191

To the surprise of no one...

you are viewing a single comment's thread
view the rest of the comments
[-] ChaoticNeutralCzech@feddit.org 18 points 1 day ago* (last edited 1 day ago)

Being FOSS is not a prerequisite of E2EE but a prerequisite of knowing it's E2EE for sure. Like, I can give you a black box that prints PGP key pairs and says "includes RPGP, MIT-licensed PGP library" but you can't trust that the machine doesn't use modified, low-entropy RNG or exfiltrate the results. The communication you do with these PGP keys is technically E2EE − a third party server relaying your messages will not be able to read them, unless I provide them with the potentially not-so-secret "random" data my box generated.

But you're right: if my black boxes are also used to encrypt/decrypt the messages with "your" keys (made by them) and I run a non-transparent ssrvice that delivers the messages, there is a case for not calling it E2EE.

this post was submitted on 28 Jan 2026
191 points (99.5% liked)

Privacy

45081 readers
183 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS