The E2EE only means the message is not readable "in transit" (as in after it leaves a Facebook client)
The E2EE only means the message is not readable "in transit" (as in after it leaves a Facebook client)
However it does make it a bit more difficult for them to spy on a conversation, which is arguably a good thing.
Combine this with the frequency of your chatting and your location (at least based on ip) and the other little bits of stuff users give about themselves, Meta doesn't really need to know specifically what the contents of your messages are.
In the mass of their users, an informer smart guess is more than enough.
* Who are you messaging most (best friends, family). If they like stuff, you might like the same stuff.
* When are you messaging people (awake time > profiling)
* Messaging companies (obvious, what are you into)
You clicked an ad about Product X, you're messaging your friend B from a store that sells Product X
-> Serve ads about Product X to B.
e2e isn't a tech issue, it's a trust issue. Do you* trust FB?
* You in general.
As opposed to the prior step, "0. Analysis During Composition", in which the Messenger client is doing all the metadata analysis/collection while you are typing, and already knows all the tags its going to assign to you for Meta, before the message is encrypted.
Sure, third parties won't be able to see your message. But you did give Meta permission to analyse your content prior to posting.
This anti-pattern is all over Meta's products. You can see it in use when you type an update in Facebook using a browser - just try to leave your comment un-posted, or close the page, etc. Every single keystroke prompts Meta's analysis - which is completed when you press "Post" (prior to encryption/transfer ..)
So this is some slick positioning on the part of Meta's technical PR managers ..
I believe this is the future in a GDPR world. The server sends a list to the client of 1000 ads, and the client decides which to show based on all the data available locally and a big local neural network model to decide which you're most likely to click.
"...when a Brave Ad is matched to you, it is done on your own device, by your own device, inside Brave itself. Your personal data never leaves your own device."
The mechanism is very similar to what you describe.
[0] https://support.brave.com/hc/en-us/articles/360026361072-Bra...
Alas, the GDPR might force a rethink on that when it gets enforced with teeth.
E2EE is great but does not help at all if you don't want Facebook to read your messages and profile you based on their content / who you talk to etc.
If the client just leaks the plaintext or leaks any information about the plaintext that encryption is supposed to protect then the encryption scheme cannot be described as "end to end".