3 ms·
E2EE is a valid term. Just because both ends are controlled by the same person doesn’t make it not “client ↔ client”. Just because Google wrote the software and
by amarshall 3y ago
E2EE is a valid term. Just because both ends are controlled by the same person doesn’t make it not “client ↔ client”. Just because Google wrote the software and stores the backups does not mean that those backups should be readable to someone (e.g. Google servers) with access only to the backup. E2EE means that no one other then the end-users can see the data—in this case, that is just the one user. Neither transit encryption nor encryption at rest provide that.
Encryption at rest is not really part of the discussion. There’s no way to verify client side that it is happening, and it does not prevent Google servers from seeing the plaintext backup.
> In general the linked post doesn't do a good job describing what they found and how they found it
Seemed pretty clear: they did MITM to bypass any transit encryption and saw the plaintext secrets being sent, and thus Google servers can see all the secrets.