5 ms·
> The logs of location sharing uploads and queries contain two pieces of information that together would allow for certain types of analytics Yes, metadata can
by apayan 6y ago
> The logs of location sharing uploads and queries contain two pieces of information that together would allow for certain types of analytics
Yes, metadata can always be analyzed and exploited. I just hope that by open sourcing the server and the client, that I can earn some trust from people to know that I'm not doing anything like that. This is not a problem unique to this server, it's a problem of all servers in the world. And if a user is particularly concerned about exposing their IP to the server, they can always access it via a VPN or proxy server.
Zood Location can't overcome every single threat out there, but it can significantly reduce the number of threats you have to deal with.
- bostik 6y agoTrue enough, you can't eliminate metadata (or as it should be really called: "traffic analysis"). And don't get me wrong, I think you're improving things. It's just that with something that advertises E2E encryption, the expectations are high. Unavoidably so. Doesn't help that various snake-oil salesmen have tried to hijack the term too, because of its implied strength. So being upfront about the threat model and in particular what your service can not protect against is important. It just happens that in this particular case, the not-in-threat-model-scope is also a thing of interesting value. Perhaps even more so if your service gets adopted by civil rights or other organising movements.