Breaking message franking
Message franking is a mechanism to facilitate abuse reporting when using end-to-end encryption. This article describes how it works and how it can fail. Facebook Messenger provides end-to-end encryption. This means that Facebook is not aware of the contents of messages. This introduces a problem when a user reports an abusive message to Facebook: Alice says Bob is sending dick pics to her, but Facebook can’t know whether this is true since it can’t view the message contents. Message franking solves this by providing verifiable abuse reporting. When Bob sends a message to Alice, they first create a binding tag, which is a HMAC using a random key. The HMAC is readable by Facebook, but the HMAC key and the message are encrypted with Alice’s key. Facebook stores this HMAC before sending it and the encrypted message along to Alice. When Alice reports the message, she provides the message and the key used for the HMAC to Facebook. Facebook can verify that it indeed seen this HMAC and that th
Message franking is a mechanism to facilitate abuse reporting when using end-to-end encryption. This article describes how it works and how it can fail. The problem Facebook Messenger provides end-to-end encryption. This means that Facebook is not aware of the contents of messages. This introduces a problem when a user reports an abusive message to Facebook: Alice says Bob is sending dick pics to her, but Facebook can’t know whether this is true since it can’t view the message contents. Message franking Message franking solves this by providing verifiable abuse reporting. When Bob sends a mess
Explore this link on the map →related reading
- Illustrating Reinforcement Learning from Human Feedback (RLHF)huggingface.co
- Security incident disclosure — July 2026huggingface.co
- The Indytheindy.org
- iMessage with PQ3: The new state of the art in quantum-secure messaging at scale - Apple Security Researchsecurity.apple.com
- sndfjknio0.github.io
- Mamba 2FA: A new contender in the AiTM phishing ecosystem - Sekoia.io Blogblog.sekoia.io
- Why my macOS Messages badge lied to me (and the one-line fix) - Vox Silvablog.alexbeals.com
- iMessage, explained - JJTechjjtech.dev
- discrete blogarithm ·blog.azuki.vip
- bias-bounty-data/bias.csv.zip at main · humane-intelligence/bias-bounty-data · GitHubgithub.com
- Length extension attack - Wikipediaen.wikipedia.org
- Traceability in End-to-End Encrypted Environments - Internet Societyinternetsociety.org