But you can’t have reproducible builds at least in the App Store.
Apple can implement to show pre-encrypt hash if they want. I cannot see anything negative impact for them if we just give some pressure.
Oh, don't get me wrong, I think it would be phenomenal if Apple were to allow reproducible builds on the App Store!
But given both the existing encryption as you mention, and Bitcode (mandatory for at least the Apple Watch for now), I think it's unfortunately pretty unlikely to happen.
> Because to beat up someone and order them to unlock their phone is faster, does not require trained staff, can be done anywhere and is fun for the cops. The implicit assumption is that the states always go for the faster solution. I'd argue that intercepting an SMS/call is easier/faster for nation-states, than arrest and torture; most carriers worldwide have interception capabilities mandated by law: using the secr…
> The implicit assumption is that the states always go for the faster solution. That’s what cops in Belarus did to me twice since 2020 when I declined to unlock my phone. That’s what they did to many of my friends and colleagues. Hacking happens but it is a more of an exception as it requires planning and effort, which is hard. Blackmail and threats are much easier.
Just because B happened to you personally doesn't mean A never happens to anyone.
When a person says "A happens", and another responds by saying "A doesn't really happen - rather B happens", their assertion is insufficient to refute the existence of A, whether based on a cost analysis thought experiment or personal experience with B. It is far more accurate for the second person to make an addition rather than a refutation by saying "B also happens more frequently than A"
Can you read russian or translate it via google translate? https://medium.com/@anton.rozenberg/friendship-betrayal-clai... while the whole store is about on how Durov tried to sleep with authors wife and tried to put pressure on him using his work position, author did expose facts which very interesting: - telegram office in sankt petersburg sharing same office that mail ru does (and mail ru basically is pro governme…
Curious how good chatGPT is at translation. Tried it on Russian?
> The implicit assumption is that the states always go for the faster solution. That’s what cops in Belarus did to me twice since 2020 when I declined to unlock my phone. That’s what they did to many of my friends and colleagues. Hacking happens but it is a more of an exception as it requires planning and effort, which is hard. Blackmail and threats are much easier.
Just because B happened to you personally doesn't mean A never happens to anyone. When a person says "A happens", and another responds by saying "A doesn't really happen - rather B happens", their assertion is insufficient to refute the existence of A, whether based on a cost analysis thought experiment or personal experience with B. It is far more accurate for the second person to make an addition rather than a refu…
That actually makes a lot of sense. Matrix should add it as a feature.
There's too many practical drawbacks. For example you have to send the OTP without getting it intercepted. How do you do that? It also has to be truly random. You can't pick a page from a book or anything, that undermines the whole model and makes cryptanalysis possible. It's useful but only in very specific cases. Mostly it's just a paradigm in cryptography. Note that for all its fame as unbreakable it does lack per…
Sitting in a cafe almost an entire week later: oh, but it does have perfect forward secrecy, as long as you discard the beginning of the pad as soon as you use it (which is actually strictly better than passing a temporary key over a potentially decryptable channel, and then discarding it after session ends). If I correctly understand what perfect forward secrecy is.