Earlier quoted context omitted.
This is called "Reproducible Builds". https://signal.org/blog/reproducible-android/
Reproducible builds are for developers. As a user I didn't build the app on my phone. I have a phone with Signal on it. Tell me what I should do to verify it's running the open source Signal code.
Global Encryption Day: Demand End-to-End Encryption in DMs
21–30 of 78 posts
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#22Honestly, for most people I don't think that's functionality they would want, at least without us getting much better at interfaces and usability. Standard ways of storing keys, for example in a password manager, would be a good start (does this already exist and I've missed it?)
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#23Earlier quoted context omitted.
This is called "Reproducible Builds". https://signal.org/blog/reproducible-android/
Reproducible builds are for developers. As a user I didn't build the app on my phone. I have a phone with Signal on it. Tell me what I should do to verify it's running the open source Signal code.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#24Which is why many of us are firmly against RCS. End to end encryption is critically important and no messaging standard should exist that doesn't include it.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#25As I understand it, if we had true end-to-end encryption, I would have to make sure I kept a set of keys, copied them between every computer and phone I used for chatting, and if I lost those keys I'd lose all my messages? Honestly, for most people I don't think that's functionality they would want, at least without us getting much better at interfaces and usability. Standard ways of storing keys, for example in a pa…
Unless you made an unencrypted backup, then yes, that's true and that is the reason why Telegram decided against E2EE by default. According to them their users prefer easy cloud access to their messages over security.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#26It's mind blowing e2e is not a standard. I guess the equivalent is looking back and realising cars and homes did not have locks at one stage
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#27As I understand it, if we had true end-to-end encryption, I would have to make sure I kept a set of keys, copied them between every computer and phone I used for chatting, and if I lost those keys I'd lose all my messages? Honestly, for most people I don't think that's functionality they would want, at least without us getting much better at interfaces and usability. Standard ways of storing keys, for example in a pa…
People need to learn again how the devices in their pocket work and the risks for not doing things properly!
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#28As I understand it, if we had true end-to-end encryption, I would have to make sure I kept a set of keys, copied them between every computer and phone I used for chatting, and if I lost those keys I'd lose all my messages? Honestly, for most people I don't think that's functionality they would want, at least without us getting much better at interfaces and usability. Standard ways of storing keys, for example in a pa…
Only if the developers of the software insist on encryption at rest in addition to transit encryption.
For example, you don’t lose the ability to open files you have already downloaded via HTTPS just because the client or server certificate later expires.