frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Meta Shuts Down End-to-End Encryption for Instagram Messaging

https://www.pcmag.com/news/meta-shuts-down-end-to-end-encryption-for-instagram-dms-messaging
59•tcp_handshaker•1h ago

Comments

aucisson_masque•1h ago
> Our messaging system has long been designed to balance user privacy with the ability to respond to scams, harassment, and other safety concerns when users report them or when required by law

TikTok about why they won’t put e2e for private messages.

I guess it’s reasonable to give up privacy to save the children, TikTok cares so much about our kids safety and wellbeing !

2ndorderthought•1h ago
This is awful. They are doing this so they can literally advertise to kids. I bet their dbs aren't encrypted at rest either. Complete foolishnes
chadgpt2•59m ago
Can you steelman TikTok's argument?
airstrike•3m ago
[delayed]
milderworkacc•1h ago
I'm not sure if this meets the bar for substantive and thoughtful discussion, but this kind of corporate cowardice, enforced by unelected bureaucrats standing at the bully pulpit is only going to get worse as the noose tightens on the open web.

The combination of hardware attestation and walled garden "app stores" is the end goal of most policymakers in this area, and it happens to suit the monopolists in Google and Apple and Facebook down to the ground.

Perhaps a timely reminder that things do not always get better over time, and that we may have lived past the high point of secure communications in our lifetime.

chadgpt2•44m ago
Do people expect that Instagram can't read their Instagram private messages? I don't think people expect that. And E2EE is not nearly as cheap as the HN crowd likes to pretend—how do those devices get those keys if not through a central service? Especially if one of them is a web browser?
onemoresoop•37m ago
Ok, so drop all pretense then and blatantly scavenge through private conversations?
ryandrake•33m ago
I would expect any message facilitated by a company's software, and going through that same company's servers to be compromised.
mrexcess•30m ago
The answer to most everyone question you’re asking is just, “public key cryptography”. It’s kind of disheartening to me that such basic 1990s tech as implemented by Phil Zimmerman is now obscure enough to merit questions like this.

Both parties exchange public keys through the central service. Only the possessor of the respective (on device, Secure Enclave ideally) private keys can decrypt the messages encrypted to the public key. The process can also work in reverse, encrypting with the private key so only holders of the public key can decrypt: this is called “signing”.

feurio•12m ago
And how does one verify that the public key received belongs to the intended party, rather than a mitm?

If the answer is blind trust in a third party that runs the messaging service then I suspect that you can guess what the people asking those questions are really asking.

rileymat2•8m ago
The fly in the ointment is that they control the software and updates to that closed software so can short circuit that with appropriate pressure.
2ndorderthought•1h ago
Instagram should be shut down. Not using encryption for social media and places where users expect any level of privacy is insanity.
chadgpt2•1h ago
Do users expect that Instagram can't read their Instagram chats?
weberer•24m ago
Yes, most people have the expectation that the carrier is not actively snooping on their conversations.
daniel_reetz•20m ago
Users generally do not believe Instagram is reading their chats. Source: I have had this conversation many, many times.
josh-wrale•1h ago
How likely is this about collection of LLM training data?
daft_pink•1h ago
I'm not sure the value of end to end encryption for proprietary application chats. For emails and SMS messages, your messages are being sent between different multiple servers on the open internet and it opens you up to spying, but end to end encryption on instagram is only protecting your chats from Meta.

I find the end to end encryption on Facebook to be detrimental to ease of use, because you always have to use a pin code, etc for the web interface.

If you don't trust meta with your chats, you probably shouldn't be using their application to begin with.

ergocoder•1h ago
Actually, by doing e2e encryption, Meta can say to the authorities that Meta doesn't see any message and cannot be blamed for anything. We cannot snoop user's conversation, and that's generally a good thing.

The authority holds Meta responsible anyway; they don't care about the implementation detail. They want to catch a pedo, and Meta is unable to produce evidence that helps them. Everyone else will yell at Meta for helping pedos.

You can substitute "pedo" with any other heinous crime e.g. terrorism.

And this is how we arrive at the current situation.

mrexcess•25m ago
> The authority holds Meta responsible anyway

What form of accountability are you suggesting is even being leveraged, here? No law could force Meta to backdoor its encryption, afaik. Public pressure would be unlikely to work.

Is Meta afraid of anything real, or is this just blame shifting via ungrounded speculation?

ergocoder•18m ago
They can because Meta has chosen to implement e2e encryption. They could have chosen not to implement e2e encryption. All within their controls.

Australia already has this law in place where a company must hand over user's conversation. A company cannot make an excuse that they themselves implement e2e to prevent themselves from reading user's messages. Source: https://www.bbc.com/news/world-australia-46463029

UK has a proposal to ban encryption this year. It is still being discussed.

> Public pressure would be unlikely to work

Public pressure works to a certain degree. Do you think a product manager at Meta would want to be labeled as "protecting pedos"?

Barrin92•49m ago
the entire point of encryption is that you don't trust the channel you communicate through, that's what it was invented for, communication across adversarial channels. Distrust is the only condition under which you need encryption.

In addition from a practical POV it's if anything the reverse is the case. Email encryption is larp security because plain text is the default, leaks metadata and its interfaces make it trivial for people to leak entire conversations. If there's one technology where you should just assume your messages are public, it's email before someone copy pastes or wrongly forwards your encrypted communication to fifty other people.

Private message encryption makes sense because it's now a default, information exchanged is usually personal, and the problem isn't just Meta but law enforcement extorting your data out of their hands, which encryption in the real world has prevented a few times now already.

ergocoder•12m ago
It's a governance.

The executives don't want anyone else to be able to use the messages in a malicious way, so they decide to cut it at the sources of the messages i.e. e2e encryption.

This is like: corporate emails being deleted after 6 months. When an authority asks for emails from the last year, they can say they don't have it.

Now the authority can ask for the emails not to be deleted at all but then that will be a different battle the authority has to fight.

Corporate emails often don't involve pedos/terrorism, so there's much less push to retain corporate emails forever.

shiandow•49m ago
I'm not sure I disagree, but I would summarise it slightly differently.

If you don't want Mark Zuckerberg to upload your private messages into his own chat AI, then stop using Instagram immediately.

sedatk•17m ago
> but end to end encryption on instagram is only protecting your chats from Meta.

No. It protects your chats from Meta and all governments of the countries where Meta operates.

In fact, I expect Instagram to be more reachable globally now because these relaxed communication standards would be welcomed by oppressive governments as they can now retrieve messages as they please for whatever purpose they deem.

tylerchilds•45m ago
Put simply:

I’ve talked to Apple engineers.

Siri fell behind due to how good Apple’s privacy is.

Everyone made fun of them for protecting them.

This is exactly the opposite of that, where Mark is throwing you and your children under the bus again because he’s unoriginal and doesn’t know how to make money any other way than by getting all up in your business, statistically.

cyanydeez•43m ago
thats a generous view. The dystopian fascist view is he's aligning with the surveillance state's interests and instagram is seen as a breeding ground for anti-american-american activities.
nothinkjustai•43m ago
Apple feels like the only big tech company that remotely cares about its users. Thank god they make the best computer and OS too.

I’m sure this will not be a popular take on HN however.

dwedge•28m ago
Android was originally enticing because of iOS locking everything down and controlling the ecosystem
throw1234567891•27m ago
“But I want my freedom, I want to install whatever I want, bad Apple for locking down my devices away from me.”

They stay rather secure because of all these measures. But they’ll get dismantled, too. Because idiots push idiots in power to weaken Apple’s stance. Useful idiots is the right term.

Handy-Man•42m ago
They were kinda forced to in the name of "think of the children". The New Mexico case that's been going on at the moment.
al_borland•28m ago
I usually defend Siri, because I’m perfectly fine trading a little functionality for security. I prefer it that way.
stego-tech•24m ago
Same. The fact they're shoving AI into it and expanding it to providers who don't have privacy as a guiding principle is a key reason I'm sitting on a 14 Pro still, and why I'm exploring local alternatives with Home Assistant.

Besides, we just need to set verbal timers and control music. We don't need a full-blown verbal Oracle.

kypen•14m ago
Home Assistant is indeed quite nice and relatively simple to set up with the Docker images provided by the team. Device setup on iOS was a little inconsistent, but has been rock solid for over a year. Check out Homebridge as well. I run both.
amazingamazing•5m ago
Im curious what the threat model is that you're protecting against
tyre•4m ago
They’re hosting their own Gemini, so they aren’t sacrificing to Google’s standards even if using their technology.
dyauspitr•25m ago
Privacy is the reason I’m still on team Apple.
bramhaag•23m ago
Apple's response to the UK gov asking to see users' iCloud data says enough about where their priorities lie [1]. They do something far worse in China [2].

Don't fool yourself into believing Apple cares about your privacy. They care about money.

[1] https://www.bbc.com/news/articles/cgj54eq4vejo

[2] https://www.reuters.com/article/technology/apple-moves-to-st...

alex1138•16m ago
Do you know what Zuckerberg said in an interview? I think it was to Lex Fridman but I could be wrong

"Apple hasn't come up with anything new in 20 years"

Very likely in response to Apple's granularity. Poor Zuck can't steal people's credentials

alex1138•24m ago
While encryption already ruined FB Messenger (no comment on IG encryption or lack of but people have hated Insta since Zuck took over)

While they ALREADY probably only have Messenger for nefarious reasons https://news.ycombinator.com/item?id=4151433

He's a bit of a... something. That might get a 'low effort comment' moniker attached to it. Rhymes with ociopath

Google broke reCAPTCHA for de-googled Android users

https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users
399•anonymousiam•4h ago•140 comments

You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE)

https://ze3tar.github.io/post-zcrx.html
99•MrBruh•3h ago•62 comments

AI is breaking two vulnerability cultures

https://www.jefftk.com/p/ai-is-breaking-two-vulnerability-cultures
186•speckx•5h ago•79 comments

AWS data center outage hits trading on Fanduel, Coinbase

https://www.cnbc.com/2026/05/08/aws-outage-data-center-fanduel-coinbase.html
24•bigflern•1h ago•6 comments

Cartoon Network Flash Games

https://www.webdesignmuseum.org/flash-game-exhibitions/cartoon-network-flash-games
255•willmeyers•7h ago•85 comments

AWS says data center overheating in North Virginia disrupts services

https://www.reuters.com/business/retail-consumer/amazon-cloud-unit-says-data-center-overheating-n...
76•christhecaribou•20h ago•35 comments

Non-determinism is an issue with patching CVEs

https://flox.dev/blog/achieving-rapid-cve-remediation-in-an-era-of-escalating-vulnerabilities/
26•mathewpregasen•2h ago•7 comments

Looking at the data behind prediction markets

https://asteriskmag.com/issues/14/are-prediction-markets-good-for-anything
38•kqr•1d ago•12 comments

David Attenborough's 100th Birthday

https://www.bbc.com/news/articles/cp3pww9g0p5o
387•defrost•11h ago•74 comments

Wi is Fi: Understanding Wi-Fi 4/5/6/6E/7/8 (802.11 n/AC/ax/be/bn)

https://www.wiisfi.com/
21•homebrewer•2d ago•2 comments

Serving a website on a Raspberry Pi Zero running in RAM

https://btxx.org/posts/memory/
182•xngbuilds•8h ago•74 comments

Mux (YC W16) Is Hiring

https://www.mux.com/jobs
1•mmcclure•2h ago

An Introduction to Meshtastic

https://meshtastic.org/docs/introduction/
361•ColinWright•12h ago•135 comments

Compound drivers of Antarctic sea ice loss and Southern Ocean destratification

https://www.science.org/doi/10.1126/sciadv.aeb0166
14•littlexsparkee•1h ago•0 comments

Meta Shuts Down End-to-End Encryption for Instagram Messaging

https://www.pcmag.com/news/meta-shuts-down-end-to-end-encryption-for-instagram-dms-messaging
64•tcp_handshaker•1h ago•39 comments

All means are fair except solving the problem

https://yosefk.com/blog/all-means-are-fair-except-solving-the-problem.html
24•akkartik•2d ago•26 comments

Rumors of my death are slightly exaggerated

1465•CliffStoll•2d ago•227 comments

Teaching Claude Why

https://www.anthropic.com/research/teaching-claude-why
50•pretext•5h ago•10 comments

Mojo 1.0 Beta

https://mojolang.org/
262•sbt567•20h ago•170 comments

US Government releases first batch of UAP documents and videos

https://www.war.gov/UFO/
209•david-gpu•11h ago•324 comments

Poland is now among the 20 largest economies

https://apnews.com/article/poland-economy-growth-g20-gdp-26fe06e120398410f8d773ba5661e7aa
873•surprisetalk•11h ago•719 comments

PC Engine CPU

https://jsgroth.dev/blog/posts/pc-engine-cpu/
115•ibobev•9h ago•50 comments

Maybe you shouldn't install new software for a bit

https://xeiaso.net/blog/2026/abstain-from-install/
812•psxuaw•1d ago•427 comments

Man finds $1M worth of Yu-Gi-Oh cards in a dumpster

https://www.404media.co/man-finds-1-million-worth-of-yu-gi-oh-cards-in-a-dumpster/
94•danso•2d ago•32 comments

Roadside Attraction

https://theoffingmag.com/essay/roadside-attraction/
15•aways•3h ago•3 comments

Show HN: GETadb.com – every GET request creates a DB

https://www.getadb.com/
22•nezaj•7h ago•29 comments

Ask HN: We just had an actual UUID v4 collision...

280•mittermayr•15h ago•238 comments

Podman rootless containers and the Copy Fail exploit

https://garrido.io/notes/podman-rootless-containers-copy-fail/
111•ggpsv•10h ago•23 comments

My first in-prod corrupted hard drive problem

https://blog.pavementlink.ch/2026/05/07/my-first-corrupted-hard-drive-problem/
33•r1chk1t•3h ago•26 comments

GeoJSON

https://geojson.org/
144•tosh•13h ago•68 comments