FHE would be nice, but there's a lot of products that could be E2EE today. Plenty of breaches are just server-side files and dumps, there's no excuse for not using E2EE cloud storage.
Databases are much more tricky, but if we're talking a significant shift, it is as good a plan as any. Clearly server trust is not working.
AI is accelerating both sides for defenders and attackers, but mobile clients are already way ahead of typical desktop. Android's desktop mode exists in the OS now but needs a lot of work and more powerful chips before it can replace desktops.
For security against remote attacks, I'd rank clients roughly: GrapheneOS, iOS/iPadOS, stock Android on Pixels, ChromeOS, macOS, Windows, desktop Linux. Prefer more secure clients, always, but now the client is all that's left to trust for content.
Native clients avoid the web E2EE problem and are easier than ever to build. With AI, you can audit the source as often as you want and reproducible builds mean you know that's what you're running.
I really like the UI especially the about page. I don't think you are supposed to be able to see the about page on the playing page (it took a bit to start and then started when I was in about) but it looks good there with the blur.
It's crazy SimpleX is fine being based there. I mean, everything is open, the clients have reproducible builds, but it seems like it may end up being a hassle.
Has the UK started attacking any open source E2EE projects yet?
Apple's control over iOS is the main reason I prefer GrapheneOS so much over it. You get amazing privacy and security without sacrificing control. GrapheneOS has said they won't introduce age verification and a backdoor they obviously won't implement.
I'm guessing they could, in theory, attack open source projects, but it would not be very effective as those could be infinitely forked. That's the reason why governments will actually support an encourage an oligopoly of proprietary platforms via regulations (e.g. mandatory automated scanning) which only companies can practically comply with.
There's no way to obtain root access on GrapheneOS without making your own builds (which won't be affected by many of the apps adding support for GrapheneOS, who likely would only whitelist the official signing keys) or keeping the bootloader unlocked in perpetuity (because AFAIK there is currently no way to recalculate verified boot hashes on top of a systemless root like Magisk -- not that I even know if that works on GOS in the first place). Some years back I was actually working on calculating AVB2 hashes from a live system rather than ONLY through the Android build process, until TWRP wiped my phone without consent or confirmation due to an OpenRecoveryScript that I absolutely did not put there and I basically stopped tinkering with Android root due to that. I have an iPhone nowadays.
I think it means their extortion victims. So we actually know who some of their "clients" are. Like instructure/canvas. We certainly know the ones who "don't become clients" because they are all posted.
They mention hindering trust because for an extortion gang, they want companies to trust that they won't leak the data in order to make it seem worthwhile to pay.
You can also factory reset, check boot key hash, and use Auditor to verify integrity on devices sold with GrapheneOS preinstalled. That's what they currently recommend to do for Pixels sold with GrapheneOS preinstalled.
Databases are much more tricky, but if we're talking a significant shift, it is as good a plan as any. Clearly server trust is not working.
AI is accelerating both sides for defenders and attackers, but mobile clients are already way ahead of typical desktop. Android's desktop mode exists in the OS now but needs a lot of work and more powerful chips before it can replace desktops.
For security against remote attacks, I'd rank clients roughly: GrapheneOS, iOS/iPadOS, stock Android on Pixels, ChromeOS, macOS, Windows, desktop Linux. Prefer more secure clients, always, but now the client is all that's left to trust for content.
Native clients avoid the web E2EE problem and are easier than ever to build. With AI, you can audit the source as often as you want and reproducible builds mean you know that's what you're running.
reply