3 ms·
> trusting them to just not spy on you on their servers with client-to-server encryption. Everyone would eventually spy on you on their server. Either by volun
by magic_quotes 8y ago
> trusting them to just not spy on you on their servers with client-to-server encryption.
Everyone would eventually spy on you on their server. Either by voluntary choice or being forced by some government entity. In this day and age it doesn't even make sense to discuss any hypothetical situations where they are not collecting (all of) your data.
> And if they are forced to implement a backdoor, it doesn't matter whether they do it on their servers or push an update to a supposedly secure app.
One of this things is not like the other. Remember, Signal-style e2e encryption isn't concerned with individual safety that much, it's main aim is the governmental mass surveillance. Server side data collection is, obviously, completely transparent for the end user. Client side backdoor would be quite inconvenient on that scale: the more it's used, the higher would be the chance of discovery. Thus, presumably, it would be used less frivolously.
- zzzcpan 8y agoYou are making assumptions that are rather obviously false. Every centralized app preserves an ability to eventually spy on you. End-to-end encryption doesn't take it away. If a government wants mass surveillance it either asks/coerces someone from the company to implement a backdoor or blocks the app in the country pushing people into mass surveillance friendly alternatives. So end-to-end encryption cannot possibly protect from mass surveillance. Client side backdoors obviously don't need to be pure client side either, only revert back from end-to-end encryption to client-to-server encryption preserving plausible deniability for the company. Possibly even leaving end-to-end encryption in the app, just not enabled by default. Such change can even be advertised as an improvement, like cross device chat history feature or something.
- magic_quotes 8y ago> Every centralized app preserves an ability to eventually spy on you. End-to-end encryption doesn't take it away. Never said anything like that. > If a government wants mass surveillance it either asks/coerces someone from the company to implement a backdoor or blocks the app in the country pushing people into mass surveillance friendly alternatives. Yes. > So end-to-end encryption cannot possibly protect from mass surveillance. Are you arguing for mass surveillance friendly software? Decentralized software? What are you arguing? I'm completely lost there.
- zzzcpan 8y agoI'm arguing that end-to-end encryption in a centralized app doesn't actually do better with regards to any threat from its threat model as compared to client-to-server encryption. It's sort of a fallacy, centralization cancels out any benefits that end-to-end encryption is supposed to bring over client-to-server encryption. So "but they have" or "don't have end-to-end encryption" cannot be an argument.