Remix.run Logo
IshKebab 5 hours ago

Yes that's exactly his point. E2E is often sold as preventing the owners of the server from being able to read the messages at all, even if they are evil and misleading you.

That's obviously only the case if they aren't also the sole providers of the "ends".

johnsmith1840 4 hours ago | parent [-]

There are actual methods to do this though just not sure anyone does it yet.

1. 3rd party audit of a current repo hash 2. Public hosting of hash 3. Modern attested compute can check the current startup and running code hash and return to the user for their own checks. 4. User encrypts the last known hash they used or trust a 3rd party to perform the check like azure's methods.

Another way is to open source it and repeat 2/3/4

The way around that requires either a backdoor in attested hardware which would be wild if discovered because it's the same tech protecting companies and governments most sensitive info so they're all incentivised to audit that.

slashdave 4 hours ago | parent | next [-]

I seem to recall that Apple provided an audit

IshKebab 2 hours ago | parent | prev [-]

How would that work for closed source apps like iMessage and WhatsApp?