Hacker News new | ask | show | jobs
by masterof0 1240 days ago
Taking into account that they are known to work closely with the FBI. So what they call e2ee cryptography is ridiculous. Their business is built off violating users privacy, why would anyone trust them? They've got your keys. Signal exists for this very reason.
3 comments

Technically we also trust Signal not to push a signed update to their software that exfiltrates our keys. Whether or not Meta is doing E2EE should be clear from snooping their protocol or reverse engineering the software.
Nothing is stopping you from auditing the code and building the client software yourself: https://github.com/signalapp

You don't even have that option with closed source software.

> Taking into account that they are known to work closely with the FBI

This is basically true for any sizable company in the US. And this is also true with small companies. If the FBI wants to work with you, you don't really have a choice.

And if you're not in the US, you're working with whoever is the FBI in that country.

No you are not, many companies have warrant canaries. Or make public the warrants, and state exactly all the information they can share with the authorities, that is usually nothing besides IP, or device the customer used to connect. My point was that Facebook will decrypt(in the case that are really encrypted) your messages.
> many companies have warrant canaries

Many? It feels like it's been 10 years since I've seen one, and it's only a US thing. I'm wondering if Signal still has one (I can't find it, so maybe the canary is "dead"). Canaries are also a legal grey area.

> My point was that Facebook will decrypt(in the case that are really encrypted) your messages

That's FUD.

I think some users might be happy that the average FB engineer can't just see all their messages.

That the FBI can is a concern to absolutists, but I don't think the masses.

> I think some users might be happy that the average FB engineer can't just see all their messages. Maybe not the regular L4 SDE, but the people who are supposed to see it, can and will see it.