Remix.run Logo
kyralis 6 hours ago

This is based on a faulty understanding of the underlying systems. The risk with this sort of E2E encryption is not that the service provider pinky promises not to decrypt what they have, it's that they promise they will not insert a new key into your circle of trust to subsequently start decrypting things.

IshKebab 5 hours ago | parent [-]

I think you've imagined this faulty understanding. There are many mechanisms by which Apple could actually decrypt the data despite pinky promises not to. You listed one. There are others.

johnsmith1840 4 hours ago | parent [-]

You're suggesting they purposely put a backdoor into all their custom methods? Why?

From a liability standpoint that implies a security breach could result in massive loss of customer data and if it did occur would destroy their privacy image to their customers.

I agree with the point that what you actually trust is the company to not insert maliscous code or keys into your protected path but modern systems actually contain ways to truly lock out the company itself from seeing your data.

Security wise it's amazing. If a company's admin cannot take your data it's excedingly hard for a hacker to do so.

IshKebab 2 hours ago | parent [-]

> You're suggesting they purposely put a backdoor into all their custom methods? Why?

I'm not sure what you mean by "custom methods", but I'm not saying they have bypassed the e2e encryption - I'm just saying that they technically could.

And as for why they would do that, they might get compelled by a government to do it secretly. As far as I know that hasn't happened yet but I see no reason it couldn't and it would take a whistleblower to find out.

> Security wise it's amazing. If a company's admin cannot take your data it's excedingly hard for a hacker to do so.

I agree, it is the best option available. But Apple/Meta are technically lying when they say it's impossible for them to read your messages.