cross-posted from: https://lemmy.ml/post/1874605

A 17-year-old from Nebraska and her mother are facing criminal charges including performing an illegal abortion and concealing a dead body after police obtained the pair’s private chat history from Facebook, court documents published by Motherboard show.

  • Flying Squid
    link
    English
    8210 months ago

    For all of those saying Facebook was just complying with the law- there is absolutely no reason for Facebook to have access to its users’ private information. The company I work for can’t do anything with a customer’s account unless they give us the password. We can’t see anything they have saved there. All of the private stuff they have is private and even if a court ordered us to show it to them, we literally couldn’t comply.

    We’re a small company and we can do it. A company the size of Meta can certainly do it.

    • @RagingRobot
      link
      English
      910 months ago

      Can’t you just look at the data in. The database though? No need to login as the user. Surely not every field is hashed

      • @fishpen0
        link
        English
        20
        edit-2
        10 months ago

        Hashing is not reversible so obviously it is not hashed. You hash data you want to compare later to see if it is still the same. For example you may hash user passwords you store in your database. So you don’t know the actual password, but can confirm later that the same password is still being used. You know or can infer someone is storing your passwords in plaintext when they have a maximum length as that indicates they are not correctly hashing.

        It is however possible and even easy in many databases to do row or document level encryption. Many privacy first applications do client side keys and encryption so the database does in fact have no plain text in it.

      • Flying Squid
        link
        English
        610 months ago

        That’s a good point and I don’t know the answer to that (my guess is encryption is involved), but as other people have pointed out, Facebook has an alternate encrypted messaging service, WhatsApp, so Facebook is clearly capable of not being able to access its users’ messages.

        • @essteeyou
          link
          English
          6
          edit-2
          10 months ago

          Yeah, based on Signal’s protocol. Signal is the only messaging app I use.

    • @afraid_of_zombies
      link
      English
      -310 months ago

      You are the product. Are you paying money for the service? No? Zero expectation of privacy.

      • @[email protected]
        link
        fedilink
        English
        410 months ago

        We enable them to make profit via ads and data harvesting. Private texts/DMs do not need to be involved in that.

        • @afraid_of_zombies
          link
          English
          110 months ago

          Don’t use them. I haven’t had an account for over a decade.

        • @kava
          link
          English
          010 months ago

          To be fair, I’d imagine there’s a wealth of data to plug into their AI models from private chats.

          I’d imagine it’s hard for them to resist the temptation

    • @Skyrmir
      link
      English
      -410 months ago

      You can do it because you’re a small company. Get enough attention, and the FBI will force you to decrypt on demand. They’ve done it before and the supreme court backed them up. Do it over seas and expect your US traffic to get blocked, if they don’t raid your offices.

      • @EricHill78
        link
        English
        1910 months ago

        That is untrue. The FBI tried to get Apple to decrypt a shooter’s iPhone in Florida a few years back and they wouldn’t budge.

        • KairuByte
          link
          English
          310 months ago

          This isn’t quite right…

          Apple didn’t have the means to decrypt the information, but it was within their ability to do (by writing code to do so.)

          But asking a company for the unencrypted data, and forcing a company to produce a new application, are completely different things.

          • @False
            link
            English
            210 months ago

            Apple didn’t have the means to decrypt the information, but it was within their ability to do (by writing code to do so.)

            Happen to have a source for that? That’s nigh impossible for most encryption

      • @ikidd
        link
        English
        1010 months ago

        E2EE is what prevents this, which is why the TLAs hate it and legislators are trying to prohibit it.

      • @ABCDE
        link
        English
        810 months ago

        WhatsApp, Signal and Telegram don’t have that issue.

        • @[email protected]
          link
          fedilink
          English
          28
          edit-2
          10 months ago

          Signal yes, WhatsApp yes but not the meta data, telegram only if explicitly set to encrypted otherwise no.

        • @Skyrmir
          link
          English
          110 months ago

          Because they have a back door due to cloud storage.