Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Twitter thread on FB forcing an accelerated E2EE timeline for messaging apps (twitter.com/elegant_wallaby)
10 points by 1cvmask on Nov 23, 2021 | hide | past | favorite | 2 comments


Child safety has been repeatedly used as justification for terrible, egregious violations of privacy though. This is why E2EE proponents including myself remain highly skeptical.

As a recent example, Australia rolled out metadata retention mandates to ISPs under the explicit banner of child safety and terrorism prevention.

Immediately after implementation, numerous government bodies which have nothing to do with child safety or terrorism have full, unaccountable access to the system. Bodies like local government councils investigating littering. It was an extremely quick leap from "only for the bad stuff" to "actually, littering is bad enough you deserve to have your privacy desecrated". Other than those abuses, agents with access to the system have been caught using it to stalk girlfriends, acquaintances and otherwise. Repeatedly.

These child safety organizations are often used as a weapon by government to tear down privacy and institute mass surveillance. Not to mention these organizations are often so intertwined with government that it's hard to tell where the charity starts and the government ends.

For example, there are FBI agents working directly at NCMEC, the largest and most notable child safety organization pushing a lot of these initiatives. NCMEC also is independent in name only, in reality they have laws carved out for them that makes them appear to be a quasi-government agency. When they speak, I consider the words as coming from government. Because they are.

Child safety is a mirage. Governments do not care about child safety. If governments cared about child safety, they wouldn't have literally operated dark web CSAM websites, distributing millions of images of abuse. [1]

[1] https://www.usatoday.com/story/news/2016/01/21/fbi-ran-websi...


It's somewhat reasonable to say that algorithmically amplified content shouldn't be encrypted end to end.

But it is very weird to apply that to people's personal non-shared photo libraries (as Apple proposed, and it's no clear they have cancelled those plans), messages (as some are suggesting), and even to things like iPhone backups. To this day, iCloud is your only option for internet backups for your iPhone -- and it is not encrypted end to end.

The combination of monopoly control and weak encryption is not good for society. Apple should either allow for E2EE iPhone backups for those of us who know what we are doing (eg. let us generate a publickey), or allow third-party backup apps like Backblaze on the iPhone.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: