I used to store GPG encrypted files in google drive. But then I noticed bitrot in the stored files which made them impossible to decrypt. So I started adding CRC redundancy through DVDisaster. Which worked but became a PITA. So I finally gave up.
They really want your data.
Pika@sh.itjust.works 6 hours ago
I don’t agree that would fit the protocol of end to end, E2E by design means that it’s encrypted from the sender to the intended recipient. When you send a message the intended recipient isn’t the server, it’s the user you are sending to. That type of system would be called a encrypt in transit or a server client encryption not E2E. If they are classifying it as E2E that would be incorrect.
baronvonj@piefed.social 6 hours ago
An e2ee group chat would need every member to have every other member’s public key. So for 5 people, your client would sign with your private key and send 4 unique messages encrypted each with 1 other person’s public key. Each of them would decrypt their copy of the message with their private key and verify the signature with your public key. So I think what arcterus was saying was that employee who requests access to a user’s messages then becomes just another member of a group chat, but the UI just doesn’t show it as such. Every message you send is then secretly encrypted, on your client, with their special public key and sent to them to be decrypted. That would still be E2EE.
Pika@sh.itjust.works 5 hours ago
Yea, I do agree with that POV on it. A ghost key like that would be within spec, cause yea at that point it would just be another member. I wasn’t taking it as an additional group member though, since the whistleblower is stating that they can put in any user id and have access to all messages live, that would mean they would have a ghost user on all messages period regardless of if its a group chat or not.
baronvonj@piefed.social 5 hours ago
I will say, not too long ago there was some question if I had setup a WhatsApp account with my number due to some emails I was receiving. Not wanting to install the app and unwittingly create an account just by checking if I had one, my wife created a group chat with just her and my number, sent a message, and then we saw it get marked as read by all. Which in an E2EE system should not have been possible without me having the app setup. so I did go ahead and wiped an old and setup the app to make sure I was in control of any account for my number, and I did then receive that group chat. But still, very sketchy.