important ways. For example, we will always protect your personal conversations with end-to-end encryption, so that neither WhatsApp nor Meta can see these private messages.
- hapless 4y agoThat statement was worded carefully They are saying they dont store or forward your message text, not that your phone doesnt send them topics of interest
- Melatonic 4y agoExactly. Zuckerburg cannot directly read your convo but the app itself writing down a few key keywords of interest and sending it back to facebook / whatsapp is not out of the question. And that amount of traffic is so tiny and could be so easily mixed in with everything else.....
- jlarocco 4y agoDo you really trust TOS like that, though? Assuming they're not blatantly violating the policy (which I think they've done before), it's pretty easy to weasel out of that statement by only sharing keywords from the conversation, or only sharing the info with advertisers (but not WhatsApp and Meta), or redefining what a "personal conversation" is, or carefully redefining what "end-to-end encryption" means, or ... There's no transparency, a huge power imbalance, and terrific pressure on WhatsApp/Meta to monetize as much as possible.
- kadotus 4y agoBut the problem arises, I think, is when they say they can't read them: "WhatsApp's end-to-end encryption is used when you chat with another person using WhatsApp Messenger. End-to-end encryption ensures only you and the person you're communicating with can read or listen to what is sent, and nobody in between, not even WhatsApp." https://faq.whatsapp.com/general/security-and-privacy/end-to-end-encryption https://faq.whatsapp.com/general/security-and-privacy/end-to...
- pb7 4y agoMeta->Joe: “Focus on yourself bro”