Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

311–312 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#311
post #292

Earlier quoted context omitted.

Server would have the keys _because_ the client-side code can send it to the server. That's also possible in the native app, isn't it?

The apps are updated relatively infrequently, and you can put off updating to see if problems are found with each release. In the browser, you'd have to analyze every script Facebook ever sends you to see if it's exfiltrating your key.

Valid point. But apps too can have non-obvious backdoors that don't require updating the new version. If you don't have source code and reproducible builds, you are already fully trusting the server.
Post reply on HN