Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I replied above, but there are few communication tools with such a wide userbase that have forward-secrecy and similar strong E2E crypto built in and available. People die because of what they post to Facebook or what they send in Messenger, I know this for a fact. With E2E security locked to devices it means that in the few seconds it takes me to wipe my phone while someone is knocking on the door with a gun then the other party to the conversation is not going to be compromised. Is that sufficient?


A totally satisfying explanation! I apologize, you had every right to invoke the risking of lives. However, I hope your hopefully hypothetical dissident who is saying the things that cause armed men to knock knows to avoid Facebook altogether (you know, that company predicated on watching the things that you do and turning that knowledge into actionable data in exchange for money). Failing to do that is indeed an existential risk if one thinks one's speech is that threatening to $AUTHORITY_IN_BED_WITH_FB.

I'll admit, too, that my reaction to your statements is colored by my other comment in this thread, which consists of being shirty about a dude who pontificated about PGP being unnecessary because of FB's new feature, which of course is ridiculous. Lives wouldn't be being lost, I reasoned, because only the foolhardy and unprepared dissident uses a surveillance network to organize dissent.


As a former FB employee I can empathize with the desire to avoid the mass data trawling that is involved in using the product, but having seen things from the inside I also know that people working there really, honestly do have users best interests at heart. During my tenure I worked on the effort to create Tor hidden nodes so that people could use FB via secure channels and watched the E2E effort go from Alec's wild idea to an actual product ready to ship. There are risks in using any centralized service, but having also poured almost a decade of money and sweat into an actual secure service only to see it wither because most people really didn't care I have finally come around to the idea that the efforts which will have the most long-term impact are the ones that subvert a popular service into providing the sort of security and privacy from government agencies that we all hope to eventually see. At some point you have to decide who is a greater threat, and FB doesn't have an army and really does try to do their best to resist overly-broad efforts by LEOs to gain access to user data. I understand why you would have absolutely no reason to believe any of this, but those of us who spent a bit of time toiling away inside will still keep trying to fight the good fight to deliver what people really need even if we have to put it in a sometime unpleasant wrapper.


>As a former FB employee

Oh shit, sorry dude D:

>I understand why you would have absolutely no reason to believe any of this

Well, it's not really that. Most serious tech-folk have realistic conceptions of privacy issues (he said in a comment on HN, but whatever), and your response above shows that you likely do, too. The controlling suits, however, typically have different priorities. Thanks for your response!




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: