5 ms·
I've read the whole thread and I'm surprised that nobody mentionned how easy it would be for Facebook to store the secret keys. Page 10 of the white paper ment
by r2dnb 10y ago
I've read the whole thread and I'm surprised that nobody mentionned how easy it would be for Facebook to store the secret keys.
Page 10 of the white paper mentions that there is a remote key stored on Facebook servers which can be used to decrypt the local key. If Facebook still is to be trusted, I don't see what's the deal here.
I think that as soon as you put the words "end-to-end" encryption on a marketing material, you have to be ready to open-source your client. This is the cost that companies aiming to be credible can't escape.
End-to-end encryption without open-source has no value. It is a waste of energy for the company doing that too - or perhaps a marketing cost.
- Sylos 10y agoYou are correct, but displaying a little message in millions of user-devices which says that it is end-to-end-encrypted, that makes them correcter.
- HappyTypist 10y agoYou've read it wrong. The local key is encrypted with the remote key. It means if someone steals your phone, they still have to pass facebook's authentication (e.g. 2fa) before being able to read your messages.
- jomamaxx 10y ago"End-to-end encryption without open-source has no value. " Not quite. It means nobody is going to be able to read your data other than: A) A nefarious Facebook staffer who has hacked their internal systems B) A government entity with a court order It's a step up from no encryption
- cyphar 10y ago> It means nobody is going to be able to read your data other than: (Assuming it is properly implemented and doesn't have backdoors, which can only be practically verified if the client is free software).