| ▲ | upofadown 5 hours ago | |
The unfortunate fact about E2EE messaging is that it is hard to do. Even if you do have reproducible builds, the user is likely to make some critical mistake. What proportion of, say, Signal users actually compare any "safety numbers" for example? There is no reason to worry about software integrity if the system is already insecure due to poor usability. Sure, we should all be doing PGP on Tails with verified key fingerprints. But how many people can actually do that? | ||