Live data from Hacker News

Global Encryption Day: Demand End-to-End Encryption in DMs

blog.torproject.org

1–10 of 78 posts

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#4
post #3
post #2

Kind of meaningless if you can't trust the software running on your device though, since it could be scanning locally or relaying to remote services.

So run free software?

Like signal that still refuses to put their client on fdroid?

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#6
post #3
post #2

Kind of meaningless if you can't trust the software running on your device though, since it could be scanning locally or relaying to remote services.

So run free software?

Are you confident enough to audit the free software yourself - or pushing the trust back to someone else?

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#9
post #2

Kind of meaningless if you can't trust the software running on your device though, since it could be scanning locally or relaying to remote services.

Exactly. Demand an open source for every encryption app - or at least those offered to the public en masse.

It's not enough that a FOSS alternative _exists_; it needs to be the case that closed-source encryption is not considered as an actual encryption "end".

Re: Global Encryption Day: Demand End-to-End Encryption in DMs

#10

How do you know if the Signal client running on your phone right now doesn't include a backdoor? Sure it's open source. But how do you know how it was compiled? What if someone changed the open source before shipping it to the app store?

How do you know that the AES instruction set on your device's processor doesn't include a backdoor? Sure, the algorithm is public, but how do you know how it was implemented?
Post reply on HN