6 ms·
Before you can answer this, you need to ask a more basic question: "What am I trying to secure against?". Are they secure against an opportunistic thief? Sure.
by connordoner 4y ago
Before you can answer this, you need to ask a more basic question: "What am I trying to secure against?".
Are they secure against an opportunistic thief? Sure.
Are they secure against a state actor with an unlimited budget? One word: LOL.
- tianqi 4y agoI think that the end-to-end encryption way (if the key is not uploaded) is secure even against such a government. Isn't it?
- thesuperbigfrog 4y ago>> I think that the end-to-end encryption way (if the key is not uploaded) is secure even against such a government. Isn't it? No.
- tianqi 4y agoWould you please expand on that? Like what?
- smoldesu 4y agoWell, if you're using a Mac/iPhone then you trust Apple with most of your encryption keys. Apple is a company that gives the Chinese government access to their citizen's encrypted data. Do they do the same thing in your country? Who knows!
- tianqi 4y agoI am in China and aware of the Apple risk. But I don't think Apple is indiscriminately recording the keys people enter for each app and providing them to the gov, so I don't think that threatens end-to-end encrypted data. Am I right? With all ears.
- t-3 4y agoDiscriminatory access is more than enough for your security to be compromised by state actors. If your endpoint device can be accessed by government decree, end-to-end encryption is useless. Encrypted drives and files can be another layer of security, but can easily be made ineffective if your endpoint can be compromised by the OS vendor in conjunction with the government. Even if you succeed in technologically hardening yourself and performing all data access with exceptional opsec discipline, actually going to such lengths could draw unwanted attention from automated analysis tools. That's why criminals almost always favor pseudo-steganographical methods such as slang dialects and gang symbols - simple codes which are obvious to the initiated and easily misinterpretated by others. Cloud data is vulnerable to attack by insiders and hackers. Local storage is vulnerable to theft and physical damage. Networked devices running proprietary applications are hard to secure and impossible to fully trust. You will have to come to a compromise with the risks and benefits of each to make an appropriate choice for keeping your data.
- tianqi 4y ago>> "actually going to such lengths could draw unwanted attention from automated analysis tools. That's why criminals almost always favor pseudo-steganographical methods such as slang dialects and gang symbols" Thank you. This is inspired.
- lelandfe 4y agohttps://en.wikipedia.org/wiki/Evil_maid_attack https://en.wikipedia.org/wiki/Evil_maid_attack Nothing is secure against a state.
- tianqi 4y agoThank you. I see.