Skip Navigation
81 comments
  • That article may as well be sponsored by WhatsApp. Zero direct mentions of Signal, but tons pushing people to WhatsApp. That's a bit disappointing.

    Edit: I was wrong, it does talk about Signal as well.

    • The second half of the article is about Signal.

      It sucks they mention WhatsApp first, but I think the bigger omission is that they don't mention non-US entities or anything you can self-host and federate like Matrix.

      • Oh, fair enough then!

        ETA: Yes, the lack of mentions of Matrix, etc are a bit disappointing. But I think Matrix is waaay outside their target democratic.

      • Matrix isn't super private though. It's halfway there, but compared to something like XMPP, it falls short due to the fact that any instance a user federates with gets a gigantic copy of all of their metadata, and the server operator can do whatever they want with it. So all you would have to do is spin up a new host, message a target user and get them to respond, and you're done.

  • Such an advice coming from surveillance authorities, perhaps it's a Harvest now decrypt later strategy?

    Harvest now, decrypt later, also known as store now, decrypt later or retrospective decryption, is a surveillance strategy that relies on the acquisition and long-term storage of currently unreadable encrypted data awaiting possible breakthroughs in decryption technology that would render it readable in the future - a hypothetical date referred to as Y2Q (a reference to Y2K) or Q-Day.

    The most common concern is the prospect of developments in quantum computing which would allow current strong encryption algorithms to be broken at some time in the future, making it possible to decrypt any stored material that had been encrypted using those algorithms. However, the improvement in decryption technology need not be due to a quantum-cryptographic advance; any other form of attack capable of enabling decryption would be sufficient.

    (Wikipedia)

    The more data, the better for surveillance authorities in the future, when E2EE is somehow broken.

    Maybe I'm too paranoid, but this (Harvest now decrypt later) is an ongoing known strategy.

81 comments