Live data from Hacker News

Global Encryption Day: Demand End-to-End Encryption in DMs

blog.torproject.org

11–20 of 78 posts

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#11

How do you know if the Signal client running on your phone right now doesn't include a backdoor? Sure it's open source. But how do you know how it was compiled? What if someone changed the open source before shipping it to the app store?

This is called "Reproducible Builds".

https://signal.org/blog/reproducible-android/

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#12

How do you know if the Signal client running on your phone right now doesn't include a backdoor? Sure it's open source. But how do you know how it was compiled? What if someone changed the open source before shipping it to the app store?

Have a classic: https://www.usenix.org/system/files/1401_08-12_mickens.pdf

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#13
post #2

Kind of meaningless if you can't trust the software running on your device though, since it could be scanning locally or relaying to remote services.

This is an instance of the trope "if you can't solve everything, you shouldn't solve anything".

It is fallacious because you'll never get there if you're not allowed to make incremental advances.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#14
Remember when Zoom claimed that meetings were E2EE yet you could join the meeting by phone and no one batted an eye for at least one or two years? Noticed how no regular person cares when the "security code" of a chat partner changes in WhatsApp or Signal? Not to mention no regular person uses self-compiled apps for that, even if it were possible. E2EE is close to becoming a cargo cult, because done properly key management and identity verification are a usability nightmare. It will always remain a toy for a niche audience. Most people just don't care, and the non-technical people that do care are happy with a green lock appearing somewhere. I do hope to be proven wrong, though.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#16
post #3
post #2

Kind of meaningless if you can't trust the software running on your device though, since it could be scanning locally or relaying to remote services.

So run free software?

Every free software will have dozens or even hundreds of transitive dependencies.

It literally isn't possible for an ordinary person to audit all code.

At some point you have to blindly trust.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#17
post #14

Remember when Zoom claimed that meetings were E2EE yet you could join the meeting by phone and no one batted an eye for at least one or two years? Noticed how no regular person cares when the "security code" of a chat partner changes in WhatsApp or Signal? Not to mention no regular person uses self-compiled apps for that, even if it were possible. E2EE is close to becoming a cargo cult, because done properly key mana…

So what you're saying is, we can just put a green lock in the UI and call it a day.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#18
post #11

How do you know if the Signal client running on your phone right now doesn't include a backdoor? Sure it's open source. But how do you know how it was compiled? What if someone changed the open source before shipping it to the app store?

This is called "Reproducible Builds". https://signal.org/blog/reproducible-android/

Reproducible builds are for developers. As a user I didn't build the app on my phone.

I have a phone with Signal on it. Tell me what I should do to verify it's running the open source Signal code.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#19
post #14

Remember when Zoom claimed that meetings were E2EE yet you could join the meeting by phone and no one batted an eye for at least one or two years? Noticed how no regular person cares when the "security code" of a chat partner changes in WhatsApp or Signal? Not to mention no regular person uses self-compiled apps for that, even if it were possible. E2EE is close to becoming a cargo cult, because done properly key mana…

So what you're saying is, we can just put a green lock in the UI and call it a day.

We can put some thought into how to set up the third parties to be trusted with our keys. Curretly it's very haphazard. And it's not avoidable. Even Phil Zimmerman, inventor of PGP, won't accept PGP encrypted mail because he claims to have lost his private key.

The outrage "own your private keys or bust!" is much easier tho.

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#20
post #3

Earlier quoted context omitted.

So run free software?

Like signal that still refuses to put their client on fdroid?

Like Element which does publish its client on F-Droid: https://f-droid.org/en/packages/im.vector.app/

(Yes, F-Droid availability is a very good cutoff, I agree.)

Post reply on HN