4 ms·
> "They haven't done it yet because it's hard. Really hard." How "hard" is it though? The following seems straightforward to me: - Generate a pgp key pair -
by ComradePhil 4y ago
> "They haven't done it yet because it's hard. Really hard."
How "hard" is it though?
The following seems straightforward to me:
- Generate a pgp key pair
- protect private key with a E2E password ("if you forget your E2E password, all your DMs will be lost")
- store public key and encrypted private key in the Twitter account
- download private key to each device/browser session the user logs in to, have them enter the E2E password to decrypt it
- make public key of any user available to anyone they send message to
Why would this not work?
- Ekaros 4y agoNot something I would call exactly good user experience for your average twitter user... And then come the governments which will have slight issues on this. And fake apps, third-party apps, malicious browsers and malware in general... It is simple, but actually to make it usable for other than nerds and have them not yell at twitter when they handily forget their password and can't recover. Not really worth the customer support and PR load following.
- karmakaze 4y agoRight, specifically which part is different "in a modern, patched web browser" that makes it so hard compared to a desktop or mobile app? Or even the point about being so much harder to add after having non-e2e messages beforehand, I don't buy--they can co-exist with a new default.
- bradknowles 4y agoYou don't want to re-use that private key on every device. You need separate keys for each device. You want to be able to burn the private key of a given device without burning all keys for all devices.