you are viewing a single comment's thread
view the rest of the comments
[–] 52 points 2 years ago (6 children)

As they should. I hope they burn all data and figure out a way to function going forwards without storing any data

  • source
  • hideshow 6 child comments
  • [–] 35 points 2 years ago* (1 child)

    Or they could just store the data locally on the user's device and not transmit it back to a central server, such that the company never even has possession of the data nor any way to retrieve it? Like I get it would require a major rewrite if they weren't already doing this, but at least they'd be keeping their users safe while also having no way for authorities to gain any data.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 10 points 2 years ago (3 children)
  • [–] 4 points 2 years ago (2 children)

    That requires that you trust the app vendor not to have some sort of back door, no?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago

    Not necessarily. If you trust the code running on your device then there is no backdoor they could install on a server that would break e2ee. They would have to backdoor the client where the keys are.

  • source
  • parent
  • [–] 2 points 2 years ago*

    True, unless it's open source and maybe self hosted.

    Edit: Nevermind, I'm right, I have no confidence in my own intelligence lol. If the key is on the phone and the phone stores the encrypted data to the server, that'll be secure

  • source
  • parent