28 ms·
Centralized services are not going to provide 100% reliable end-to-end encryption, they're vulnerable 'single-point-of-failure' that can be pressured/hacked/etc
by FrozenVoid 6y ago
Centralized services are not going to provide 100% reliable end-to-end encryption,
they're vulnerable 'single-point-of-failure' that can be pressured/hacked/etc to disclose their users data.
- bayindirh 6y agoProton is "Zero Knowledge" so, they can't divulge anything but, with a weak enough password, high enough computational power or with a big enough wrench[0], you can get anything. [0]: https://xkcd.com/538/ https://xkcd.com/538/
- faeyanpiraat 6y agoAll that zero knowledge stuff goes out the window once someone deploys malicious code to prod.
- skinkestek 6y agoKind of. But it is a really good point and I'll try to explain: As long as both parties use a known safe version of e.g. Signal everything is kind-of good. Messages may pass through NSAs and GRUs headquarters and they are none the wiser even if they have access to Signals servers. However, if any of them somehow manage to strongarm a release of Signal through the release channels and you or whoever you talk to updates or auto-updates Signal and that new release somehow uploads data from the Signal client, then for most of us we would be none the wiser.