Showing posts with label end-to-end. Show all posts
Showing posts with label end-to-end. Show all posts

Thursday, December 8, 2022

Merry Encryptmas

from here and here

Christmas came early for iPhone users who care about security and privacy. They're getting a bunch more end-to-end encryption, and the government can suck it.

Enjoy it while it lasts, of course. Tech companies usually give you less of those things, not more.

Thursday, September 29, 2022

The cipher can't be trusted right now

from here and here

It seems that life is imitating art a weird sort of way. Matrix, an ecosystem of open source chat and collaboration clients, has vulnerabilities that subvert the protection of it's end to end encryption, but unlike the movie there's a fix that allows you to trust the cipher again if you hurry up and apply the patch.

Tuesday, September 7, 2021

Nothingburgers for everyone

from here

$15 - $25 per user for tricking users into thinking their communications were secure and private seems completely inadequate as either a form of restitution or as a deterrent to keep Zoom or other companies from doing it again.

Tuesday, November 10, 2020

The security claims were pulled out of their ass

from here

The lesson we should all learn from Zoom is that it's not really end-to-end encrypted if a middleman holds the keys

Friday, June 12, 2020

You can't censor what you can't see

from here

So Zoom doing the Chinese government's bidding is apparently a thing, and it makes me wonder if the flaws in their previous attempts at encryption were mistakes or perhaps something else. It also makes me wonder if their motivation for only giving their future end to end encryption to paying customers might be something other than the fight against child porn  ("Think of the children" is just a little too convenient).

Thursday, April 2, 2020

Cheap, Fast, or Secure... Pick Two

from here

So it appears that Zoom's "end-to-end" encryption only counts as end-to-end if you consider Zoom's servers themselves to be one of the ends. Specifically, according to their own blog, they have software running on their servers acting like legitimate communication endpoints so that they can send the unencrypted data to devices that don't support their end-to-end encryption. It's a backdoor dressed up as a compatibility feature. We have to take them at their word that this backdoor will never be used by misbehaving employees and that various governments will never or can never compel them to use it to reveal our communications.

They could have (and arguably should have) simply told customers they can't use the end-to-end encryption feature when participants are using devices that don't support it, but they chose to compromise the communication channel instead so that users could maintain a (now false) sense of security.