Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I felt the same as you, until I read that Google is going to manage your keys or handle the cert. authority part (however that ends up). Then I realized their end game, which is to control end to end encryption adoption to keep another vendor from controlling it.

It's the same strategy google did with the browser and mobile. They don't want to be locked out of this play, because if they don't have influence then they may potentially loose all sorts of profiling data on you. So, with Google controlling the adoption they can ensure mechanisms to provide services around your encrypted data to benefit you (while also serving google by letting them into your encrypted life).



Unless I'm reading this wrong, according to the End-to-End docs, it looks like keys are kept in a "Key Directory", and that Google will run one Key Directory, but you can use whatever Key Directory you want. I haven't seen evidence that Google will have any access to your unencrypted data.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: