3 ms·
I think, to a large extent, this is a question of threat models. You're absolutely right that a lot of E2EE is fundamentally a "circle of protection against la
by ryan-c 3y ago
I think, to a large extent, this is a question of threat models.
You're absolutely right that a lot of E2EE is fundamentally a "circle of protection against law", but that doesn't mean it isn't useful. The protection varies a lot depending on which law (jurisdiction) the threat has, after all.
Against a government entity, communications providers (telcos) can be considered already compromised, and represent approximately zero marginal resistance.
Even reproducible builds and audits only raise the bar, they can't solve the problem completely. I'm sure other comments are bringing up reflections on trusting trust, and the underhanded crypto contest has run a few times (I was a finalist).
I suppose my point is that security in real-world systems is never absolute, and always involves trade offs. Our goal should be to have better trade offs.
- ryan-c 3y agoWhat if certificate transparency but for app distributed via app stores?