Hacker News new | ask | show | jobs
by seqastian 1317 days ago
> I personally wouldn't even run a public service for others without E2E encryption.

So don't? seems like everyone got what they wanted.

1 comments

Well, thinking logically: if everyone really got what they wanted, that question wouldn't be in the FAQ, would it?
Especially with things like notifications, even e2e encryption can't generally provide complete privacy because metadata is data too ;)
You solve that by forwarding/decrypting/adding noise between servers, enough to cover metadata traffic you generate. The only data you reveal is anyone listening know you might have used it at some point. See https://vuvuzela.io/ I suspect it is named so because it uses a lot of bandwidth.
It's of course possible to mitigate, but that's somewhat more involved than "just" sprinkling e2e encryption on top ;)
Signal does it just fine.