Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

All E2EE does is keep the general herd of users safe from malicious insiders and script kiddies. It's valuable but doesn't make these apps worthy of the catch-all "secure" descriptor.

For anyone worth targeting, there are so many options available to actors with moderate resources. They will pwn your OS with an RCE exploit; or interfere the next time you update that "E2EE" app via Google or Apple's servers; or your laptop will take a few seconds longer to reappear at airport security; etc.

Marketing messengers as "secure" because they use some derivative of the Double Ratchet is like your bank saying your funds are secure because their website uses TLS.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: