logoalt Hacker News

i_am_proteustoday at 12:07 PM1 replyview on HN

Reminder that no end-to-end encryption arrangement can do anything before encryption, or after decryption, at the endpoints.


Replies

windowlikertoday at 12:21 PM

Right. It's purely a protection against MitM snooping. The app has to have the messages in plaintext to display to you via whatever mechanism the OS uses. Seems obvious, but also not, at the same time.

I've found other ways Signal can leak information, even with disappearing messages. It's not the total install-and-be-done privacy screen that some people think it is, and requires a little effort at the user end to fill in a few gaps.