3 ms·
I think my messages sent over e2e encrypted chat with expiring session keys (like Signal) is more secure than broadcasting on radios with known weaknesses. Can
by cristoperb 2y ago
I think my messages sent over e2e encrypted chat with expiring session keys (like Signal) is more secure than broadcasting on radios with known weaknesses. Can you explain briefly why I'm wrong/"delusional"?
- rwaksmunski 2y agoSure, Signal encryption is better implemented than Motorola's. That means nothing when your device can be cracked with something like Pegasus without any interaction form you.
- DyslexicAtheist 2y agoProtection against 0-click commercial exploit chains like Pegasus, that cost thousands to maintain, can not be done with just switching to another messenger app. If that is part of your threat model IMO better to have good OpSec understanding and continuous training in compartmentalization. Ideally travel guidelines and dedicated devices. Most journalists/activists don't even have that (sadly). So the argument to just use better Technology is a dud because no amount of tech can solve them from themselves. (poorly) Paraphrasing Grugq: > Good OpSec will get you through a time of compromised encryption better than good encryption gets you through a time of poor OpSec. Software based encryption (not using HW backed) appeals if the threat-model needs to protect against the case where you think (or know) the hw might be broken e.g. in your given example AES. That claim might be true especially when you're trying to build a solid solution without control of the hardware or the underlying OS (like e2e mobile messengers trying). That would be a good reason to ditch HW based encryption. But unless you fully trust the OS or the hardware, or your own ability to compartmentalize (which IMHO you should not), why put trust in an app running on top of all this compromised garbage :D