{"id":18693,"date":"2022-04-06T10:45:10","date_gmt":"2022-04-06T18:45:10","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/04\/06\/news-12426\/"},"modified":"2022-04-06T10:45:10","modified_gmt":"2022-04-06T18:45:10","slug":"news-12426","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/04\/06\/news-12426\/","title":{"rendered":"Meta Tries to Break the End-to-End Encryption Deadlock"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/624b8400a8eca935d76e7024\/master\/pass\/security-meta-endtoend.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Wed, 06 Apr 2022 11:00:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/lily-hay-newman\">Lily Hay Newman<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">After years of<\/span> tech companies and police fumbling and clashing over end-to-end encryption, Meta this week brandished a new tool in its arsenal that may help the social media giant resist government pressure to change course or weaken its plan to implement end-to-end encryption across its private communication services.<\/p>\n<p class=\"paywall\">On Monday, Meta <a data-offer-url=\"https:\/\/about.fb.com\/news\/2022\/04\/expanding-end-to-end-encryption-protects-fundamental-human-rights\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/about.fb.com\/news\/2022\/04\/expanding-end-to-end-encryption-protects-fundamental-human-rights\/&quot;}\" href=\"https:\/\/about.fb.com\/news\/2022\/04\/expanding-end-to-end-encryption-protects-fundamental-human-rights\/\" rel=\"nofollow noopener\" target=\"_blank\">published a report<\/a> about the human rights impacts of end-to-end encryption produced by Business for Social Responsibility, a nonprofit focused on corporate impacts. Meta, which commissioned the independent BSR report, also published <a data-offer-url=\"https:\/\/about.fb.com\/wp-content\/uploads\/2022\/04\/E2EE-HRIA-Meta-Response.pdf\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/about.fb.com\/wp-content\/uploads\/2022\/04\/E2EE-HRIA-Meta-Response.pdf&quot;}\" href=\"https:\/\/about.fb.com\/wp-content\/uploads\/2022\/04\/E2EE-HRIA-Meta-Response.pdf\" rel=\"nofollow noopener\" target=\"_blank\">its response<\/a>. In a study that took more than two years to complete, BSR found that end-to-end encryption is overwhelmingly positive and crucial for protecting human rights, but it also delved into the criminal activity and violent extremism that can find safe haven on end-to-end encrypted platforms. Crucially, the report also offers recommendations for how to potentially mitigate these negative impacts.\u00a0<\/p>\n<p class=\"paywall\">Since 2019, Meta has <a data-offer-url=\"https:\/\/www.facebook.com\/notes\/2420600258234172\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.facebook.com\/notes\/2420600258234172\/&quot;}\" href=\"https:\/\/www.facebook.com\/notes\/2420600258234172\/\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> that it will eventually bring end-to-end encryption to all of its messaging platforms. The security measure, designed to box services out of accessing their users&#x27; communications, has already <a href=\"https:\/\/www.wired.com\/2014\/11\/whatsapp-encrypted-messaging\/\">long been deployed<\/a> on the Meta-owned platform WhatsApp, but the initiative would bring the protection to Facebook Messenger and Instagram Direct Messenger as well. Meta has said that its delay in fully deploying end-to-end encryption on these other services largely has to do with technical challenges and interoperability issues, but the company has also faced <a href=\"https:\/\/www.wired.com\/story\/opinion-encryption-has-never-been-more-essential-or-threatened\/\">criticism<\/a> about the plan from the United States government and other countries around the world over concerns that adding the feature would make it more difficult for the company and law enforcement to counter a range of threats, like child abuse and distribution of child sexual abuse material, coordinated disinformation campaigns, viral hate speech, terrorism, and violent extremism. The US government, and the FBI specifically, has <a href=\"https:\/\/www.wired.com\/2016\/12\/year-encryption-won\/\">long argued<\/a> that comprehensive encryption that protects user data <a href=\"https:\/\/www.wired.com\/story\/fbi-backs-down-apple-encryption-pensacola-iphones\/\">equally protects suspects from criminal investigations<\/a>, thus endangering the public and <a href=\"https:\/\/www.wired.com\/story\/encryption-wars-facebook-messaging\/\">national security<\/a>.<\/p>\n<p class=\"paywall\">\u201cI am glad to see BSR\u2019s report affirm the crucial role that encryption plays in protecting human rights,\u201d says Riana Pfefferkorn, a research scholar at the Stanford Internet Observatory who was not involved in the study. \u201cWhile it\u2019s true that undesirable conduct occurs in encrypted contexts, most people aren\u2019t criminals, whereas everyone needs privacy and security. Weakening encryption is not the answer.\u201d<\/p>\n<p class=\"paywall\">The question for Meta and privacy advocates around the world has been how to develop mechanisms for stopping digital abuse before it starts, flagging potentially suspicious behavior without gaining access to users&#x27; actual communications, and creating mechanisms that allow users to effectively report potentially abusive behavior. Even very recent efforts to strike a balance have been met with intense criticism by privacy and encryption advocates.\u00a0<\/p>\n<p class=\"paywall\">For example, Apple announced plans in August to debut a feature that would <a href=\"https:\/\/www.wired.com\/story\/apple-csam-detection-icloud-photos-encryption-privacy\/\">scan user&#x27;s data locally on their devices for child sexual abuse material<\/a>. That way, the reasoning went, Apple wouldn&#x27;t need to access the data directly or compile it in the cloud to check for abusive material. Researchers raised a host of concerns, though, about the potential for such a mechanism to be manipulated and abused and the risk that it wouldn&#x27;t even accomplish its goal if the system produced a slew of false positives and false negatives. Within a month, <a href=\"https:\/\/www.wired.com\/story\/apple-icloud-photo-scan-csam-pause-backlash\/\">Apple backed down<\/a>, saying it needed time to reassess the scheme.<\/p>\n<p class=\"paywall\">In its report to Meta, BSR did not endorse such \u201cclient-side scanning\u201d mechanisms, saying that the approach ultimately produces an untenable slippery slope. Instead, BSR recommended that Meta pursue other mechanisms like safe and responsive reporting channels for users and analysis of unencrypted metadata to catch potentially problematic activity without direct communication scanning or access.<\/p>\n<p class=\"paywall\">\u201cContrary to popular belief, there actually is a lot that can be done even without access to messages,\u201d says Lindsey Andersen, BSR&#x27;s associate director for human rights. \u201cAnd what is essential to understand is that encryption isn\u2019t just any old technology, it\u2019s a really important means to advance human rights, and it&#x27;s unique in that way. I&#x27;m not sure we\u2019ve seen anything that has so many clear human rights benefits as end-to-end encryption.\u201d<\/p>\n<p class=\"paywall\">The BSR report includes 45 recommendations, 34 of which Meta has committed to implementing. The company says it will partly implement another four and that it is doing further research about six of the remaining recommendations. The company declined to adopt one recommendation related to exploring a special type of math known as <a href=\"https:\/\/www.wired.com\/2014\/11\/hacker-lexicon-homomorphic-encryption\/\">homomorphic encryption<\/a> as a means to potentially develop more secure client-side scanning. Meta says this recommendation is not worth pursuing because, it concluded, it is not technically feasible.<\/p>\n<p class=\"paywall\">Meta says that throughout BSR&#x27;s research process the company has been guided by the findings and that its direction is already largely aligned with BSR&#x27;s proposals. And at the beginning of March, the company rolled out end-to-end encryption for Instagram Direct Messaging in Ukraine and Russia in response to Russia&#x27;s invasion of Ukraine. The company told WIRED on Monday that it will not deploy the protection across its messaging services in 2022, but that it is planning to move forward in 2023.<\/p>\n<p class=\"paywall\">\u201cFrom a human rights perspective you realize there are tensions, but it isn\u2019t an either-or,\u201d says Gail Kent, Meta&#x27;s Messenger global policy director. \u201cThat&#x27;s something we are hoping that we can show in our product\u2014you don\u2019t need to choose between privacy and safety, you can have both. And we clearly know from speaking to users that users expect us to provide both. On Messenger or Instagram DMs they expect to have a trusted space where they can communicate freely without interactions they don&#x27;t want.\u201d<\/p>\n<p class=\"paywall\">After decades of going in circles on the problem, the debate won&#x27;t be resolved by one report. But it doesn&#x27;t hurt to have the biggest social media company on the planet pushing and investing to find a solution.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/meta-end-to-end-encryption-bsr-report\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/624b8400a8eca935d76e7024\/master\/pass\/security-meta-endtoend.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Wed, 06 Apr 2022 11:00:00 +0000<\/strong><\/p>\n<p>A new report Meta commissioned aims to redefine comprehensive encryption as essential to protecting human rights.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21465,21382,21357],"class_list":["post-18693","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-national-security","tag-security-privacy","tag-security-security-news"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18693","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18693"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18693\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18693"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18693"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18693"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}