| ▲ | slashdave a day ago | |||||||||||||||||||||||||||||||
Only if the company misleads and adds a backdoor to the front-end app (thus this entire discussion). If the company is misleading, any encryption technology is irrelevant anyway. | ||||||||||||||||||||||||||||||||
| ▲ | majorchord a day ago | parent | next [-] | |||||||||||||||||||||||||||||||
In the US at least, companies can and do receive secret demands from the government to add whatever kind of backdoor they want, and you're not allowed to disclose it in any way, they even order you to preserve any warrant canaries you have implemented. This is for example why Lavabit chose to go out of business instead of giving up their keys. | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
| ▲ | dd8601fn a day ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||
The company can provide secure enclave and allow the architecture to be audited by third parties. Which apple does. It's largely academic though, as almost nobody opts-in to escalated e2e posture in apple services unless they're a high risk person (journalist, dissident, etc). The headaches that come from e2e everything are too great for most people. | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
| ▲ | IshKebab a day ago | parent | prev [-] | |||||||||||||||||||||||||||||||
Yes that's exactly his point. E2E is often sold as preventing the owners of the server from being able to read the messages at all, even if they are evil and misleading you. That's obviously only the case if they aren't also the sole providers of the "ends". | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||