|
|
|
|
|
by dwaite
946 days ago
|
|
Maybe. The challenge with E2EE is how to resolve an email address or phone number to the authoritative public key and networking route, securely. If we wind up with multiple authoritative sources of that mapping, each one has the potential to lie and become an avenue for surveillance. Thats ignoring for the moment lesser issues, such as privacy issues with leaked metadata in querying these sources. Things like Key Transparency in the IETF are tackling some of this, in the sense that they'll provide public evidence of tampering. I don't suspect what Google has implemented for their own client/server setup gets us close to a multi-party solution within RCS Universal profile. |
|