Comment on Lawsuit Alleges That WhatsApp Has No End-to-End Encryption
lavander@lemmy.dbzer0.com 2 weeks agoUnfortunately even the best intentioned and best audited project can be compromised. So that is not a guarantee (sure, much better than closed source but that is a given)
You may be forced by a rubber hose attack (or legal one) to insert vulnerabilities in your code… and you have the traffic… a single point to attack… signal/proton/etc
Is it possible with two different vendors? Sure it is but it is way more complicated
Quexotic@infosec.pub 2 weeks ago
That’s a really good point. All we’d need is for signal devs to be compromised in some way and the next update ends security for signal.