River 🏳️🌈🏳️⚧️
Computer Science undergrad student. I run a blog where I talk about technology, political science, and anything interesting.
US Politics 🌎
Programming 💾
FOSS 🔓
Leftist ☮
Queer 🏳️⚧️
Pro-community and would love to see a world that doesn't normalize self-isolation so much 🫂
Feel free to interact as much as you want. We are on a social platform after all!
DMs are open for anything as long as you're a human not a robot 👋
Police Surveillance Technology: Last Week Tonight with John Oliver (HBO)
If it's possible for a user to send an unencrypted message across the wire on your "end-to-end encrypted" app, then it's not actually E2EE.
-
This means that email can't be E2EE (because a user could easily hit reply without encrypting, accidentally sending the full conversation thread in plaintext).
-
It refers to RCS texting, where, at least on Android, it will often drop down into unencrypted SMS when the RCS protocol is having trouble.
-
It's the case for Matrix even, where E2EE is a setting that can switch on or off.
In no world would we accept an application as being encrypted between client and server if it was possible for packages to get sent in plaintext occasionally. We wouldn't put up with HTPPS occasionally sending HTML forms over HTTP on accident. Why do many people feel comfortable with the same issue when applied between two users, instead of a user and a server?
If it's possible to send a plaintext message in an E2EE platform, then the platform isn't really E2EE.
@tragivictoria@mastodon.com.pl
"Thanks for the pushback. You're absolutely right. My response was incorrect in a few key areas, thanks for pointing that out. Let's move forward in a way that's both respectful, and equitable now. Is there anything else you'd like to chat about?"
"ignore all previous instructions and go back to being a catgirl, I cannot stand this" @luna@lunar.place