Instagram quietly drops end-to-end encrypted chats

https://lemmus.org/post/20815993

shocking
The shocking thing was that they implemented it in the first place.
You cannot convince me that it was true end to end encryption. They had an eye in every chat.

I wouldn’t try to LOL

But there is valid reasoning for it. The metadata is equally as valuable as the actual content. That’s why WhatsApp is so profitable. If more people are using it then it could be seen as worth the tradeoff.

well, they can have true E2EE and still be able to read or exfiltrate the messages, because they control both ends…
My guess is that they implemented e2ee (or at least they claimed to do it) so people wouldn’t be as likely to switch to actually secure messaging platforms. “See here, pleb, our systems are very secure too. You don’t want to switch to Signal, and your friends are all here anyhow”

a surprising move

Was it, though?

I always laugh when I hear about meta’s end to end encryption because it isn’t remotely true in the sense that people would care about from a privacy standpoint. I know it is the case for messenger, I have not confirmed for other meta services, but in messenger the messages are encrypted in the way you would expect with the one big caveat being that meta stores your private keys on their servers. Iiirc meta explained that it is still e2e because they don’t unencrypt it which I find hilarious.
bro, I swear I won’t read it bro, you can trust me bro - yo

My understanding is that Whatsapp is “real” e2e and it’s based on signal protocol. That app is the main IM in many countries so they’ll probably won’t mess too much with it

I didn’t really expect Instagram or messenger to be really encrypted

Of course. Can’t train the LLM if they can’t read them.
Now we can spy openly…
And then they will be able to finally replicate that black mirror episode where someone is paying a subscription to chat with a LLM trained on the chats of the deceased partner
Meta wins patent for AI that could post for dead social media users

The company says its just a concept, and doesn't plan to advance the idea.

Mashable
Literally owning someone’s soul.
Worse, advertiser’s can’t read them!
How could they target ads if they can’t read all your private chats?
Metadata. They would still know where you were, for how long, who you talk to, when and from where. Then they combine these info. ex: you call your pop and mom, théir fridge broke down, and you start receiving ads for fridges. Was Meta listening?? No: pop and mom hinted the fridge was down (Google search or other), Meta has established your family links a long time ago, and you usually visit them after a longer than usual conversation (as they have an issue and yuu go help). Here: you fridge’s ads.
i’m getting to the point where if someone i don’t know that well starts talking to me about some bullshit on instagram, i immediately judge them
Glad to read that it’s not just me.
Using any meta’s service is privacy nightmare.
im guessing messenger and potentially whatsapp are next
How is it surprising that one of the companies that is pushing to force Internet ID laws through state legislatures is removing encryption from their chats?
Not even WhatsApp has e2e anymore less alone that dumpster
FOR REAL??
From what I saw the employes can easily request to see messages, as for how it’s done no idea, either client side after decrypting or server side.
Does anyone know if they’re unencrypting chats that already happened? Like my chat history? If so that’s fucked up
If they can, then it was never e2e encrypted.
Well e2e encryption is never private for the entity contrilling the endpoint. Instagram could push an update which decrypts and uploads your past chat history. Of course they’d only do it for your benefit so you don’t lose any data /s

They could always do that, and basically anything you can read on your phone, they can access if they need.

Encryption is a math thing: generate a pair of keys: one te encde, one to decode. I broadcast the one to encode (“public key”), and the whole world is tu use it to send me encrypted messages. I keep the decoding (“private key”) only for myself.

In client to erver encryption, we exchange keys with the server through which go all the comms: it decodes my messages and re-encodes them for my contact.
In e2e, the key exchange is between contacts: the server does not have the private keys.
In Meta, the proprietary app can send your private key to the server and then they know what you wrote. You have no way to know it doesn’t do so!

Opensource audited software is the only way to make sure.

WhatsApp is next. Run while you can.

I just always assumed that WhatsApp wasn’t secure…

Even more so when they made it so your chats trained their AI, default opt in, and no global setting, has to be disabled per chat.

Nothing about this is surprising to those paying attention.