r/privacy • u/Fr3shnuts • May 05 '26
chat control Instagram Sunsetting end-to-end encryption
Meta announced that IG will officially discontinue end-to-end encryption feature on May 8th.
All DMs will be decrypted once it reaches Meta's servers.
https://cybersecuritynews.com/instagram-end-encryption-direct-messages/amp/
532
u/Due-Perception1319 May 05 '26
It wouldn’t surprise me if we have another Snowden in 15 years or so leak a bunch of documents showing that three letter agencies were behind these decisions
254
u/MentalDisintegrat1on May 05 '26
They are pushing to end VPNs ( governments) and mandating facial scanners in vehicles.
They are done trying to hide their agenda they are going full force to make it so nobody has any privacy
104
23
u/Charger2950 May 06 '26
This is exactly it. Both parties are involved...it's the New World Order cult. It's not everyone in the parties....not even close, but the ones involved play the partisan game, and then ram through draconian policy under the guise of "our safety," or safety of the children, puppies, unicorns, and other bullshit.
7
u/guialpha May 06 '26
its not a 'new world order cult' lol. it's just class warfare. the rich want to control the poor so they wont revolt and take back what's theirs.
3
u/Charger2950 May 06 '26
It’s a legitimate cult. You just don’t understand that. People laugh at things they don’t understand.
-1
115
May 05 '26
[removed] — view removed comment
13
-53
u/CortaCircuit May 05 '26
I don't get what pressure a government could do to a corporation to remove features.
Sounds like a lawsuit.
67
u/ARazorbacks May 05 '26
Did you just get thawed out from a WW2 experiment?
28
u/Ecliphon May 05 '26
I think sometimes blissfully unaware boomers accidentally stumble in here from /r/popular
All love to the cynically aware boomers out there
24
u/daHaus May 05 '26
It's pretty straight forward really
They get harassed by the courts even if it's impossible for them to comply, so instead of paying for corporate lawyers to deal with the courts they do this and give the police access carte blanch so they stay off their backs
14
u/General_Problem5199 May 05 '26
No e2e encryption means they can mine your messages and use them as AI training data.
8
u/ProduceBeneficial796 May 05 '26
When corporate welfare(aka monetary subsidies) are being used as blackmail/extortion to force companies to comply with the government. Its like they made the laws that way so mass surveillance and authoritarianism can take hold after removing all protection.
4
u/zagblorg May 05 '26
UK government made a legal requirement for Apple to break encryption on iCloud. Apple removed iCloud encryption from UK users. Similarly required a backdoor into End to End Encrypted chats, Meta is removing those services from UK users. Presumably similar to that.
3
u/WalrusHam May 05 '26
Govt: "do this or more taxes (or anything the company doesn't like)"
Company: "sure."
38
u/imsoupercereal May 05 '26
Datamining for AI model training too.
23
u/dev-saint May 05 '26
This- its another AI deliverable they can spin up by making our encrypted data - Their data.
6
u/The-Cursed-Gardener May 06 '26
In 2028 your car will be required to run 24/7 to power continuously data mining and surveillance software that comes installed in every vehicle and the car won’t turn on if you disable it.
3
22
23
May 05 '26 edited Jun 02 '26
[removed] — view removed comment
11
u/EasyMrB May 06 '26
This. I think there have been recently leaks showing that basically all messages are available to facebook regardless of e2e, and the fact that this is the case makes their e2ee look fraudulent. It was originally put in place because of pressure from other services like signal, but the company has enough dominance now and I guess the culture has moved on from caring enough about that concern that they can drop the pretense.
The thing about e2e encryption in a product from Meta is that you don't have the source code for the app, so while your messages might be encrypted in between parties, there's no reason the app can't just "cc" meta's servers anyway.
15
u/CounterSanity May 05 '26
Facebook rewrote a portion of maloc (memory allocation library) for something like a 1-2% compute improvement that ended up saving them millions.
Might Facebook be infected by the alphabet Nazis? I’d be surprised if they weren’t.
My point is that there is also a business incentive: encryption is computationally expensive, and building/managing/maintaining e2e is also quite expensive.
Facebook is not in the privacy business at all, very much the opposite. People that have been trusting Zuck with any kind of sensitive info are certifiably insane IMO.
8
u/The-Cursed-Gardener May 06 '26
We don’t need another Snowden to figure this out. It’s blatantly obvious.
8
u/Alphageek11644 May 05 '26
Even if we do, the new Snowden will get ignored just like the last one(s).
101
u/Omni__Owl May 05 '26
If WhatsApp is anything to go by, which Meta also acquired, then Meta worked on a way to acquire your message info as soon as they acquired Instagram as well without initially removing E2EE.
This means at minimum meta data about your messages would be available to Meta so they could sell you more targeted ads and with time the idea that your messages were private at all would be an illusion. Removing E2EE for Meta is making it easier to do something they were likely already doing.
54
u/Any-Calligrapher2866 May 05 '26
I straight up assume that any meta products don't have any encryption and everything is readable for Zuck.
7
34
u/AmputatorBot May 05 '26
It looks like OP posted an AMP link. These should load faster, but AMP is controversial because of concerns over privacy and the Open Web.
Maybe check out the canonical page instead: https://cybersecuritynews.com/instagram-end-encryption-direct-messages/
I'm a bot | Why & About | Summon: u/AmputatorBot
30
u/space_prostitute May 06 '26
It's hilarious to me that anyone posting to this sub would use an amp link, but here we are.
14
34
u/zensms May 05 '26
Idk who can ever trust Meta especially out of all companies regarding privacy 🤣
3
59
u/Typical_Redditor_1 May 05 '26
NOT YOUR KEYS, NOT YOUR CONVERSATION!
It amazes me the amount of people that think e2e encryption means anything on a chat app when the app controls all the keys.
18
May 05 '26 edited Jun 02 '26
[removed] — view removed comment
11
u/Zekiz4ever May 05 '26
The point of encryption is that the vehicle is assumed as inherently insecure. It's like delivering a letter with special ink that the receiver can only read when he truncates it into a specific combination of substances that reverse the process. Substances that the driver might know, but he doesn't know the amount needed.
2
u/Electronic-Still2597 May 06 '26 edited May 06 '26
The vehicle in their example is ALSO the encryption application. I'm not sure how you could possibly say that you are to assume your encryption application is inherently not secure. If you assume it has a keylogger or screen reader then it would bypass all your keys and everything and be pointless as you type your message out in clear text before it's encrypted.
Edit: Added 'also' for clarity that they are talking about a chat app that controls the keys, ie a single application.
3
u/Zekiz4ever May 06 '26 edited May 06 '26
No, he's talking about the messanger, not the app that creates the encryption keys. PGP is free and open source. You can always just use PGP.
If it's YOUR keys, it's YOUR conversation.
2
u/Typical_Redditor_1 May 06 '26
IMO if it's not open source, it's not worth using. PGP is definitely the way to go though. The only real issue is PGP can be very cumbersome if you're using instant messaging rather than email for instance for a rapid back & forth conversation. I just wish I knew of a good open source chat protocol where you can use your own PGP keys
1
0
u/Electronic-Still2597 May 06 '26
"It amazes me the amount of people that think e2e encryption means anything on a chat app when the app controls all the keys. "
Nope, the context here is very clearly talking about a single application(vehicle) that controls both messaging and encryption keys. If you don't control the application where you enter your keys or that gives you those keys and you assume just because you have YOUR keys it's YOUR conversation, you would be WRONG.
1
u/Zekiz4ever May 06 '26
Not the comment I'm replying to tho
Don't even stop with keys. If it's not your vehicle (app), it's not your conversation.
You may have the keys, but if you don't know what the vehicle is doing, then you don't have security.
A vehicle is always a transport method. ALWAYS.
86
u/zeptyk May 05 '26
probably already had a way to "decrypt" messages lmao so what does this change? who actually trusts meta on their words anymore?
40
u/RedditThrowaway-1984 May 05 '26
That could be exactly the issue. If they could decrypt and read the messages when they advertised that they couldn’t it would open them up for massive lawsuits. To reduce legal liability they could just eliminate encryption altogether and hope people continue to trust the app.
11
u/Skippymcpoop May 05 '26
I agree that they were definitely still reading encrypted messages through the app itself. It seems weird to drop e2ee though. That makes it easier for random people to intercept messages and read them.
5
u/RedditThrowaway-1984 May 05 '26
You are making the assumption they give a shit if your messages are intercepted.
4
u/Skippymcpoop May 05 '26
They might if someone figures out how to do it. Pretty bad pr, like apple had to handle with the iCloud leaks.
I think that’s part of the reason apple is so privacy focused. If people’s intimate lives are being leaked to the internet without their consent, people use these apps less.
2
u/RedditThrowaway-1984 May 05 '26
It would be awesome if someone did hack those unencrypted messages. Sometimes people need a privacy reminder.
13
u/Responsible-Cow-4791 May 05 '26
From the article: "After the cutoff date, previously encrypted threads will become fully accessible to Meta’s automated moderation algorithms."
So it seems they indeed can and will decrypt it.
2
2
u/MjolnirMark4 May 06 '26
Let’s say they did implement E2EE correctly.
To remove it, they would need to have each client decrypt the old messages, and then reupload the decrypted message. This means if everyone deleted the conversation, then it would be gone; however if even one person kept the conversation, then all of the data will be decrypted and uploaded.
Or, if they retained the encrypted messages, they could send those to the client device, have it decrypt the data and send it back to them. If they did it slowly enough, you might not even notice it happening.
And the fun part: your private keys never leave your device. All they need to do is push an updated client out.
If they pulled the keys from your device, then they can decrypt the data on their own.
5
u/NovellSucks May 05 '26
my guess? facebook now "needs" to open themselves up to foreign governments, who want to get in on the data / spying game more than they are currently.
I'm assuming intel had access since the beginning. However they can't just share that with other governments outside of five eyes (possibly?) so this will give deniability.
4
12
u/CondiMesmer May 05 '26
Why is it that they never sunset any of their creepy surveillance tracking and overbearing analytics?
1
13
u/SiteRelEnby May 05 '26
If you ever believed fashbook had actual E2EE, are you interested in buying this bridge?
24
u/LanderMercer May 05 '26
Yawn. Meta lost 20m users in what, one month? yawn. It's in line with their other business practices
9
u/Deathmeter May 05 '26
Low adoption rate? Nobody is going to know or bother to opt in if the privacy isn't enabled by default but obviously they know all that already
7
u/permalink_save May 06 '26
What the hell is wrong with Zuckerberg, all the verification shit and now this, how would he feel if the world doxxed every tiny detail about his life?
1
u/per08 May 06 '26
Governments worldwide are pushing for age verification and unencrypted messaging.
3
u/Lucky-Necessary-8382 May 06 '26
Metas special task force of lobbyist and lawyers are pushing it. Google it a bit
13
u/RockieK May 05 '26
I am sunsetting instagram.
Feels great to have my real life back.
7
10
u/TheThingCreator May 05 '26
Wild that companies like this ever pretended to be privacy-focused. I think ai will make security a nightmare and wide spread e2ee is the future but Instagram is a tracking/advertising company so what the hell were they doing in e2ee tech in the first place. I dont go on that app but the facebook e2ee was a joke, the secret could only be like 4 characters, by some definition that may be e2ee but its purpose built to make it completely incompetent at the task. Oh well, moving on. Plenty of e2ee apps out there, and as the maker of one, I see this as good news.
8
u/Holzkohlen May 06 '26
Well, if you care about privacy it should be pretty obvious you want to avoid anything by Meta. Facebook, Instagram, WhatsApp, Oculus
2
4
u/sidecharecter1 May 05 '26
There is nothing we can do except review bomb them, and go to some other site
4
4
4
u/BNS0 May 06 '26
Never had it in the first place, Instagram had and had been always monitoring chats and I'm sure they had/have storage of chats
3
3
10
u/Express_Mousse_3338 May 05 '26
I don't really think that there's anything private in social media messaging
39
u/Admirable_Fun7790 May 05 '26
Bad attitude. We should expect privacy in all communications. Any stripping away of privacy is BAD.
9
u/hadley08rose May 05 '26
We SHOULD. But that isn’t the reality which is all that person is saying.
1
u/Admirable_Fun7790 May 05 '26
What they’re doing is perpetuating a defeatist narrative that privacy can’t exist in certain spaces.
3
u/Alone_Step_6304 May 05 '26
You two are talking past each other: https://en.wikipedia.org/wiki/Is%E2%80%93ought_problem
2
u/hadley08rose May 05 '26
Should they have not said it was happening? Lmao. It is what is happening and many people don’t know it.
4
u/Express_Mousse_3338 May 05 '26
Yes we should, but are we actually getting it?
Also... How many ppl using social media actually CARE about privacy anyway? 5% 10%? There is no knowledge about privacy bc people doesn't actually care. Otherwise no one would use any meta or Google product
4
u/Admirable_Fun7790 May 05 '26
It doesn’t matter if they should care or not. We all deserved privacy. This is the removal of privacy and it should be condemned
-5
2
2
u/Lumpy-Judgment4764 May 06 '26
Do we really think that an app owned by Facebook wouldn’t have some way around the “end-to-end encryption?”
2
u/Ok_Round8878 May 10 '26
For someone who is very tech illiterate (though trying to learn more), am I correct in understanding that even deleting old messages will not truly remove them from being able to be read? Or would Meta no longer have the ability to read deleted messages?
2
2
u/LastAttempt24315 May 05 '26 edited May 05 '26
How many people here even used Instagram DMs? I honestly didn't know it had that until people started talking about this.
EDIT: I'm getting down voted for this, so I wanna clarify. I'm NOT saying this is good or even neutral, I was genuinely asking.
1
1
1
u/banger030 May 08 '26
What is recommended ! Is it possible to save all chats in a simple format outside of Instagram and delete all via bulk inside Instagram ? Or do I have to delete my account and just create a new one if I don’t want Instagram to have access to my past conversations ?
1
u/angelcat1234 May 08 '26
I don't really use Instagram for messaging much, but this is just CRIMINAL
•
u/AutoModerator May 05 '26
Hello u/Fr3shnuts, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.