Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The consensus is that cryptography works. Even the NSA can't get past a properly encrypted message with PGP (assuming you use PGP correctly, and I've heard its UX is horrible). So, one layer of encryption is enough. No need to make your life more complicated.

The biggest fear is not that the crypto itself breaks, but that implementations don't actually implement the crypto correctly. At this point it's mostly a matter of being reasonably sure the software is bug free. Exacting, but not impossible, especially if it's kept simple.



"Modern E2E encryption is like sending and receiving messages with a top security truck, but then on arrival, storing them in a tent."

The biggest problem is security weaknesses at the end-point. Your selfie is travelling securely over the wire, and then it reaches the end-point device where there are typically 100's of unfixed vulnerabilities:

https://www.androidauthority.com/snapdragon-dsp-android-secu... [ DSPs in Qualcomm Snapdragon chips reportedly contain over 400 vulnerabilities ]




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: