|
|
|
|
|
by twleo
1081 days ago
|
|
Even if all the decryption resides in the app/web browser side, they can just silently change the code and inject some scripts to hijack the encryption routine. Although they are open-source and can be scrutinized by anybody, it does not means that's what is run on the server side. (Just say they have the capability; no accusation) So at the end of the day, the question is whether you trust Proton or not. Encryption might not help in that case. |
|
On mobile, to do such an attack we'd have to collaborate with Apple or Google to do it, which IMHO seems infeasible - but nevertheless also there a "Binary Transparency" feature of sorts might be valuable.