|
|
|
|
|
by woodruffw
970 days ago
|
|
I agree that the verification UI sucks. I have similar stories about otherwise technical people not knowing about it or otherwise not understanding it. At the same time: the relevant comparison here is email. Email isn’t even TOFU between arbitrary identities; it’s trust-on-each-message. Similarly for conceptual identities (like a bank’s catch-all address). (I also agree with your point about this needing to be one of Signal’s businesses. WhatsApp and other chats already do this, I believe.) |
|
It's just the security story on that if you never want the content disclosed isn't great, but conversely, conceptual entity communications are always going to be a bit public by nature.
There's a whole other rant I have about this problem, where we really lack domain specific trust standards - i.e. communicating with a business, what I want to know is "is this a recognized legal business entity in it's jurisdiction, and what's it's status to mine?" which is very different to "I need to make absolutely sure me and John Smith's communication is just between us" - but they're in the same space of problem.