Your Facebook Pokes Are Stored For Two Days. Encryption Keys Then Deleted
techcrunch.com
techcrunch.com
Unless, of course, the key isn't the only way the message can be decrypted.
Caching could make sense without caching the key if the key is way smaller than the data, but why cache something that only needs to be read once?
I am not an insider, this is just a guess, etc.
This makes it practically impossible to delete data reliably. You can never be sure whether or not "ghost" copies remain after you delete data. For example on machines that failed and went offline between the write and the delete. You can expect that such machines "eventually" will receive the delete command, but you cannot be sure. Especially as the system is designed to heavily prefer data redundancy.
I would guess that encryption itself is a "trick" to avoid having to solve the "deletion problem".
Note that they are not saying they are not deleting the encrypted message contents too. What they are saying simply indicates that what they promise is that they delete the keys.
There are practical reasons to do it this way: You only need to ensure that you delete one key per user (you keep a "current" key, that is anything up to two days old, and a previous key that you delete once it reaches two days), vs. deleting a possibly much larger amount of data entries that might also be more likely to be cached all over the place.
If I were to design a system like that, I'd try to delete the contents, but assume that I'd miss something, and aim to delete the keys too. I'd probably also make at least portion of the key depend on a site-specific set of secret rolling over with time that it should be policy not to log etc. to make it even less likely that the full key would survive longer than it should.
Of course, "trying" is legally just a terrible way to not promise and still get sued. I get why their lawyers would want them not even mention the data itself.
Still...Facebook is not exactly trusted when it comes to the privacy of just about anything. They're trying to operate a service in the grey area between what they want to do and reality, and doing so depends heavily on people's trust in their intentions. You can guess how much I trust Facebook to keep my data private right now (if not from my timeline, then from the government, etc.)
Unless I misunderstand something here, the other party can store your data indefinitely, and no amount of DRM lockdown can really change that.
Please could someone with familiarity with English / EU law say if this is legal or not?
It might or might not be legal. But because of laws of physics and mathematics it's impossible for them to do it any other way.
-- you mean cost/benefit.
Nothing is impossible, if one is willing to pay the price.
This "deleting personal information" seems to fall within the spirit if the law
(http://www.legislation.gov.uk/uksi/2009/859/contents/made)
I have no idea if Facebook is covered by that law. I don't think they are, but maybe someone here knows more than I do. And maybe some groups are pushing for more organisations to retain data?
Does that mean the "encrypted photo" is deleted after 2 days, or is the photo's "identification key" (like a hash or ID) deleted after 2 days?
(edit: well I guess it is 20 seconds after it is received)
And: writing to (spinning) disk takes on the order of milliseconds. 20 seconds of RAM storage time (versus milliseconds) means several orders of magnitude larger working set size, which may well be larger than you can afford…
Don't fall into the trap of assuming that just because you don't get to see the data, that it's not stored all over the place at other companies.
All you need is an application that takes a picture without altering what is on the screen when you press both volume buttons, or something. Maybe even just takes a picture once a second for the next 30 seconds?
You could make an application explicitly for this purpose, and even build in the mirrored image logic. Only one person needs to do it, then every non-technical user can use it.
Knowing that nerds can break it isn't enough, the users need to understand that their 14 year old peer with no technical skills can also break it, without breaking a sweat.
A degree of trust is required in all relationships, but at least apps like these remove some of the incentive for abuse. And they make it impossible for someone to _inadvertently_ share your photos.
(And since sex drive is involved here, meaning there is a pretty strong incentive for laymen to go after the analog hole, it is especially important that people are made fully aware of the limitations.)
Snapchat notifies of a screenshot, but the screenshot can still be taken. The theory is Snapchat checks the photo album count and if there's an additional photo it assumes a screenshot and will notify the other party.
Here's a discussion on the topic:
http://stackoverflow.com/questions/13484516/ios-detection-of...
You can take a screenshot, but it notifies the sender.
Quote:
Can I take a screenshot of pokes I receive?
Yes. When you take a screenshot, your friend will see
[an icon] next to your name letting them know. While
pokes will disappear on the app, screenshots and photos
from other devices can capture your poke, so share
responsibly.
Edit: Fixed formatting."The Poke app for iPhone is a simple and fun way to say hello to your friends. You can send pokes, along with messages, photos and videos, to a friend or multiple friends at once. When you send messages, photos and videos, you can choose how long they'll be available for your friends to view up to 10 seconds. After that, they disappear from the app."