Hacker News new | ask | show | jobs
by spacefight 4391 days ago
There is no true E2E if you run it inside a browser.

And even if it would be application based (PGP, S/MIME), it would still leak metadata like crazy.

With all the threat models, I come to the conclusion, that there is no real E2E possible _at_all. All known platforms have been compromised, either by lawful interception/state trojan means or by direct hacking.