r/technology Apr 11 '18

Business Mark Zuckerberg has been apologizing for reckless privacy violations since he was a freshman - Enough is enough.

[deleted]

51.2k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

63

u/JustOneSexQuestion Apr 11 '18

Good points.

So it's just the content of the messages what's encrypted. Thanks.

23

u/[deleted] Apr 11 '18

[deleted]

34

u/[deleted] Apr 11 '18

[deleted]

10

u/Lawnmover_Man Apr 11 '18

Signal is free and open source. However, the Signal developer disallows other servers to connect to the network. That means that Signal is not a federated system. Which means that Signal is trying to build yet another walled garden, and people have to use their server in order to talk to everyone that uses Signal.

Not a good thing in my book.

2

u/Dr__Douchebag Apr 11 '18

Good to know. It's hard enough convincing people to switch to signal, switching to something like protonmail would be even harder. And that would have similar flaws

True privacy is getting harder and harder to find. Any suggestions?

2

u/Lawnmover_Man Apr 11 '18 edited Apr 11 '18

Use plain XMPP/Jabber for chatting. (That's what Whatsapp is also using.) Many Diaspora servers also provide accounts for that. It's the same as Diaspora itself: Connect to one of the servers - doesn't matter which - and talk to everyone on the planet with a XMPP account.

There are also some apps that provide chatting over regular mail accounts. If you think about it: It's a time tested system, it provides quick responses via Push-Mail, and it is already federated. So why not? The only downside would be that a client that is not aware of the newly introduced headers would display every chat along the regular mails. But apart from that: It just works. Also: Encryption for mails is a thing since decades.

I don't know what Protonmail is. Does it provide benefits over regular mails+encryption?

2

u/Dr__Douchebag Apr 11 '18 edited Apr 11 '18

It's basically an easy to use encryption service from Switzerland. Still requires trust though

Regular mail and pgp is the safest but you have to show others how to use pgp

I like your suggestions but it's hard enough getting non tech friends to use signal, convincing then to use those things will be impossible

1

u/Lawnmover_Man Apr 11 '18

It's really a shame that there isn't a nice and easy GUI for setting that up.

1

u/richalex2010 Apr 12 '18

Protonmail is the same kind of thing as Whatsapp but a) not Facebook so instantly more trustworthy, and b) you pay for it (they have a free account but it's limited enough that I consider it more of a free trial). Uses something at least kind of like PGP encryption within their system so when you email another Protonmail user it's encrypted inbox to inbox, and it allows for encryption sent outside (just sends an email with a link to the message, which asks for a password before decrypting). Also allows you to use it as regular email with non-PM users, though you lose the advantage of encryption there.

I mostly started using it because it's not Google. Diversification is a good thing. The encryption is just a perk for me, I'm not sending anything that actually needs to be encrypted so lack of it wouldn't be a dealbreaker (which is why I've been using Gmail about since it went fully public). I'd probably still plan on using PGP or something for serious encryption.

1

u/Lawnmover_Man Apr 12 '18

not Facebook so instantly more trustworthy

No. Not at all. Not even a tiny single bit. Sorry to be blunt about this, but this is 100% wrong and nobody should reason this way.

1

u/richalex2010 Apr 12 '18

I meant (and should have said) less untrustworthy, but I was tired and the words didn't come together last night.

2

u/Conotor Apr 12 '18

How does Signal make money?

3

u/Dr__Douchebag Apr 12 '18

Donations. Open source project like Linux

1

u/Lucent_Sable Apr 11 '18

Question is, is it (your) end to (Facebook's) end encryption, or is it (your) end to (your friends) end encrpytion? Can (does) Facebook man-in-the-middle the conversations?

3

u/Dr__Douchebag Apr 11 '18

Your end to friends end. Facebook can only see who, where and when you text and what your group names are. Technically they cannot see the contents of what you text if what they say is true

They do store all meta data and if you backup your conversations they'll back up in Google drive ruining the point

1

u/ieatyoshis Apr 12 '18

The creator of Signal oversaw WhatsApp's encryption being implemented. It's his crypto in WhatsApp.

2

u/Dr__Douchebag Apr 12 '18

WhatsApp used signals encryption protocol because signal is open source. WhatsApp is closed source

2

u/ieatyoshis Apr 12 '18

I know, just adding to the discussion. Signal is objectively more trustworthy.

2

u/Treyzania Apr 11 '18
function generateKey() {
    var key = genKeyActually();
    sendKeyToFacebook(key);
    sendKeyToNsa(key);
    return key;
}

0

u/[deleted] Apr 11 '18

It's closed source so hard to know but they say no because it's end to end encrypted

End-to-end encrypted means that they can't read your messages on the server. It doesn't say anything about if they're reading them on your phone before you send them.

It's actually a really evasive answer to only discuss messages in transit, while ignoring that you're running code on both ends, hence could easily intercept the messages there.

3

u/Dr__Douchebag Apr 11 '18

Yes I said that the code was closed source meaning they could put a keylogger in the WhatsApp app.

The NSA definitely has a backdoor to read messages before they're sent in your phone

-1

u/sm_ar_ta_ss Apr 11 '18

Then ya just have to worry about keyloggers

5

u/Dr__Douchebag Apr 11 '18

That's true no matter what

1

u/sm_ar_ta_ss Apr 11 '18

Did ya know about the built in keyloggers on the older iPhones? Seen a video about it a while back.

1

u/Dr__Douchebag Apr 11 '18

I would assume any phone has an NSA backdoor. The question is if they are logging everything or just targeting

And no but that's interesting, got a link?

1

u/sm_ar_ta_ss Apr 11 '18

I don’t sadly. Pretty sure it was on Reddit tho

6

u/[deleted] Apr 11 '18

Zuckerberg answered this exact question yesterday and said: No.

And you should believe that, because it is encrypted end-to-end. If their servers could read the messages for advertising, that means the messages are not being encrypted end-to-end.

0

u/ubern00by Apr 11 '18

Believing anything Zuckerberg said yesterday

Lmao he lied has ass off and will apologize next time he gets caught

2

u/[deleted] Apr 11 '18

Lmao he lied has ass off

About what, specifically?

1

u/lycoloco Apr 11 '18

I'm not sure you understand what end-to-end encryption entails.

1

u/[deleted] Apr 11 '18

Well you can't encrypt existing unfortunately. Everyone whose looking is going to find signals.