4 ms·
It sounds like SOLID the protocol requires the pod server to have access to your data, because it requires the server to both enforce access control and deliver
by ianopolous 6y ago
It sounds like SOLID the protocol requires the pod server to have access to your data, because it requires the server to both enforce access control and deliver plain text? That is not what I want as a consumer. I want something where I don't have to trust the server at all, i.e. everything is E2E encrypted - and if that's not true, that's not a protocol I want interacting with my personal data.
The comparison with email is apt, because no one in their right mind would design email as it is today without E2E encryption baked into the protocol.
- Vinnl 6y agoKeep in mind that you can run your own server though.
- ianopolous 6y agoYep, and that can still get hacked, or a number of other failure modes.
- dijksterhuis 6y agoSo did Iran's air gapped nuclear enrichment plant. Nothing is ever 100% secure. Ever.
- ianopolous 6y agoIf Signal's servers are hacked the attacker can see exactly zero of my messages (even an active attacker that controls the server). E2E encryption protects against hacked servers.
- dijksterhuis 6y agoThere are much cheaper ways to get around end to end encryption. https://xkcd.com/538/ https://xkcd.com/538/
- dijksterhuis 6y ago> It sounds like SOLID the protocol requires the pod server to have access to your data, because it requires the server to both enforce access control and deliver plain text? Yes. Exactly. > That is not what I want as a consumer. Okay. Don't use it then. > I want [magic beans]. Good for you. I want Heather Graham as my wife. More seriously, what you want doesn't exist yet. Not in a useful way at least. Maybe go build it yourself if it's something you really want. Or maybe accept the fact that security is not an absolute, it inherently comes with tradeoffs. Like life, really. > The comparison with email is apt, because no one in their right mind would design email as it is today without E2E encryption baked into the protocol. Have you ever worked at a company where they were legally required to do audits or handle large financial transactions? Cos baked in E2E encryption would make detecting malicious employees (defrauding clients etc) really difficult to do, and prosecuting them nigh on impossible. Like I said, security comes with tradeoffs. Golden rule of security: it can't be 100% secure and usable. The one time pad is a classic case of this golden rule.
- ianopolous 6y agoNo need to be rude. I'm just trying to understand the limitations of the protocol. A group of us are actually building this ourselves. See https://book.peergos.org https://book.peergos.org or https://github.com/peergos/peergos https://github.com/peergos/peergos The key phrase relevant to this discussion is "trust-free servers".
- dijksterhuis 6y ago> No need to be rude. I wasn't. But I was sarcastic and facetious. There's a difference. > I'm just trying to understand the limitations of the protocol. It did not read like that in the slightest. It read like someone who wants to hit everything that looks like a nail with the end to end encryption hammer. > A group of us are actually building this ourselves. See https://book.peergos.org https://book.peergos.org or https://github.com/peergos/peergos https://github.com/peergos/peergos Great! All the best with that. > The key phrase relevant to this discussion is "trust-free servers". Not with the solid standard it isn't. That's a completely different use case/problem that you're talking about. Solid is attempting to solve the "all of my data is stored, pretty poorly, by thousands of different companies in hundreds of different ways, and I don't have any control over it" problem. It's about data ownership, not server trust.