Web-based cryptography is always snake oil
devever.net
Web-based cryptography is always snake oil
1–10 of 137 posts
Re: Web-based cryptography is always snake oil
#2I think what makes the Web special is precisely that there are different browsers beyond Chromium. If the Web was Chrome I would tend to agree but even though popular I do not think it is fair to conflate it to be the Web.
Re: Web-based cryptography is always snake oil
#3Re: Web-based cryptography is always snake oil
#4Re: Web-based cryptography is always snake oil
#5Some might call this a “cryptographic innovation.” I call it “the technical outsourcing of legal disclaimers.” Unfortunately, I don’t seem to have a Harvard Law School legal team on my side.
Re: Web-based cryptography is always snake oil
#6I'm confused, is the argument that it doesn't work because Google is fueled by surveillance capitalism? If so what about Apple which is only partly so? What about Firefox and in particular its de-branded ones without Google search as default? I think what makes the Web special is precisely that there are different browsers beyond Chromium. If the Web was Chrome I would tend to agree but even though popular I do not t…
My take is that you should trust provider (developer, hoster) of said encryption app to send you actual implementation, not something that looks like the real deal, but does not encrypt anything. From a regular user's point of view: you can not inspect what you run (due to technical reasons, that on the web anything can be downloaded and executed at any moment, swapping implementation on the fly. And due to skills needed to actually read and understand executed scripts), so you can only believe and trust. At which point usual TLS is surely enough.
Re: Web-based cryptography is always snake oil
#7The entire argument is based on the definition of an “Incoherent cryptosystem”, which is too restrictive to be useful for cases that you want eg. Tor is also developed and distributed by Tor people and it is supposed to protect you against everyone, including the Tor people.
still this wouldn't guarantee that all the other nodes are not compromised
Re: Web-based cryptography is always snake oil
#8Before reading this article, I used to believe that IT companies deeply respected users’ human rights, spending millions of dollars to build end‑to‑end encryption. But thanks to this very article, I learned that they were actually saving tens of millions in administrative litigation costs – costs they would otherwise have had to pay every month to respond to wiretap warrants. Some might call this a “cryptographic inn…
Re: Web-based cryptography is always snake oil
#9Before reading this article, I used to believe that IT companies deeply respected users’ human rights, spending millions of dollars to build end‑to‑end encryption. But thanks to this very article, I learned that they were actually saving tens of millions in administrative litigation costs – costs they would otherwise have had to pay every month to respond to wiretap warrants. Some might call this a “cryptographic inn…
having E2E encryption is a marketing feature, you need it if you want to be competitive in the market, so this is another incentive to add it
Re: Web-based cryptography is always snake oil
#10Earlier quoted context omitted.
having E2E encryption is a marketing feature, you need it if you want to be competitive in the market, so this is another incentive to add it
I never believed that the messages were truly E2E encrypted and I know for sure when WhatsApp retroactively censored a message I sent to a friend a while back, I found that super sus.