Hacker News new | ask | show | jobs
by cwe 5083 days ago
Do you consider SMS private communications? Your cellphone carrier is just as likely to eavesdrop on your SMS history as FB does your chats.
4 comments

> Do you consider SMS private communications?

That question has a complex answer. In short: not really.

Unfortunately, I know a little too much about phone networks to have a representative answer. I know very little about Facebook, except that its users usually attribute to it more privacy than it really offers. Trying to understand why that is is the reason for my question.

Yes. On one hand there are quite strong laws about privacy for phone companies and second I pay them. By contrast, I would not pay FB even if I had an account. Their entire business model is, that they are selling private data. ( Technically it is unfortunately neither for FB nor for telcos a problem to eavesdrop.)
There's an illusion in online communication that makes the average user think any particular message they send is like physically handing a message to another person. Using Gmail as an example, sure, your email goes to the right person, but you first send it to/through Gmail. They just happen to pass it along to the recipient.
I consider FB chats to be much less private because they actually get stored on a server somewhere by default. Also I can access them anywhere with an internet account. Neither of these things are true of SMS.
There is nothing preventing your SMSs being saved in a telco DB. I'm fairly certain they are.
AT&T cops to saving SMS messages, not just "pen trace" (sender/recipient data), for up to 72 hours. For "delivery purposes" only. Though the release I read doesn't specify to whom.

http://gizmodo.com/349308/verizon-att-respect-your-sms-priva...

http://www.flickr.com/photos/jdawg/93928749/

Well sure it might be, but it doesn't have to. FB messages always get saved, no question.
FB chat messages don't have to be saved either.
If I log in and click the Messages button I can see all my messages. To do that they have to be on their server. There isn't an off-the-record button I missed is there?
Ideally Facebook would use public-key encryption for chats and allow each user to individually save the history with their own passphrase they input encrypting it client-side.

But hey, auto-saving history without prompting you is worth it, right? (Also figuring out what to advertise to a user.)