Remix.run Logo
SepiaSapient 5 hours ago

Beyond the privacy marketing angle, e2e allows companies with global exposure to sidestep any unpleasantness when they get a subpoena from Bumfuck, Nowhere.

Sure, the NSA, GCHQ and Mossad have a way to exfiltrate the unencrypted data but proprietary e2e is a good thing for most people IMO. Shifts the risk from "my messages are theoretically available to most law enforcement in the globe" to "YOU’RE STILL GONNA BE MOSSAD’ED UPON"[0]. This is specially good for me because I know the equivalent to the FBI where is live is too cheap to buy a Cellebrite [1] license.

[0] https://www.usenix.org/system/files/1401_08-12_mickens.pdf [1] https://arstechnica.com/gadgets/2025/10/leaker-reveals-which...

EDIT: I suppose someone could ask about Meta. The reason behind their support for scanning (and removing e2e in facebook msg) is simply regulatory capture. The zucc wishes to have a letter of marque to "protect" your children and remove the "unsafe" competitors.

EDIT2: Used the wrong term, I mixed up exfiltration channel with sidechannel attack.

johnsmith1840 4 hours ago | parent [-]

Side channel is academic at best.

Watching memory changing on a complex code base without having said code base is near impossible.

1. Run code 2. Watch memory changes 3. Correlate those to real data

If your code is doing anything complicated that's an intense thing to determine. If you're deep enough for a side channel there's likely a lot easier way of getting in.

SepiaSapient 3 hours ago | parent [-]

Brainfart on my part. I was referring to what @majorchord was worrying about, the unencrypted messages in the client get exfiltrated and get sent to the spooks using steganography on some benign request, edited my comment.

My mental model is that most competent intelligence agencies have a PRISM 3.0 deal with FAANG, including on E2E products or at least have devs on the payroll. I imagine that any backdoor is only used on important targets, so no intel sharing with Cletus the deputy.