Facebook Messenger – end-to-end encryption delayed to end of 2023
forbes.com
forbes.com
And I actually don't see how e2e and their business model sync in any possible way. They make their money off of knowing everything about what you do on and off their sites so how does walling off all of that data make any sense?
So they say they are working on it but I see a distinct contrast between their 'vision' and their needs as a company
This article sounds like it was written by a markov chain trained on members of Congress bloviating about encryption and "protecting the children".
Unlike Whatsapp, FB messenger is tied to a public profile, where people extensively share their life. This allows a predator to get contextual info like age, likes/dislikes, family problems and more which helps them in finding a victim and set a trap for the child.
I don't know enough about the structure of predation to have an opinion on the merits of the point, but it sure seems like a reasonable excuse for delaying E2EE.
We're talking about hoping that private companies will do it on their own (or be required to do it somehow?) in order to turn over to the police what their systems flag as looking like predators? And that it's important E2EE doesn't interfere with that?
If you do suspect that someone is a child predator, encrypting what is probably the most likely stashes of incriminating evidence would make things harder to build a strong case. I could see a lack of encryption being useful even when everyone follows rules that many would see as too strict (I don't fall in that camp, I think).
I don't think trade off is worth it though.
What if they do it to look for suspected terrorists (which is legal) and accidentally also check for child abusers?
> We're talking about hoping that private companies will do it on their own (or be required to do it somehow?) in order to turn over to the police what their systems flag as looking like predators
IIRC Facebook already do this, and have been criticized by charities in the domain that it isn't enough.
So, what if they do?
By reports they do indeed already do this, and it was earnestly explained in the tweet[1] linked elsewhere in this thread by a FB developer that the delay in E2EE is to make sure they can continue to do it.
I don't like it, but as you note, others have other opinions.
I think we should be clear that it's what's going on, what is we're talking about when we talk about delaying encryption to protect children, exactly what it is that is being proposed. Others in this thread still think "oh no that's not what we're talking about they'd never do that." Let's be clear about what we're talking about, whether we support it or not.
[1]: https://twitter.com/elegant_wallaby/status/14628453362888253...
https://www.newyorker.com/magazine/2021/07/26/the-german-exp...
Yet, somehow, despite child predators using these institutions regularly (in fact even the loverboys often complained about often recruit girls from child services institutions), there is no need to do anything about that. In fact, quite the opposite.
At this rate, the virtual world they are making will take 100 years, or simply, it will be even more difficult to trust facebook.
If you don't care if your chats are in plain text, then you shouldn't care if they are encrypted.
1. my phone is on and does a secure key exchange each time I login on desktop, in which case I have to carefully audit complex novel crypto or trust that FB doesn't snoop the key during the exchange.
or
2. I have to scan some QR code or some other bullshit to make desktop chat work.
And more importantly, it's possible for me to lose my message history if I lose all my devices.
I don't want any of these.
Also, requiring that users memorize another password is a pretty huge UX burden. Remember that FB has billions of users, so we're talking about mostly non saavy users. No popular E2EE messaging service that does this as far as I'm aware.
This isn't a usability tradeoff, is it? If you don't care that your messages are in clear text, then I don't see why you would then be forced to audit how their crypto works to be sure that it works so that you could then use that crypto for messaging. I don't audit how my web browser uses ssl, do you?
> 2. I have to scan some QR code or some other bullshit to make desktop chat work.
> And more importantly, it's possible for me to lose my message history if I lose all my devices.
Yea, these do seem like potential usability issues and I could see these being valid reasons for them not wanting to roll it out.
That being said, they are facebook and they have a ridiculous amount of engineering talent to apply. I would be really curious to know why they think they can solve the problem well it in a few years but not in a shorter time frame or if they don't think they can achieve it in a few years and are just kicking the can down the road in the hope that everyone forgets about the can later.
- Photos don't pinch-to-zoom
- No read-receipt indicators
- No reactions besides the primary emoji
- Primary emoji can't be changed
- No nicknames or other frills
...none of which have anything to do with E2EE itself. Feels like MVP issues, to be honest.
- server-side searching of messages becomes impossible; this essentially breaks message search for most people
- depending on how it's done, it can mean the loss of messages when changing devices (one of the top complaints I hear about signal)https://news.ycombinator.com/item?id=29200506 https://news.ycombinator.com/item?id=29308617
https://twitter.com/elegant_wallaby/status/14628453362888253...
Basically management assumed (as it seems that you do) that E2EE is a technical feature that can be flipped on without changing anything in how the social model works on Meta’s three distinct, unconnected messaging systems.
That they're delaying e2ee doesn't surprise me, but that they claim to want to implement it in the first place does. I think the intent to implement it is a effectively a farce to convince us that the "hard choice" FB will make to not give users privacy was all about protecting our children.
Child sex abuse could be brought to a practical minimum without reading everyone's communication, and reading comms is not going to stamp it out. Reading everyone's communication is the prize, not saving kids.
Large system = difficult to change
Not only because of technical challenges, but also regulatory issues.
The Metaverse doesn't really have users, so you could progress faster - but I highly doubt it as well.
There are many URLs you can't send to people on Facebook.