9 ms·
I think this is... fine? Am I just totally naive. I think it's fine to say "You don't really have privacy on this app" - as long as there are relatively good op
by Traster 7mo ago
I think this is... fine? Am I just totally naive. I think it's fine to say "You don't really have privacy on this app" - as long as there are relatively good options of apps that do have privacy (and I think there are). TikTok is really a public by default type of social media, there's not much idea of mutual following or closed groups. So sure, you don't have privacy on tiktok, if you want it you can move to snapchat or signal or whatever platform of your choice.
Like, it's literally a platform that was run under the watchful eye of the CCP, and now the US version is some kleptocratic nightmare, so I just don't see the point in expecting some sort of principled stance out of them.
In some ways I think it's worse for places like Facebook to "care about privacy" and use E2EE but then massively under-resource policing of CSAM on their platform. If you're going to embrace 'privacy' I do think it's on you to also then put additional resources into tackling the downsides of that.
- londons_explore 7mo agoTiktok has private messaging, and it is used by hundreds of millions of people. IMO no consumer service should have private 1:1 messaging without e2e. Either only do public messaging (ie. Like a forum), or implement e2e.
- trashb 7mo agoIn my experience most forums have private messaging. Additionally I think it is fine to say "we don't support e2ee". I prefer honesty to a bad (leaky) e2ee implementation, at least the user can make an informed choice.
- Ekaros 7mo agoI agree. At least take of "Yes messages are stored on our servers" is honest. And if they are accessed by anything else than limited subpoena is policy or legal issue.
- cucumber3732842 7mo ago>In my experience most forums have private messaging. Yeah but it's kind of accepted that the forum owner could read it all if they so chose. Maybe this is a hold over from back in the old days when encryption was nowhere near default during which forums arose.
- RobotToaster 7mo agoTiktok has direct messages, they don't even call them private. It's better that they're honest about this, nobody should believe for a second that WhatsApp or FB messages are truly E2EE. DM on social media shouldn't be used for anything remotely private. It's a convenience feature, nothing more.
- throw0101c 7mo ago> Tiktok has direct messages, they don't even call them private. It may not be called that, but what are users expecting? Some folks may later be surprised when a warrant gets issued (e.g., from a divorce judge).
- giancarlostoro 7mo agoIf you are a grown adult and dont do research on “messaging apps” (which Tik Tok is not) then thats really on you.
- oarsinsync 7mo agoIf you are a grown adult and don't do research on "<insert any topic that could have a material negative impact on your life, but that is not currently on your radar as being a topic that could have a material negative impact on your life>" then that's really on you. Unfortunately, this doesn't scale.
- wizardforhire 7mo agoWell it does scale… just not in the way that is good for democracy.
- hogwasher 7mo agoIt definitely ignores that many people don't have time. If someone is working over 40 hours per week, plus maybe doing unpaid labor taking care of kids or elders, where are people supposed to find the time and energy to brush up on a million different topics they don't even know they might not know enough about? Especially if they might also have medical issues, or hobbies, or want to have any time at all to relax. Obviously, one way to improve the situation would be to make sure people are paid fairly and not overworked and have access to good and affordable or free childcare and elder-care and medical care, but corporations don't want that either. If anything, they're incentivised to disempower workers and keep them uninformed, and to get as much time out of them as they can for as little money as possible.
- tuwtuwtuwtuw 7mo agoThe email protocols would like to have a chat with you.
- kgwxd 7mo agoYou can bring your own encryption to that, and bring your own client to automate it.
- em-bee 7mo agoyou can encrypt the content but not the metadata, not even the subject unless you use a customized client that encodes it (like deltachat which doesn't use a subject at all), but then you still have your email address exposed. for all intents and purposes email is not e2ee.
- Bender 7mo agoEmail encryption for most people is sufficient even if the metadata is exposed. One can simply state in their email encryption "Bing Bing Bong" or "Why did you not put the trash out?" which might mean to the recipient :: "check the second SFTP server" or "let the cat outside" or "Jump on my private Mumble chat server" or "Get on my private self hosted IRC server". The email message need not be encrypted for that matter. The intended payload can be in an header-less encrypted file on a throw-away SFTP server in the tmpfs ram disk.
- tuwtuwtuwtuw 7mo agoSo it's end to end encrypted except that third parties can see who you communicated with and when? Sure.
- unethical_ban 7mo agoI have never considered metadata a part of the term E2EE. It has always been about the message contents. I understand that metadata is valuable information for spies/governments and that encrypting or hiding it is valuable for privacy. But if you use that definition, there are almost no E2EE protocols on the planet in use. First and foremost, any protocol that uses Apple or Google push notifications is giving metadata to those organizations. Even Whatsapp, iMessage, Signal, Telegram private messages, all of that leaks metadata but the contents of messages are hidden from the provider.
- DoneWithAllThat 7mo agoAnd yet virtually all consumer services with 1:1 messaging lacks e2e. This is a bit of a quixotic position to take.
- Bender 7mo agoAdding that private self hosted forums can permit uploads of encrypted files, encrypted with a pre-shared secret or a secret shared over a private self hosted Mumble voice chat server.
- nradov 7mo agoLots of other consumer services such as Strava have direct messaging without e2e encryption. No privacy is guaranteed. This is fine, they're not deceiving anyone about how it works.
- DeusExMachina 7mo agoI don't disagree with providing people with more privacy, but what you present is a false dichotomy. For a long time we lived with private messages over SMS that were easily readable by third parties.
- khalic 7mo agoNo, saying that e2e encryption makes users _less_ safe is completely dishonest, nothing is fine about this. The logic of "anything is better than before" is also fallacious.
- roncesvalles 7mo agoDepends on your definition of "safe". Imagine an adult DMs a nude photo to a minor (or other kinds of predation). If it's E2EE, no one except the sender and receiver know about this conversation. You want an MITM in this case to detect/block such things or at least keep record of what's going on for a subpoena. I agree that every messaging platform in the world shouldn't be MITM'd, but every messaging platform doesn't need to be E2EE'd either.
- philipallstar 7mo agoImagine Hamas are your government and want to figure out who's gay. You don't want a MITM in case they can do this. Pick your definition of safe.
- trashb 7mo agoIn that case don't use Tiktok dm's to discuss your sexuality. I think it is strange that people feel like they have to be able to talk on sensitive topics over every interface they can get their hands on. Similarly in "traditional" media you may not want to discuss such private conversation on a radio broadcast. Perhaps you would rather discuss it on the phone or over snail mail as there is more of an expectation of privacy on those medium.
- jmull 7mo agoIt might be fine if they presented an honest choice. They are lying straight off though... police and safety team don't read messages only "if they needed to" to keep people safe. They do so for a large variety of other reasons, such as suppressing political dissent and asserting domination and control. I don't think we can expect most people to understand TikTok's BS here either. I notice even a skeptic like you is uncritically echoing the dubious conflation of privacy and CSAM.
- hobs 7mo agoAnyone who doubts the requirement for e2e messaging should not be considered a skeptic, they are fully buying into whatever narrative LEO would like you to believe.
- dfxm12 7mo agoTrying to gaslight the public into thinking end to end encryption makes users less safe is not fine.
- mrexcess 7mo ago>I think it's fine to say "You don't really have privacy on this app" Disagree. To analogize why: privacy isn't heated seats, *its seat belts*. Comfort features and preferences are fine to tailor to your customers and your business model. Jaguar targets a different market than Ford, and that's just fine. Safety features should be non-negotiable for all. Both Jaguar and Ford drivers merit the utmost protection against injury in crashes. Likewise, all applications that offer user messaging functionality should offer non-defective, non-harmful versions of it. To do that, e2e privacy is absolutely necessary. >I just don't see the point in expecting some sort of principled stance out of them. This is the defeatism that adds momentum to a downhill trajectory. Exactly the opposite approach arrests the slide - users expecting their applications and providers to behave in principled ways, and punishing those who do not, are what keeps principles alive. Failing to expect lawful and upright behavior out of those you depend on, be they political leaders or software solutions providers, guarantees that tomorrow's behavior will be less lawful and upright than yesterday's. Stop writing these people a pass for this horrible behavior, and start holding them unreasonably accountable for it, then we'll see behavior start to change in the direction that we mostly all agree that it needs to. The most effective protests against internet censorship came from massive grass roots movements, with users drawing a line in the sand that they will not tolerate further impositions on their freedom. >In some ways I think it's worse for places like Facebook to "care about privacy" and use E2EE but then massively under-resource policing of CSAM on their platform. The irony is so manifest of billions of people having their privacy stripped by politicians and business elites in the name of protecting our children, while those politicians and business elites conspire en masse to prey on and sex traffick our children. If these forces actually took those concerns seriously, rather than sensing them as an opportunity to push ulterior motives, they'd be eating each other alive, right now. Half of DC, half of Hollywood, and at least a tenth of most major college administrations would ALL be at the docket.
- Traster 7mo agoTesla doesn't have parking sensors. They're a safety feature. There's lots of safety features in cars that are optional, we've got an entire rating system for the safety of cars. We're talking about an app that's controlled by the CCP, I do expect them to take a principled stance - stances like Taiwan is a part of China and you can't be openly critical of the leader of the party. They don't have the same principles as you. You can force them to put in E2EE, but you can't force them to be honest about it or competent about it. I would rather know what we're getting than to push them to lie. This is the same thing as the OpenAI/Anthropic thing. You've got Anthropic taking a principled stance and getting pain for it, and you've got OpenAI claiming to take the same stance, but somehow agreeing to the terms of the DoW. Do you think it's more likely that Anthropic carelessly caused themselves massive trouble, or do you think OpenAI is claiming to have got the concessions that clearly won't work in practice. I think it's naive to think the former.
- smugglerFlynn 7mo ago> as long as there are relatively good options of apps that do have privacy (and I think there are) Once you have enormous network effect like TikTok has, you don't really have any free selection of alternative apps. You are free to use one, but you will be the only sad user over there. Regulations are needed that would force large platforms like TikTok and Instagram to enable federation, opening them up to actual competition. This way platforms would be able to compete on monetisation and usability, instead of competing on locking in their precious users more strictly.
- pixl97 7mo ago>Regulations are needed Lolololol. No, not regulations. Regulators. With the people we currently have voted into office in the US the only regulations we are going to get are ones saying Sam and Peter must look at everything you do all the time. Until we stop voting for more authoritarianism, expect ever increasing amounts of authoritarianism.
- hogwasher 7mo agoI think it was clear what they meant.
- smugglerFlynn 7mo agoI would argue the only thing that does stop current situation from snowballing into something much worse are pre-existing institutions and regulations. That's also why dismantling and challenging these is often the very first priority for authoritarian actors.
- acheron 7mo ago“Will we ever end the MySpace monopoly?” > MySpace is well on the way to becoming what economists call a "natural monopoly". Users have invested so much social capital in putting up data about themselves it is not worth their changing sites, especially since every new user that MySpace attracts adds to its value as a network of interacting people. > "In social networking, there is a huge advantage to have scale. You can find almost anyone on MySpace and the more time that has been invested in the site, the more locked in people are". https://www.theguardian.com/technology/2007/feb/08/business.comment https://www.theguardian.com/technology/2007/feb/08/business....
- dheera 7mo agoFine with me too. I think many other apps (WhatsApp, FB, etc.) are using E2EE for PR purposes and are not actually good implementations of E2EE. Good implementations of E2EE: 1. Generate the key pairs on device, and the private key is never seen by the server nor accessible via any server push triggered code. 2. If an encrypted form of the private key is sent to the server for convenience, it needs to be encrypted with a password with enough bits of entropy to prevent people who have access to the server from being able to brute force decode it. 3. Have an open-source implementation of the client app facilitating verifiability of (1) and (2) 4. Permit the users to self-compile and use the open-source implementation If company isn't willing to do this, I'd rather they not call it E2EE and dupe the public into thinking they're safe from bad actors.
- mihaaly 7mo agoI am fine TikTok remaining that 'we watch what you are doing' platforms. Those do not care can gave that if they wish, I do not mind. But bullshitting about it is making users more safe, that is ... bullshit! Worse that that, distorting public opinion, intentionally fooling the gullible.
- keybored 7mo agoThat it’s fine because it’s the CCP (commies see all) is a new one. It’s at best subpar for the same reasons as if it was the usual Silicon Valley spyware. I could leave well enough alone. But why? Because there are choices? There are five other brands of cereal that do not have 25% sugar? I’d rather be a negative nancy towards these on-purpose addictive, privacy-leaking attention pimp apps.
- LZ_Khan 7mo agoIt's fine except for their argument that it makes people less safe. If they want to disallow encryption they don't need to lie to people while they're at it.