3 ms·
> Apple also enabled true e2ee in the cloud where only you retain the keys. Is there a procedure to realistically verify that your communications are e2e and n
by irobeth 4y ago
> Apple also enabled true e2ee in the cloud where only you retain the keys.
Is there a procedure to realistically verify that your communications are e2e and not e2mitm2e ?
- walterbell 4y agoCanary content for your threat-modeled attacker, then monitor for the data being acted upon, e.g. traffic to non-public URL.
- chaxor 4y agoAll of it is a bit silly to trust companies with things like this when there are standard techniques which have stood the test of time and are *far* simpler - tar.zst.gpg or squash.gpg, luks-encrypted qemu images, etc. Things done locally are just inherently better, because it's far simpler tech, and you actually know what's happening rather than just blindly trusting some sketchy company.