3 ms·
Does anyone really believe their metadata is safe from any government... or non-government for that matter? I mean, TFA's whole argument is the un-encrypted he
by UncleEntity 1y ago
Does anyone really believe their metadata is safe from any government... or non-government for that matter?
I mean, TFA's whole argument is the un-encrypted header portion, designed to route the message, can be used to track who the message is sent to. Oh, and some dude provides internet service to Russian governmental agencies with their ISP located in Russia.
If you're doing dodgy stuff (like political speech) you don't want the government to know about it's probably best to conduct that business offline as they are all watching you.
- fsflover 1y agoThis looks like security nihilism: https://news.ycombinator.com/item?id=27897975 https://news.ycombinator.com/item?id=27897975
- danogentili 1y agoNot really, the auth_key_id really is simply equivalent to a TLS session ticket, used to avoid repeating the handshake every time a new connection is established: there's nothing "unencryted" about it, it's just an identifier of a previously established encrypted channel, like session tickets in TLS (and on top of that, the MTProto auth key ID is also rotated every 24 hours).