zlacker

[return to "The coming war on end-to-end encryption"]
1. Karell+6d[view] [source] 2023-04-21 17:53:22
>>EGreg+(OP)
The thing I don't get is... won't bans on end-to-end encryption ban https?

If I go to a website and ask for a web page over https, isn't the request and response between my device and the web server, an end-to-end encrypted message? Because the endpoints are my device and the web server.

If I can't send my credit card details to a payment provider over an end-to-end encrypted channel, doesn't all commerce on the web just fall apart?

How can a ban on end-to-end encrypted communication even fucking work?

◧◩
2. EGreg+Oe[view] [source] 2023-04-21 18:01:00
>>Karell+6d
Well, HTTPS is not end-to-end. That latter term is reserved for encryption that encrypts the messages between clients so servers can’t parse them.

When you have a centralized system like ICANN DNS, the governments know which IP addresses the domain points to. They can go and serve them National Security Letters or shake them down to install secret backdoors.

WhatsApp and Facebook can lie to you that they’re end-to-end encrypted. There is nothing stopping them from shipping custom updates. In facg they’ve been caught red-handed spying on both your video and audio. The only way you can be SURE an app isnt lying to you is with open source software, then you only have to trust the OS and browser (the Trusted Computing Base).

(That is why I am a big fan of blockchain-based smart contaracts. But blockchains are slow, so the next best thing is hosting your business logic using open source software on servers you control.)

Why do so many people trust Big Tech? Simple. We have no other choice!

Where are the VIABLE AND USER FRIENDLY open source alternatives to Facebook, Twitter, Telegram backends?

No one seems to have built anything better or more efficient than, say, Mastodon.

Except us. It was a labor of love and cost me a million dollars to date: https://github.com/Qbix/Platform

PS: If you play with it for a afternoon, post your experience or email me. I would be thrilled to hear about your experience, good or bad. And of course use it for anything you want.

I would be very happy to be proven wrong and see some more competitors being mentioned here, but if you do, make an honest assessment of how they compare! People need alternatives to the closed walled gardens, but having all these features working and up-to-date with browser tech is extremely hard: https://qbix.com/features.pdf

◧◩◪
3. nomel+Qg[view] [source] 2023-04-21 18:10:27
>>EGreg+Oe
> Well, HTTPS is not end-to-end

I'm not well versed for encryption, but isn't this a matter of perspective? If you're downloading a .midi file from a server, the other "end" is that server, isn't it? Will the forces pushing this make any nuanced distinction, outside of this?

◧◩◪◨
4. EGreg+5i[view] [source] 2023-04-21 18:16:31
>>nomel+Qg
The “end” in end-to-end encryption for regular users is never a server.

Servers are online 24/7 listening and can be found and raided and/or hacked by various forces.

Clients are harder to locate. Especially if all you need to authenticate is a public/private keypair you generated.

That is why governments are so frustrated with crypto.

◧◩◪◨⬒
5. Karell+mj[view] [source] 2023-04-21 18:22:38
>>EGreg+5i
> The “end” in end-to-end encryption for regular users is never a server.

Why not? Are servers not communication endpoints?

◧◩◪◨⬒⬓
6. EGreg+Jj[view] [source] 2023-04-21 18:24:31
>>Karell+mj
For the reason I just told you — they can be compromised much more easily, and are typically run by a party which isn’t fully aligned with your interests and those of the other participants in your conversation.
[go to top]