Hacker News new | ask | show | jobs
by jmcnulty 1596 days ago
How secure is E2EE anyway when, like WhatsApp, it's implemented such that you blindly trust a 3rd party to distribute the public keys and instruct your client who it should be encrypting and sending your messages to? How do you know your mobile app isn't also sending encrypted copies of your messages to a ghost user you have no visibility of? A ghost user that could be WhatsApp, law enforcement or anyone.