use GPG and PGP

You are viewing a single thread.
View all comments
18 points

It shouldn’t be allowed to call it E2E otherwise. If a third party is involved in the communication, it’s just a middleman attack that pinky promise to not read your messages.

permalink
report
reply
7 points

That depends for me. Is it open source? If so, check the source code, you can see for yourself whether that third party is doing anything shady? Anything closed source like WhatsApp, however, and I 100% agree with you.

permalink
report
parent
reply
7 points

Open source is not sufficient, you also need to be sure that the version you install is the version you inspected. In Appstore or Playstore for mobile this is not straightforward. Hell, even linux packages sometimes contain tons of maintainer patches that are not upstreamed

permalink
report
parent
reply
2 points

True, that’s part of the reason I switched to Gentoo

permalink
report
parent
reply
6 points

The first time I saw the message “Your messages are now encrypted” on WhatsApp my reaction was “Yes, but it’s worthless if you keep a copy of the key”.

If the end user isn’t able to create the key by themselves, it’s most likely useless.

Imagine you rent a flat and the owner is Facebook, who keeps a copy of the key and let everyone in who pays some money.

permalink
report
parent
reply

Memes

!memes@lemmy.ml

Create post

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

Community stats

  • 8.5K

    Monthly active users

  • 13K

    Posts

  • 288K

    Comments