Alec Muffett Profile picture
Oct 24, 2021 15 tweets 10 min read Read on X
> My interview with @StevenLevy of Wired re: @FrancesHaugen leaking my Facebook Engineering “Goodbye Post”

I'm posting this with password-embargo until Steven's @WIRED article is posted; but I have a message for Frances Haugen in this screencap extract.

alecmuffett.com/article/14994 Image
Frances is talking to @CommonsDCMS tomorrow, so she should have opportunity to bring this message of privacy and safety to people who would benefit from it.

/cc @DanMilmo

theguardian.com/technology/202… Image
Oh dear, oh dear:

>Facebook whistleblower warns ‘dangerous’ encryption will aid espionage by hostile nations

>Ex-employee has taken aim at Sir Nick Clegg and warns new encryption plans are an attempt to cover-up harmful online material

This is deeply bizarre of @FrancesHaugen - she is arguing that if Facebook willingly surrenders its ability to spy on user content — including on behalf of, say, the Chinese Government — then it cannot protect those users *FROM* the Chinese Government. ImageImage
She is literally proposing that Facebook should act in a supranational manner, and in the process should deny users from having message privacy.
I don't think she has thought this through terribly well; not to mention that one of the documents she leaked IS LITERALLY ALL ABOUT THIS, I KNOW BECAUSE I WROTE IT.

We are now in an exciting situation where we can pit one Facebook whistleblower against another re: E2E Encryption!

And we can also ask @FrancesHaugen if she believes that Facebook should protect UK users against malware sent by the @NSAGov or @GCHQ?

ps: if you're interested in a thumbnail sketch of the harms which will be *caused* by banning "harmful feed algorithms", here's my take on it.

A question for @FrancesHaugen at @CommonsDCMS tomorrow: should Facebook be responsible for protecting #EU citizens from state-sponsored malware being deployed by @GCHQ?

theguardian.com/uk-news/2018/s… ImageImageImage
If you want to read the unexpurgated DT article, this appears to have the content: archive.md/9qVz3
Here is a point which really does demand being driven home tonight:

Anyone who tells you that they know how "Facebook Messenger with Default End-to-End Encryption" will behave, is fibbing; especially re: anti-abuse features.

Choices of feature and "what gets launched" will still be in the air. Features can take months if not years to be shipped.

Speculate all you want but it will still just be hot air — as will any statement which declares the app to be "a recipe for disaster".
Looks like the meeting with @FrancesHaugen
and @CommonsDCMS #OnlineSafetyBill kicks off around 1430h London time.

I'm presuming that the next tranche of docs and articles will be posted a bit before then, to create dramatic tension?

parliamentlive.tv/Event/Index/cd… Image
Wow, just, wow. You can read this article at NYT by setting up an account (preferred) or by disabling JavaScript (NoScript?) and doing a page reload.

I'm not going to post a screenshot, there's too much to pick from.

In case you're still reading this thread, the saga continues here:

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Alec Muffett

Alec Muffett Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @AlecMuffett

Nov 2, 2023
Hot on the heels of #ChatControl and in the name of “identity” and “consumer choice” the EU seeks the ability to undetectably spy on HTTPS communication; 300+ experts say “no” to #Article45 of #eIDAS #QWAC alecmuffett.com/article/108139
If you would like to see more discussion regarding:

Regulation: EU Digital Identity Framework — including #eIDAS and #QWAC

…here's a #ReadyMadeTwitterSearch with links & more information at: github.com/alecmuffett/re…
Read 8 tweets
Jul 20, 2023
When Signal and WhatsApp have fled the surveillance of the #OnlineSafetyBill, what app will still be around for politicans, journalists, and actual normal people to use, securely.

The answer might be this:

alecmuffett.com/article/85187
@JohnNaulty @matrixdotorg Let's be clear: we are talking about the evacuation of the entire Signal and WhatsApp userbase / niche, from the United Kingdom.

That's a lot of people.
WOW:

- No Signal
- No WhatsApp
- No iMessage
- No Facetime

@jamesrbuk called it #internexit; the UK will be extraordinarily isolated from the rest of the internet.

bbc.co.uk/news/technolog…
Read 15 tweets
Jul 21, 2022
All Watched Over By Filters Of Loving Grace: GCHQ's Holistic, Sociotechnical , "Thoughts on Child Safety on Commodity Platforms" #ghostProtocol #ghost #NCSC
alecmuffett.com/article/16236
THE NEW GHOST PROTOCOL PAPER'S UP!

tl;dr —

* @GCHQ like client-side filters

* …and ghost chat participants

* …and would like everyone else to buy into them defining what E2EE means

* …because they *don't* like simple definitions of E2EE

arxiv.org/abs/2207.09506
Read 17 tweets
Jul 20, 2022
I've been saying stuff like this for ages, maybe if @alexstamos says it too then people will listen? #DMA
Inevitably the response is something glib like "Use Matrix"
A big part of the the reason for the existence of that API was because the European Union wanted to enable people to access their data; so they created the problem, complained when the inevitable leaks happened, and are now reinventing it
Read 4 tweets
Jun 10, 2022
Could be the attached, but my suspicion is that this is going to be another CYBER! DARKWEB! CYB3R! SYBER! CAMBRIDGE ANALYTICA‼️BRAIN CONTORL! YOU SAW AN ADVERT AND SO A RUSSIAN ARTIFISHIAL INTELLIGENCE APP MADE YOU VOTE FOR UKIP! … thing.

READING BETWEEN THE LINES:

Plucky spooks in Cheltenham but dressed for speed-dating in 2015-era Shoreditch, battle "Russian influence operations" that Nadine Dorries will soon cite as rationale for the #OnlineSafetyBill.

Token American subplots help sell the series to the US.
Read 4 tweets
Jun 2, 2022
Back in 1991 I published an open-source password cracking tool which defined the state of the art for the next 5+ years, so much so that echoes of it can be found in all major password crackers of today.

Some folk criticised me for doing this, choosing words like these to do so: Image
I know that in general it's bad form to take a single quote out of context and use it to critique an entire essay (concerned.tech) — but I do feel that this time it's deserved.
The concerned-dot-tech essay has had extensive technical debunking, e.g.:

1/ prestonbyrne.com/2022/06/01/deb…

2/

…but that's not what bothers me.
Read 12 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(