Would you trust Elon's #Twitter with your direct messages, phone, or video calls, even when he claims end-to-end encryption is in place?

@lauren

Well the whole point of end-to-end encryption is that we don't have to answer that question.

@volkris well the implementation matters. well would you trust e2e encryption implemented as directed by elon musk? well?

@lauren

@mawhrin

So one funny thing about this question is that is legitimately difficult to do correctly, with plenty of room for mistakes.

So part of the story is that even if you think
is a terribly dishonest person, while some other developer is a completely honest one, the trickiness of implementation means that you still can't trust the honest one. The intention becomes something of a side note because it's just that easy to screw it up.

So I don't care who implements it. I really don't go for that sort of drama. The product needs to sink or swim on its own, to be shown to be solid regardless of any kind of ad hominem attack on its author.

I don't care who writes it; I'm going to gauge my trust on what independent experts in the field say once they have analyzed it.

But again, the whole point of encryption is not having to trust the developer.

@lauren

@volkris there are layers of trust, and in this case it starts with (at least) “do you trust musk as a manager to employ competent engineers and to not micromanage them in order to ship the product faster”?

(also do read something about the current twitter implementation of e2e encryption, matthew garrett error an interesting blog about it.)

@lauren

@mawhrin @volkris @lauren Honestly, if you have taken any read at how Teslas software allegedly works, I'd not trust this man to hold a set of perfectly average eggs during a supermarket run.

That's aside, encryption is at least somewhat like writing tests - any encryption is better than no encryption.

Here's the blogpost for the lazy among us btw: https://mjg59.dreamwidth.org/66791.html

Reading this, the implementation strikes me as "simple, yet just as exploitable as necessary if law enforcement comes knocking". Which probably is fine enough for most people.

@glitch @mawhrin @volkris I disagree. Weak encryption that users think is strong encryption is WORSE than nothing, because they will use it thinking it is strong, in ways they wouldn't when no encryption was present.

Follow

@lauren

Which comment are you disagreeing with? I think we're all on that same page, unless there's a comment I'm not seeing here.

@glitch @mawhrin

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.