you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 2 years ago (2 children)

That requires that you trust the app vendor not to have some sort of back door, no?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago

    Not necessarily. If you trust the code running on your device then there is no backdoor they could install on a server that would break e2ee. They would have to backdoor the client where the keys are.

  • source
  • parent
  • [–] 2 points 2 years ago*

    True, unless it's open source and maybe self hosted.

    Edit: Nevermind, I'm right, I have no confidence in my own intelligence lol. If the key is on the phone and the phone stores the encrypted data to the server, that'll be secure

  • source
  • parent