Hacker News new | past | comments | ask | show | jobs | submit login

No company is obligated to do anything. Such lack of obligation is not sufficient reason to praise companies that do the bare minimum to keep user data safe. Sure they aren't obligated but how on earth does that matter?



E2EE certainly is not the "bare minimum", TLS is. Maybe encryption at rest, but even that's debatable.


If E2EE is “the bare minimum”, how are there so many successful and thriving companies who don’t do it? And why are you even on HN, which doesn’t do it?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: