I’m aware of what end-to-end encrypted means in a technical sense, but does the lack thereof guarantee the messages are just plaintext readable to whoever’s manning the machine?
My guess is yes but I’ve been known to have wildly incorrect guesses so I want to double-check.
bamboo@lemmy.blahaj.zone 18 hours ago
Probably yes. General rule of thumb is if you don’t control the keys, it doesn’t matter if it’s E2EE, your communications could be intercepted. Famously iMessage is E2EE but your keys are uploaded to iCloud under standard data protection. They say “Your iCloud data is encrypted, the encryption keys are secured in Apple data centers so we can help you with data recovery, and only certain data is end-to-end encrypted.” ^[support.apple.com/en-us/102651]. The encryption key is included in iCloud backups which is provided to law enforcement with a subpoena. ^[appleinsider.com/…/what-apple-surrenders-to-law-e…]
Even if a service claims it is E2EE, it’s still important to understand where that those encryption keys are stored, how they’re managed, and if security researchers have raised concerns about the E2EE claim.