3 ms·
> the idea of E2E is precisely to remove trust from the equation It doesn't do that. You don't have a way to verify what software runs when you send a whatsapp
by psv1 7y ago
> the idea of E2E is precisely to remove trust from the equation
It doesn't do that. You don't have a way to verify what software runs when you send a whatsapp message.
- zzzcpan 7y agoOh, it's worse. End-to-end encryption assurances are essentially in conflict with centralized control over software development and distribution. Literally the same organization end-to-end encryption is supposed to protect from is the one responsible for implementing and deploying that protection and doing that well and correctly.
- fdeage 7y agoThat's interesting. Could you develop on this conflict? For some reason it reminds me of the famous Moxie article: https://signal.org/blog/the-ecosystem-is-moving https://signal.org/blog/the-ecosystem-is-moving Is it the same idea?
- zzzcpan 7y agoIt's the opposite of Moxie's propaganda. Here's an example of this conflict at play: https://news.ycombinator.com/item?id=22106536 https://news.ycombinator.com/item?id=22106536
- fdeage 7y agoAgreed, but I meant "properly implemented E2EE".
- psv1 7y agoI really think that you aren't even trying to understand what other people are writing in this thread and you're just going back to the same ideas that were in your head before you asked your question.