Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Saying it is not encrypted is directly misleading.

Sorry, that's my bad. I edited the message to clarify that I meant end-to-end encryption, since Telegram's implementation (mtproto) of e2ee is the topic of this submission.

> also true for mail, banking and about everything else except the most secure instant messaging networks

That is indeed the state of things. People like the convenience though: imagine you could only retrieve your data from Protonmail by knowing the encryption password. People would irrecoverably lose all their emails on a regular basis. Banking makes less sense though, since the bank needs to know how much money you have to be able to give some of that money (per your instruction) to e.g. merchants. Websites can be end to end encrypted, if the endpoint is owned by the person you're trying to reach. Cloudflare's "TLS MITM as a service" (and similar offerings) undermine that, but if you go to https://lucb1e.com then your traffic is end-to-end encrypted to me. If you want, we can also verify fingerprints out of band, just like you should with encrypted chats to make sure you're not trusting the server (or in this case the signing authorities)!



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: