Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> And for public channels, E2E is pointless - everyone can see it anyway.

Shouldn't it at least provide some guarantee that what you receive is what was sent?



E2E doesn't typically provide that. No common E2E messenger enforces the necessary key verification. Only some inform about key changes. Only Matrix can be configured to refuse mis-signed messages.

And then there is even stuff like OMEMO, which is E2E, but intentionally does not do authentication of messages, quite the opposite: It's protocol is designed such that you can always deny having sent such a message...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: