▲ 191 ▼ Nothing Chats, an iMessage app for Android, is a privacy nightmare (9to5google.com) submitted 2 years ago by ijeff@lemdro.id [M] to c/android@lemdro.id 18 comments fedilink hide all child comments
[+] helenslunch@feddit.nl -5 points 2 years ago* (last edited 2 years ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 7 points 2 years ago (1 child) Sticking two E2EE tunnels together with a plaintext middleman doesn't result in a single E2EE tunnel. The reason the distinction is important is because the security profile is vastly different—a compromised server leads to a compromised message—which isn't true for actual E2EE services like a pure Matrix link. Side note: the first thing you should ask of a "end-to-end encrypted" product to you is "which 'ends' do you mean?" I've seen TLS advertised as E2EE before. permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 1 point 2 years ago* Adding: TLS is actually a pretty apt analogy here. You could make a chat server that just accepts plain text messages over a TLS link, and that's basically the same security topology as with this Beeper bridge. But no one would call that a E2EE chat. permalink fedilink source parent
[–] Spedwell@lemmy.world 7 points 2 years ago (1 child) Sticking two E2EE tunnels together with a plaintext middleman doesn't result in a single E2EE tunnel. The reason the distinction is important is because the security profile is vastly different—a compromised server leads to a compromised message—which isn't true for actual E2EE services like a pure Matrix link. Side note: the first thing you should ask of a "end-to-end encrypted" product to you is "which 'ends' do you mean?" I've seen TLS advertised as E2EE before. permalink fedilink source parent hideshow 2 child comments replies: [–] Spedwell@lemmy.world 1 point 2 years ago* Adding: TLS is actually a pretty apt analogy here. You could make a chat server that just accepts plain text messages over a TLS link, and that's basically the same security topology as with this Beeper bridge. But no one would call that a E2EE chat. permalink fedilink source parent
[–] Spedwell@lemmy.world 1 point 2 years ago* Adding: TLS is actually a pretty apt analogy here. You could make a chat server that just accepts plain text messages over a TLS link, and that's basically the same security topology as with this Beeper bridge. But no one would call that a E2EE chat. permalink fedilink source parent