21 ms·
> 1. Only the sender and recipients of an E2EE message can see its contents. > 2. Nobody (not even Meta) should be able to forge messages to appear to have bee
by bArray 3y ago
> 1. Only the sender and recipients of an E2EE message can see its contents.
> 2. Nobody (not even Meta) should be able to forge messages to appear to have been sent from someone they weren’t.
From a business perspective, it makes perfect sense. Users want security and Meta don't want to be responsible for the data communicated.
One question I have is how Meta will comply with UK law on E2E [1]:
> Meta has been a leading industry player in the fight to tackle child sexual abuse. For over a decade, Meta has utilised hash matching technologies to enable it to detect child sexual abuse material being shared on its platforms. This has made it one of the leaders in detecting and reporting online child sexual abuse, providing law enforcement with leads to safeguard children and arrest child sex offenders.
> However, Meta and other companies are now planning to implement E2EE, without similar technologies in place, across their messaging platforms such as Facebook Messenger and Instagram Direct Messages. The roll out of E2EE is likely to happen later this year. The National Center for Missing and Exploited Children (NCMEC) estimate up to 70% of Meta referrals could be lost following the roll-out of end-to-end encryption.
Firstly, I would like to know what the UK government does with all of these referrals. Given the current state of UK policing, I predict it's almost nothing. Local government was itself complicit in child exploitation [2].
It appears this E2E implementation may have some form of backdoor anyway [1]:
> The Safety Tech Challenge Fund is a UK government funded challenge programme that first ran from 2021 to 2022. The fund was designed to support the development of proof-of-concept tools to detect child sexual abuse material across E2EE environments, whilst upholding user privacy. The fund demonstrated that it would be technically feasible.
> It is recognised though that each and every online social media platform and service is different, and therefore solutions will need to be tailored. Therefore, companies such as Meta should utilise their vast expertise and engineering resources and build on the outputs of this fund and develop solutions for their individual platforms/services.
> In addition, some of the UK’s leading cryptographers have written an academic paper outlining a variety of techniques that could be used as part of any potential solution in E2EE to provide both user privacy and security, while protecting child safety and enabling law enforcement action.
"The fund demonstrated that it would be technically feasible" - you can't leak information from a message without leaking information. The same method used to detect harmful content could also reveal information about the messages. For example, if an E2E message was delivered with hashes of images inside the message, it could also be used to detect political decent memes.
[1] https://www.gov.uk/government/publications/end-to-end-encryption-and-child-safety/end-to-end-encryption-and-child-safety https://www.gov.uk/government/publications/end-to-end-encryp...
[2] https://en.wikipedia.org/wiki/Rotherham_child_sexual_exploitation_scandal https://en.wikipedia.org/wiki/Rotherham_child_sexual_exploit...