3 ms·
And your REALLY think E2E is going to "protect" you? If the "services" want to watch, don't worry they will, "they don't need your password". But I guess they
by sylware 3mo ago
And your REALLY think E2E is going to "protect" you?
If the "services" want to watch, don't worry they will, "they don't need your password". But I guess they "do" that only for the very baddies, aka child exploitation, human trafficking, terrorists, killers, drug dealers, etc.
We all know here that "information system security" does not exist, this is a fantasy: there is only some "best effort" with a wide spectrum of compromises. If somebody talks to you about "deliverable security", that guy wants to sell you something.
E2E will protect you only against John Doh, "hacker only on Sundays". And we better keep that in mind.
- exfalso 3mo agoWhat are you talking about. You think service providers can backdoor aes-gcm? There will always be technology that they cannot get around. The only way to backdoor is to explicitly change the encryption.
- sylware 3mo agoAre you misunderstanding on purpose? This is not specific to 'backdooring aes-gcm implementations' at all. Read again what I wrote, namely this is the general status quo on 'information system security': they don't need your password or aes-gcm key to watch if they really want to. You would be a fool to presume anything else.
- int_19h 3mo agoService providers like say Apple and Google can push an update to your phone which will intercept all that data after it has been decrypted.
- exfalso 3mo agoI understand. So don't use them. There are plenty of OS alternatives