• Treczoks@lemmy.world
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    3
    ·
    22 hours ago

    As long as the keys are handled via a closed source app and server system, e2ee is potentially broken.

    Even if you generated the key, keep the private part locally and submitted only the public part to your communication partner, you can never be sure that the intransparent app does keep your private key private.

    With WhatsApp I’m quite sure that they somehow can retrieve the private key. Certain events point to that. But I see no reason to consider signal or telegram any more trustworthy - they are all prone to governmental influence.

    And as open source and closed app infrastructure are incompatible, I would not handle anything important on an Android or Apple device.

    • DeckPacker@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      Why would you not trust Signal?

      You don’t have to trust their server infrastructure, because the end to end encryption has been verified by countless experts (and all their client side code can be looked at by anyone).

      • adhdsergio@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        15 hours ago

        I’ve no proof of this, but technically the whatsapp app is closed source so they could push an update that collects the private keys, if they don’t do this already

        • ඞmir@lemmy.ml
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          One way to prevent this is would be to re-sign the app with your own signing key and delete that key before court, I guess. But those people whose conversations appeared probably just had Google Drive plaintext backups enabled.

      • Scrollone@feddit.it
        link
        fedilink
        English
        arrow-up
        8
        arrow-down
        1
        ·
        20 hours ago

        I don’t know about WhatsApp, but macOS backups your keys on iCloud by default, so…