3 ms·
E2E encryption fails on a large number of subjects when it comes to a chat application such as Slack. One of the simplest issues I can see is the search functi
by codefined 9y ago
E2E encryption fails on a large number of subjects when it comes to a chat application such as Slack.
One of the simplest issues I can see is the search functionality, something I use daily in Slack and would sorely miss not having. Elasticsearch requires access to the contents of a message to index it (basic requirement).
Another thing that would become difficult would be adding people to a group, although my technical knowledge in this area is perhaps not massive, my thoughts are that if a user can join a group with another key, surely a Slack attacker would also be able to add their own key?
I'm sure there are many other things that ensure Slack cannot be E2E encrypted since it stops a significant amount of the logic they can do (they would become a dumb proxy), similar to why Google hasn't gone E2E.
- JumpCrisscross 9y ago> E2E encryption fails on a large number of subjects when it comes to a chat application such as Slack As I said, not every communication mode must be secure. Slack trades off security for other features, and that is okay. It's odd for Slack to be beating their chest, however, about staying secure when security is not a feature they optimize for.