3 ms·
> Are you counting HTTPS as “E2E encrypted”? No. > Because if not, consider that we do private communication over mere HTTPS all day long. Me loading the HN w
by krn 4y ago
> Are you counting HTTPS as “E2E encrypted”?
No.
> Because if not, consider that we do private communication over mere HTTPS all day long. Me loading the HN web page and having my own personal rendering of it with my user cookie header and all my upvote/downvote/karma/profile state is private communication, for example.
Because there is a good reason for it: it wouldn't work well with E2E encryption.
- hamburglar 4y agoWell, ok, I guess we can use that as a justification for anything then. For example, the “good reason not to” use E2E for ntfy could be “market analysis says the small and somewhat theoretical benefit isn’t worth the complexity.”
- krn 4y agoPrivate messaging is one of the primary use cases for E2E encryption in the entire tech industry.
- hamburglar 4y agoYes, but you said all private communication should be E2E. Apparently you're defining communication in some way that excludes an awful lot of what I'd consider communication (e.g. HTTPS traffic).
- krn 4y agoMy key point was "unless there is a good reason not to". And in many cases there is a good reason not to use E2E encryption, like the example you have given. But in the case of Ntfy, E2E encryption would be a perfect fit, and eliminate any need for self-hosting.
- horsawlarway 4y agoI'll be blunt - as someone who worked in the space extensively... if you really need e2e encryption, you want to be self hosting anyways. By the time you're trusting a hosting provider to properly do e2e for you... you've basically already lost the game. At any point they can update what's running and remove any/all protections you think you have. So again - what is your threat model here? Because it sounds like you want "super convenient" and also "super secure" and those aren't two options you just check off - they're really more like diametrically opposed sides of the same slider.