5 ms·
Not a web person, but isn't https end-to-end encryption
by NextHendrix 5y ago
Not a web person, but isn't https end-to-end encryption
- k__ 5y agoTheoretically, yes. But the owner of the domain can decide at which point they terminate. Could be that your connection is just encrypted until a proxy that's inbetween.
- emteycz 5y agoYes, it can be. SSH too.
- moreira 5y agoYes, but only in the sense that it's encryption between you and the server you're talking to. That's not what people are referring to when they talk about end-to-end encryption, though. What people are talking about there is that when I send you a message, it leaves my device encrypted, and can only be decrypted by you, on your device. Whatever servers it goes through, in order to get to you, cannot decrypt it at all. Law enforcement, third-party companies, doesn't matter, they can't see it, only you and I can.
- monocasa 5y agoOnly in the sense that Zoom got lambasted for calling their original setup E2EE. "Well technically our servers that log everything are a end of the communication". At least in the states they faced legal penalties for such a claim (albeit a slap on the wrist).
- RHSeeger 5y agoIf the other "end" you are talking to is their server, then it's end-to-end encryption. If the other end is another person's computer, and their server is only one jump on the way there, then it's not end-to-end. Clearly, with Slack, "their server" was not the other "end" in anyone's mind; so they were being disingenuous. But for many cases (banking), their server _is_ the other end.
- monocasa 5y agoExcept that wouldn't even be affected by this legislation because the whole shitck is forcing servers to log everything. I guarantee your bank is already logging everything.
- bonoboTP 5y agoYes, but the other end is a centralized website under govt supervision. They are against normal end users directly talking to each other in an encrypted way.
- xg15 5y agoIt's encryption, but not end-to-end. My understanding is, to be E2E encrypted, the keys must only be known by you and the actual other user you're communicating with. With https, this is not the case: you're only communicating with the server, which then relays the messages. However, the server can see everything. You can use the term in different contexts, depending on what you consider the "ends": If you think of your machine as one end and the server as the other, it is technically E2E encrypted. But in the more meaningful sense where your device is one end and your communication partner's device is the other end, it is not.