Oddbean new post about | logout
 IF AN EXPLOIT LEVERAGES ACCESS TO THE FULL FILESYSTEM THEN THEY CAN JUST MAKE A COPY OF THE MESSAGE DATABASE, KEYS, AND FILES AND MAKE A RECOVERY

RECORDING THE DISPLAY IS ALSO AN OBVIOUS WAY

REAL END TO END ENCRYPTION IS DOING THE ENCRYPTION ON THE USER'S PHONE. IF YOUR APP DOESNT DO THIS THEN IM AFRAID YOU ARE BEING SCAMMED. THEY WOULD NEED TO PUSH A MALICIOUS UPDATE ON BOTH THE SERVERS AND THEIR APP FOR MESSAGES TO BREAK MESSAGE CONTENT.

RUNNING A GLOBAL CONSPIRACY OF COMPROMISING A COMPANY, APP AND SERVERS TO GET AN IRRELEVANT NEWS REPORTER = MONTHS IF NOT YEARS OF WASTED TIME, STUPID, EASY TO GET CAUGHT

PRESSING THE ZERO-CLICK STEALTHY EXPLOIT WITH SPY PAYLOAD BUTTON = IMMEDIATE RESULTS, THE SMART WAY, HARDER TO CATCH

HE LIKELY HAS NO CYBER SECURITY EXPERIENCE AT ALL. HE IS A NEWS REPORTER. ALSO WE CANT REALLY BE SURE IF WHAT HE IS SAYING IS EVEN TRUE BUT THATS OKAY.

IN END TO END ENCRYPTION THE SECURITY OF THE ENDS STILL MATTER. ITS ALL GONE TO WASTE IF ANY OF THE CHATTERS ARE FUCKED.