4 ms·
Everyone talking about not having E2EE in messenger, am I missing something? How would one implement E2EE on a web application? How would the key sharing work o
by harshitaneja 4y ago
Everyone talking about not having E2EE in messenger, am I missing something? How would one implement E2EE on a web application? How would the key sharing work on such a transient platform?
- deleted 4y ago[deleted]
- aftbit 4y agoWell, there _is_ E2EE in messenger, it is just off by default. I am not sure how they manage key sharing, but likely in some way that would allow them to add another device to your session relatively transparently, which means that they could always bypass it in that way. Of course, they could also bypass it by shipping a targeted software update to force your app to resubmit all the messages unencrypted.
- ahahahahah 4y agoAnd of course, all those ways to bypass e2ee are properties of e2ee itself (or of common features required for usable e2ee like being able to add devices), not properties of facebook or facebook's implementation. e2ee generally should not be considered to be protecting you from a malicious messaging service.