▲ 191 ▼ Nothing Chats, an iMessage app for Android, is a privacy nightmare (9to5google.com) submitted 2 years ago by ijeff@lemdro.id [M] to c/android@lemdro.id 18 comments fedilink hide all child comments
[–] sbv@sh.itjust.works 51 points 2 years ago (2 children) It's bizarre that Sunbird touted their solution as end-to-end encrypted, when it can't be - iMessage drops to plaintext on the Mac farm. permalink fedilink source hideshow 4 child comments replies: [+] helenslunch@feddit.nl 15 points 2 years ago* (last edited 2 years ago) (6 children) [deleted] permalink fedilink source parent hideshow 12 child comments replies: [–] entropicdrift@lemmy.sdf.org 39 points 2 years ago (2 children) While it's a good solution, it is entirely untrue. A message is either End to End Encrypted or it is not. If the message is decrypted at any point between the sender and the intended recipient, it is definitively not End to End Encrypted. permalink fedilink source parent hideshow 4 child comments replies: [+] HeartyBeast@kbin.social 1 point 2 years ago [deleted] permalink fedilink source parent [+] helenslunch@feddit.nl -6 points 2 years ago* (last edited 2 years ago) (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] entropicdrift@lemmy.sdf.org 13 points 2 years ago You can't change encryption in the middle without decrypting, however briefly. permalink fedilink source parent [–] Railcar8095@lemm.ee 2 points 2 years ago It’s encrypted at the beginning and at the end, but NOT from beginning to end. permalink fedilink source parent [–] habanhero@lemmy.ca 24 points 2 years ago E2EE means it's End-to-End Encrypted. If it's decrypted at any point during transit then it's by definition not E2EE and Beeper shouldn't be making that claim. permalink fedilink source parent [–] skullgiver@popplesburger.hilciferous.nl 20 points 2 years ago* (last edited 2 years ago) (1 child) [This comment has been deleted by an automated system] permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 1 point 2 years ago* (last edited 2 years ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] skullgiver@popplesburger.hilciferous.nl 2 points 2 years ago* (last edited 2 years ago) (1 child) [This comment has been deleted by an automated system] permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 0 points 2 years ago* (last edited 2 years ago) [deleted] permalink fedilink source parent [–] SuddenlyBlowGreen@lemmy.world 9 points 2 years ago* (1 child) It's E2EE from the sender to your Beeper server, where it's decrypted, then re-encypted as a Matrix message. Then it's not E2E encrypted. One end is your device, the other end is the other device. It's only E2E encrypted if it is not decrypted until it reaches the other device. permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl -5 points 2 years ago* (last edited 2 years ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 7 points 2 years ago (1 child) Sticking two E2EE tunnels together with a plaintext middleman doesn't result in a single E2EE tunnel. The reason the distinction is important is because the security profile is vastly different—a compromised server leads to a compromised message—which isn't true for actual E2EE services like a pure Matrix link. Side note: the first thing you should ask of a "end-to-end encrypted" product to you is "which 'ends' do you mean?" I've seen TLS advertised as E2EE before. permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 1 point 2 years ago* Adding: TLS is actually a pretty apt analogy here. You could make a chat server that just accepts plain text messages over a TLS link, and that's basically the same security topology as with this Beeper bridge. But no one would call that a E2EE chat. permalink fedilink source parent [+] kinttach@lemm.ee 5 points 2 years ago [deleted] permalink fedilink source parent [–] Sjy@lemm.ee 2 points 2 years ago* (last edited 2 years ago) (1 child) How does one host their own beeper server? Edit: found it permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 3 points 2 years ago* (last edited 2 years ago) [deleted] permalink fedilink source parent [–] dandroid@dandroid.app 9 points 2 years ago As someone who works in the tech industry, this is not surprising to me at all. Typically the people who communicate with the media and customers don't know a single thing about tech. They don't know what end to end encryption means. They know just know encryption is involved and they have heard the buzzword, so they repeat it. permalink fedilink source parent
[+] helenslunch@feddit.nl 15 points 2 years ago* (last edited 2 years ago) (6 children) [deleted] permalink fedilink source parent hideshow 12 child comments replies: [–] entropicdrift@lemmy.sdf.org 39 points 2 years ago (2 children) While it's a good solution, it is entirely untrue. A message is either End to End Encrypted or it is not. If the message is decrypted at any point between the sender and the intended recipient, it is definitively not End to End Encrypted. permalink fedilink source parent hideshow 4 child comments replies: [+] HeartyBeast@kbin.social 1 point 2 years ago [deleted] permalink fedilink source parent [+] helenslunch@feddit.nl -6 points 2 years ago* (last edited 2 years ago) (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] entropicdrift@lemmy.sdf.org 13 points 2 years ago You can't change encryption in the middle without decrypting, however briefly. permalink fedilink source parent [–] Railcar8095@lemm.ee 2 points 2 years ago It’s encrypted at the beginning and at the end, but NOT from beginning to end. permalink fedilink source parent [–] habanhero@lemmy.ca 24 points 2 years ago E2EE means it's End-to-End Encrypted. If it's decrypted at any point during transit then it's by definition not E2EE and Beeper shouldn't be making that claim. permalink fedilink source parent [–] skullgiver@popplesburger.hilciferous.nl 20 points 2 years ago* (last edited 2 years ago) (1 child) [This comment has been deleted by an automated system] permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 1 point 2 years ago* (last edited 2 years ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] skullgiver@popplesburger.hilciferous.nl 2 points 2 years ago* (last edited 2 years ago) (1 child) [This comment has been deleted by an automated system] permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 0 points 2 years ago* (last edited 2 years ago) [deleted] permalink fedilink source parent [–] SuddenlyBlowGreen@lemmy.world 9 points 2 years ago* (1 child) It's E2EE from the sender to your Beeper server, where it's decrypted, then re-encypted as a Matrix message. Then it's not E2E encrypted. One end is your device, the other end is the other device. It's only E2E encrypted if it is not decrypted until it reaches the other device. permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl -5 points 2 years ago* (last edited 2 years ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 7 points 2 years ago (1 child) Sticking two E2EE tunnels together with a plaintext middleman doesn't result in a single E2EE tunnel. The reason the distinction is important is because the security profile is vastly different—a compromised server leads to a compromised message—which isn't true for actual E2EE services like a pure Matrix link. Side note: the first thing you should ask of a "end-to-end encrypted" product to you is "which 'ends' do you mean?" I've seen TLS advertised as E2EE before. permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 1 point 2 years ago* Adding: TLS is actually a pretty apt analogy here. You could make a chat server that just accepts plain text messages over a TLS link, and that's basically the same security topology as with this Beeper bridge. But no one would call that a E2EE chat. permalink fedilink source parent [+] kinttach@lemm.ee 5 points 2 years ago [deleted] permalink fedilink source parent [–] Sjy@lemm.ee 2 points 2 years ago* (last edited 2 years ago) (1 child) How does one host their own beeper server? Edit: found it permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 3 points 2 years ago* (last edited 2 years ago) [deleted] permalink fedilink source parent
[–] entropicdrift@lemmy.sdf.org 39 points 2 years ago (2 children) While it's a good solution, it is entirely untrue. A message is either End to End Encrypted or it is not. If the message is decrypted at any point between the sender and the intended recipient, it is definitively not End to End Encrypted. permalink fedilink source parent hideshow 4 child comments replies: [+] HeartyBeast@kbin.social 1 point 2 years ago [deleted] permalink fedilink source parent [+] helenslunch@feddit.nl -6 points 2 years ago* (last edited 2 years ago) (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] entropicdrift@lemmy.sdf.org 13 points 2 years ago You can't change encryption in the middle without decrypting, however briefly. permalink fedilink source parent [–] Railcar8095@lemm.ee 2 points 2 years ago It’s encrypted at the beginning and at the end, but NOT from beginning to end. permalink fedilink source parent
[+] helenslunch@feddit.nl -6 points 2 years ago* (last edited 2 years ago) (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] entropicdrift@lemmy.sdf.org 13 points 2 years ago You can't change encryption in the middle without decrypting, however briefly. permalink fedilink source parent [–] Railcar8095@lemm.ee 2 points 2 years ago It’s encrypted at the beginning and at the end, but NOT from beginning to end. permalink fedilink source parent
[–] entropicdrift@lemmy.sdf.org 13 points 2 years ago You can't change encryption in the middle without decrypting, however briefly. permalink fedilink source parent
[–] Railcar8095@lemm.ee 2 points 2 years ago It’s encrypted at the beginning and at the end, but NOT from beginning to end. permalink fedilink source parent
[–] habanhero@lemmy.ca 24 points 2 years ago E2EE means it's End-to-End Encrypted. If it's decrypted at any point during transit then it's by definition not E2EE and Beeper shouldn't be making that claim. permalink fedilink source parent
[–] skullgiver@popplesburger.hilciferous.nl 20 points 2 years ago* (last edited 2 years ago) (1 child) [This comment has been deleted by an automated system] permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 1 point 2 years ago* (last edited 2 years ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] skullgiver@popplesburger.hilciferous.nl 2 points 2 years ago* (last edited 2 years ago) (1 child) [This comment has been deleted by an automated system] permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 0 points 2 years ago* (last edited 2 years ago) [deleted] permalink fedilink source parent
[+] helenslunch@feddit.nl 1 point 2 years ago* (last edited 2 years ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] skullgiver@popplesburger.hilciferous.nl 2 points 2 years ago* (last edited 2 years ago) (1 child) [This comment has been deleted by an automated system] permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 0 points 2 years ago* (last edited 2 years ago) [deleted] permalink fedilink source parent
[–] skullgiver@popplesburger.hilciferous.nl 2 points 2 years ago* (last edited 2 years ago) (1 child) [This comment has been deleted by an automated system] permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 0 points 2 years ago* (last edited 2 years ago) [deleted] permalink fedilink source parent
[+] helenslunch@feddit.nl 0 points 2 years ago* (last edited 2 years ago) [deleted] permalink fedilink source parent
[–] SuddenlyBlowGreen@lemmy.world 9 points 2 years ago* (1 child) It's E2EE from the sender to your Beeper server, where it's decrypted, then re-encypted as a Matrix message. Then it's not E2E encrypted. One end is your device, the other end is the other device. It's only E2E encrypted if it is not decrypted until it reaches the other device. permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl -5 points 2 years ago* (last edited 2 years ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 7 points 2 years ago (1 child) Sticking two E2EE tunnels together with a plaintext middleman doesn't result in a single E2EE tunnel. The reason the distinction is important is because the security profile is vastly different—a compromised server leads to a compromised message—which isn't true for actual E2EE services like a pure Matrix link. Side note: the first thing you should ask of a "end-to-end encrypted" product to you is "which 'ends' do you mean?" I've seen TLS advertised as E2EE before. permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 1 point 2 years ago* Adding: TLS is actually a pretty apt analogy here. You could make a chat server that just accepts plain text messages over a TLS link, and that's basically the same security topology as with this Beeper bridge. But no one would call that a E2EE chat. permalink fedilink source parent
[+] helenslunch@feddit.nl -5 points 2 years ago* (last edited 2 years ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 7 points 2 years ago (1 child) Sticking two E2EE tunnels together with a plaintext middleman doesn't result in a single E2EE tunnel. The reason the distinction is important is because the security profile is vastly different—a compromised server leads to a compromised message—which isn't true for actual E2EE services like a pure Matrix link. Side note: the first thing you should ask of a "end-to-end encrypted" product to you is "which 'ends' do you mean?" I've seen TLS advertised as E2EE before. permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 1 point 2 years ago* Adding: TLS is actually a pretty apt analogy here. You could make a chat server that just accepts plain text messages over a TLS link, and that's basically the same security topology as with this Beeper bridge. But no one would call that a E2EE chat. permalink fedilink source parent
[–] Spedwell@lemmy.world 7 points 2 years ago (1 child) Sticking two E2EE tunnels together with a plaintext middleman doesn't result in a single E2EE tunnel. The reason the distinction is important is because the security profile is vastly different—a compromised server leads to a compromised message—which isn't true for actual E2EE services like a pure Matrix link. Side note: the first thing you should ask of a "end-to-end encrypted" product to you is "which 'ends' do you mean?" I've seen TLS advertised as E2EE before. permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 1 point 2 years ago* Adding: TLS is actually a pretty apt analogy here. You could make a chat server that just accepts plain text messages over a TLS link, and that's basically the same security topology as with this Beeper bridge. But no one would call that a E2EE chat. permalink fedilink source parent
[–] Spedwell@lemmy.world 1 point 2 years ago* Adding: TLS is actually a pretty apt analogy here. You could make a chat server that just accepts plain text messages over a TLS link, and that's basically the same security topology as with this Beeper bridge. But no one would call that a E2EE chat. permalink fedilink source parent
[–] Sjy@lemm.ee 2 points 2 years ago* (last edited 2 years ago) (1 child) How does one host their own beeper server? Edit: found it permalink fedilink source parent hideshow 2 child comments replies: [+] helenslunch@feddit.nl 3 points 2 years ago* (last edited 2 years ago) [deleted] permalink fedilink source parent
[+] helenslunch@feddit.nl 3 points 2 years ago* (last edited 2 years ago) [deleted] permalink fedilink source parent
[–] dandroid@dandroid.app 9 points 2 years ago As someone who works in the tech industry, this is not surprising to me at all. Typically the people who communicate with the media and customers don't know a single thing about tech. They don't know what end to end encryption means. They know just know encryption is involved and they have heard the buzzword, so they repeat it. permalink fedilink source parent