3 ms·
We do, but that would require the company to lie about what they are doing with the app. At Twitter's scale it's very possible that someone would notice and lea
by ajconway 4y ago
We do, but that would require the company to lie about what they are doing with the app. At Twitter's scale it's very possible that someone would notice and leak that.
The goal as I imagine it is to go from "Hundreds of Twitter employees can definitely access my messages today and anything I've sent and received up until now" to "Twitter will likely need to perform a MITM attack to read my messages starting from the moment when the attack was performed. Maybe they have a secret backdoor, but it's probably too valuable to use on my cat photos".
- brian-armstrong 4y agoIf it's just about internal access, how is it any different from implementing access controls? Put another way, at Twitter's scale, any employee access to production data is intentional.
- ajconway 4y agoCorrect, but with everything in plaintext one just needs to read a file stored somewhere in a database. With encryption, one needs to perform an active attack.
- dontcare007 4y agoYou mean like leaking the collusion between certain parties to down-rate certain other parties using a secret algorithm? It would only take a couple of people I'm key positions to accomplish it.