Hacker News new | ask | show | jobs
by kuschku 655 days ago
You can only trust E2EE if whoever controls the server does not also control the client. Otherwise they can just backdoor the client.

I wonder what'd happen if a three letter agency subpoena'd Signal and demanded Signal's app signing key so they can ship a backdoored update to a handful of targets.