As I understand it, if we had true end-to-end encryption, I would have to make sure I kept a set of keys, copied them between every computer and phone I used for chatting, and if I lost those keys I'd lose all my messages? Honestly, for most people I don't think that's functionality they would want, at least without us getting much better at interfaces and usability. Standard ways of storing keys, for example in a pa…
> if I lost those keys I'd lose all my messages? Not neccessarily, that just happens with bad implementations (i.e. most of them, sigh). If you get a confidential letter in the physicsl world, you open it, read it, and then store it in a safe,.or a locked drawer, correct? The software world chose to "re-seal" the letter in its envelope again instead. So if you loose your key, you loose access to the letter. The prope…
Global Encryption Day: Demand End-to-End Encryption in DMs
61–70 of 78 posts
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#62Earlier quoted context omitted.
So what you're saying is, we can just put a green lock in the UI and call it a day.
We can put some thought into how to set up the third parties to be trusted with our keys. Curretly it's very haphazard. And it's not avoidable. Even Phil Zimmerman, inventor of PGP, won't accept PGP encrypted mail because he claims to have lost his private key. The outrage "own your private keys or bust!" is much easier tho.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#63Earlier quoted context omitted.
No, it does not. Google’s proprietary implementation implements Google’s proprietary encryption system. RCS does not.
While this is currently only in Google's and Samsung's Messages apps, it's basically just the Signal protocol implemented as an RCS extension. It will most likely end up formalised in the next standard release of RCS.
Based on what evidence.
If it hasn't been added after all these years it doesn't seem likely it will be added soon.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#64Earlier quoted context omitted.
This is called "Reproducible Builds". https://signal.org/blog/reproducible-android/
That page says: > the Signal Android codebase includes some native shared libraries that we employ for voice calls (WebRTC, etc). At the time this native code was added, there was no Gradle NDK support yet, so the shared libraries aren’t compiled with the project build. Also, assuming you trust the client, how to tell if the Signal server is running the published code, especially given Signal's track record of (not)…
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#65Earlier quoted context omitted.
> if I lost those keys I'd lose all my messages? Not neccessarily, that just happens with bad implementations (i.e. most of them, sigh). If you get a confidential letter in the physicsl world, you open it, read it, and then store it in a safe,.or a locked drawer, correct? The software world chose to "re-seal" the letter in its envelope again instead. So if you loose your key, you loose access to the letter. The prope…
Most people don't have encrypted drives with fallbacks to retrieve its contents (whatever that means).
Fallbacks can be key escrow (i.e. put a printout or a physical key into a sealed envelope and deposit it at a family member, friend, or notary), and backups, encrypted with a different (or more than one) key.
https://en.wikipedia.org/wiki/Linux_Unified_Key_Setup for example allows the use of multiple keys, so a backup could use the same (primary) key as your drive and some secondary key(s) to access the backup if the primary key is lost somehow. As I mentioned in another comment here, keys should have been physical features for a long time, but hardware vendors would had to standardize on a general implementation and as we know, they all like to "standardize" on exactly their way of doing things.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#66Mail and GPG. For IM's, tox. Or Jabber+Omemo.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#67Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#68Remember when Zoom claimed that meetings were E2EE yet you could join the meeting by phone and no one batted an eye for at least one or two years? Noticed how no regular person cares when the "security code" of a chat partner changes in WhatsApp or Signal? Not to mention no regular person uses self-compiled apps for that, even if it were possible. E2EE is close to becoming a cargo cult, because done properly key mana…
We don't live in a perfect world. I'm glad that everyone I talk to is using something this secure by default.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#69Earlier quoted context omitted.
> What I find intriguing is that E2EE was significantly more common long ago than it is today. This is absurd. Today a large fraction of the world's population is using E2EE via WhatsApp.
Today a large fraction of the world's population is using E2EE via WhatsApp. That is good example of the problem I am describing. People are using E2EE created, deployed and maintained by WhatsApp in WhatsApp. That is a problem. The E2EE in WhatsApp is not truly E2EE if it is maintained by the very people providing the service in my unwavering opinion. True E2EE is entirely outside of the service transport that messa…
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#70Remember when Zoom claimed that meetings were E2EE yet you could join the meeting by phone and no one batted an eye for at least one or two years? Noticed how no regular person cares when the "security code" of a chat partner changes in WhatsApp or Signal? Not to mention no regular person uses self-compiled apps for that, even if it were possible. E2EE is close to becoming a cargo cult, because done properly key mana…
Keybase Chat is fully encrypted, persistent, and cross platform, and has the best solution to the identity problem.