Court orders WhatsApp to suspend users sharing pirated movie
torrentfreak.com
torrentfreak.com
So this does not require Whatsapp/Facebook to proactively monitor its network and suspend users who share it (if it did and Facebook complied, it would disprove their claim that e2e encryption as they use it provides sufficient privacy).
I don't see how this could happen if that claim was true.
Our theory is that at least images on WhatsApp are human-reviewed, and one reviewer saw the credit card go through and took the opportunity.
We reversed the transaction and switched to Signal...
Eh ...
The same can surely be done with web links.
I don't see the relation. They could (and I'm sure they do) attach a message id to the e2e-encrypted payload, shared between message sender and receivers. They could remotely delete messages by id, either by design or through a bug. None of this requires breaking e2e.
I mean, I'd argue that remote message deletion by id should not be possible (i.e. the client should not permit it) and certainly not without user notification, but that's a different matter.
While what you're saying is theoretically possible, I find it such a stretch that the only reasonable explanation save for some very unlikely bug is that message contents are indeed accessed in some form outside of our own devices.
What do you believe is the likely reason for the link to be deleted? Do you think that the organizer (your friend) did something at his end that caused the link to be deleted everywhere? I.e., he wanted to delete the link. In that case, it should be possible to reproduce this.
Or do you think Facebook or WhatsApp disapproved of the link and therefore deleted it? Was it something controversial or against Facebook rules? It could be possible to reproduce that as well if a group of users shares an equally controversial link.
The only thing that I think could potentially be controversial would be that it was a social gathering during the pandemic. The event page itself was and still is up. If it was deemed against FB rules I'd expect it to be reflected in some way on FB, and not just by deleting WhatsApp messages refering it.
I really can't give a good reason apart from "some ML model got triggered somehow, which prompted a human somewhere to look at it for a couple of seconds and click the delete button"
Such a mechanism allows governments to turn WhatsApp into a propaganda machine very easily, though, so I'm not sure if I would consider such a mechanism for my app if I were in a similar position.
> The event next week:
> https://....
(Neither of us remember if those two lines were distinct messages or two lines in the same message; regardless, neither is there anymore)You made me envision this "end-to-end encryption" scheme:
- Alice sends a message to Bob. True to its word, WhatsApp encrypts the message on Alice's client and transmits it through to Bob without the WhatsApp server ever being able to read the message.
- Bob receives the message, which is decrypted for his viewing by his WhatsApp client.
- Bob's WhatsApp client reads the message and reports it back to the WhatsApp server.
In every copy of the app, WhatsApp explicitly says, "Your messages, calls and status updates stay between you and the people you choose. Not even WhatsApp can read or listen to them."
Of course, the scenario you describe is possible, but WhatsApp would be lying.
WhatsApp is already lying. It can, as demonstrated above.
This changed a few months ago.
Signal got this right.
Welcome to Article 11 & 13: https://juliareda.eu/eu-copyright-reform/
"Yes, we recognize this requires setting up a monitoring infrastructure for compliance with the article, but we reserve the right to publicly condemn any company that uses that same infrastructure for self-serving purposes."
In the end it doesn't matter how it will be followed. If general monitoring is the only way to follow it then nobody needs to follow it. Simple as that.
I always thought that they only managed the public keys.
I thought that your backup is stored in iCloud or Google Drive unencrypted. Facebook doesn't have direct access to that. You phone must be already logged in to those services.
Some folks will tell me "but it's end-to-end!" and it feels kinda like they're telling me that it's "what plants crave."
EDIT: if you don't believe me, turn on the setting, have a friend reinstall the app and watch the re-keying happen. It's indistinguishable from an attack unless you trust the broker. If you trust the broker, then why claim it's "end to end"? Also refer to the various articles that describe this behavior that WhatsApp says is by design.
Double EDIT: why is it this way by design? Because it would be a PITA if every time you replaced your lost phone your buddies got a warning that looked like "Either Dave has got a new phone or the NSA is attacking you. Resend ten years of hilarious memes and intimate conversations to whoever is on the other end?" Real cryptography comes with real inconveniences when you lose your keys. It's the same kind of headache with securing cryptocoins - if you lose the secrets you lose the money. Trusting an agent is the only way to escape, but it comes at a significant cost. Cryptocoin custodians like exchanges get attacked all the time. And communication broker/relays get lawful intercepts all the time.
AFAIK, it won't resend already received messages; if the other end didn't have a backup, these ten years of old messages are lost for that end. I don't know whether it will resend sent but not yet received messages, and it certainly will use the new key for new messages (but at that point, you already received the "key changed" alert).
I want to watch in a small, portable screen changing positions on my couch, not sitting in a static position for over an hour, on a huge screen, full of lines, people, smells, and even 20 minutes of ads.
I wouldn't mind paying the price TO SEE A MOVIE. It's just that all the rest of the theatre experience is crap.
Also, most cases of piracy are of those who otherwise couldn't afford or would not have paid the theater experience. So the pirate is a ghost customer who only exists in the pirated world.
I never paid for western shows up until Netflix came along. I never paid for games until steam started using regional pricing. I never paid for music until Spotify.
In every case it was about access, convieneience and the willingness of the service provider to meet me where my wallet was.
Did you yourself refrain from piracy when all the movie theaters were closed for the last year?
6 sense above the E2E encryption ?
How they do this ?
Bottom line choose your friends wisely or join seedy groups with caution.
Easy, someone squealed.
All the encryption in the world won’t do you any good if the recipient of the message can’t be trusted. And the larger the group the more likely it is that someone is a bad actor.
Where do snitches fall in reference to handling of evilness[originally defined in RFC3514]?
Should the evil bit be set in reference to the activity of a group in isolation of the maliciousness of an implementation of a system operating on a network medium?
Example:
>A group uses a tool or protocol legitimately in the way in which it was designed [non-evil manner] to facilitate an illegal workflow [debatably evil, but at a level irrelevant to the network]. Based on RFC 3514, this group carrying out the illegal activity in a way not malicious on the to tge network SHOULD NOT set the evil bit; they are up to no mischief within the context of the network. as they are making use of hosts as they were designed to be used. A snitch within the group, however, SHOULD set the evil bit, and furthermore, if IPv6, should set the attack identifier to something appropriate since they are exploiting the implicit trust of the network in a malicious way [see RFC's 7258 and the IPv6 relevant part of 3514]
Clearly, there is intent based on related work with optical switches and routing that the evilness bit should cascade appropriately between contexts, such as there being evil lambdas, and evil polarizations, etc.... How then, does one then handle the problem of "relative evilness", in which the state of the evil bit is dependent on higher order constructs, in particular where higher order activities are directly recognized to be a form of network attack, thereby warranting the setting of the evil bit by one party or the other? Note, this issue does not just impact the criminal element, as the same setup could easily afflict law enforcement by which a snitch jeopardizes legal activity through the same attack pattern, or rogue law enforcement participating in unlawful surveillance jeopardize the safety and integrity of the network.
I believe the very future of security on the Internet and the integrity of activity mediated over it is at stake if we cannot reach a rough consensus on this topic.
In our context "evil" just meant that someone breached the secrecy a group assumed to be a shared value.
Encryption is never evil and the tools used to facilitate communication in democratic societies should not be equipped with traps to enforce whatever power positions exist at one time.
I think it's safe to assume anyone that referencing it is doing so for comedic purposes.
Note: I’m not advocating they do this or supporting the ask , merely providing a technical option.
but really if the code is not open source it doesn't really help for them to claim E2E. You don't really have any guarantees they won't circumvent encryption.
"Pirates" first, and the next wave will be people critical of his government and especially his Corona clusterfuck. The Modi government already ordered Twitter to silence critics.
Facebook have their own infra but still, they can't ignore the law.
I just wish they'd cast a wider net.