Hacker News new | ask | show | jobs
by the_gipsy 924 days ago
Just because WhatsApp does it too, doesn't make it right.

These apps are not e2ee if almost every user has in effect encryption disabled.

1 comments

Which app would qualify in your case? Signal suffers from the same client-side problem.
Matrix also provides the ability to back up keys in the server, but you select a separate passphrase for encrypting them before they're uploaded.

(Yes, it would be nice if the user didn't need two passphrases for this use, but Matrix cannot safely revert to key derivation because client could accidentally leak the master password to the server due to existing implementations.)

Don't know why you got downvoted, it's a very good question.

I've been using matrix. It's e2ee and multiple client sessions seem to be working just fine, they all sync without problems.

not by default, which is a massive difference.
I am not sure what the answer is here. What you are arguing for will hurt regular users who will lose their digital lives if they lose their passwords.

Signal will be backed-up on iCloud _by default_ and client side will be an issue.

> Signal will be backed-up on iCloud _by default_

No, it absolutely is not. It seems like you don't have a good understanding of how actual E2EE systems work.

"lose their digital lives" is hyperbolic emotive language. We're talking about a loss of chat history, not the death of people. Lots of people lose their chat histories all the time, it hurts but people get over it.