This does not make messages inaccessible to Facebook, as they control both endpoints.
This does not make messages inaccessible to Facebook, as they control both endpoints.
Although when it comes to Facebook, we have to take them at their word that it's truly end-to-end.
Just because the protocol is well-formed doesn’t mean the totality of the implementation is trustworthy.
#ShowUsTheCode
https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...
They seem to be VR meeting spaces: https://blog.mozvr.com/introducing-hubs-a-new-way-to-get-tog...
The model you describe seems like a good one, similar to what most Linux distributions do. The distro maintainers are trusted and they compile packages and distribute the binaries, but people can run the package generation scripts themselves to get their own package straight from the source. Reproducible builds allow users to confirm that the maintainers aren't doing anything sketchy - that probably isn't a possibility here, but this model is still far better than what FB/WhatsApp and even Signal do.
It's better to have to trust somewhat verifiable promises about the Facebook app than to have to trust unverifiable promises about Facebook-the-entire-organization. That's the advantage that E2E provides.
Maybe they'll start training a personalized ML model on client devices and maybe even send it back to the mothership for further exploitation.
A good analogy: it's like writing a letter and asking the mailman to put it into an envelope, so she leaves the room and comes back with your sealed envelope.
The mailman then looks at you and says "I won't read it, I promise.", Wink wink.
That's end-to-end encryption for the commons.
Nah, nobody gives a damn about the source code, or reproducible builds to ensure the binary they're executing was compiled with that source.
The main gap in trust is that Facebook has a long history of lying and cheating to maximize for themselves so there's no basis to trust that their new moves are good for users.
But conspiracy theories about e2e being read by Facebook are probably bogus, and certainly a distraction.
Even though the source is closed, I'd bet they're doing a credible job of securing messages so that even Facebook can't read them.
That's not the issue, it's a distraction from what's really important.
What's really important is that Facebook has lost control of the monster it created. This is a way to let the monster loose and avoid accountability.
Their platform amplifies harmful content like incitement to violence, terrorist recruiting and coordination, and political propaganda.
By encrypting everything so even Facebook can't read it, Facebook escapes accountability for the harm their platform inflicts on people.
Very similar to a chemical company dumping toxic waste in public water, Facebook is dumping their pollution on the public by using strong encryption to make it physically impossible for Facebook to control the monster they created.
The keynote's online. (https://www.facebook.com/FacebookforDevelopers/videos/422572...) He mentions end-to-end encryption a variety of times, but one example is at about 15:23, where he states, and here I do quote, "without having to worry about hackers, governments, or even us being able to see what you're saying".
Now, skepticism about Zuckerberg and Facebook is warranted, but my recollection of the keynote is that statements like this didn't leave much wiggle room on this particular point. They were playing word games in other areas, like abusing the term "interoperability" to mean "between the different Facebook-owned apps", but I don't think they were here.