Hacker News new | past | comments | ask | show | jobs | submit login

Isn't the whole point of e2e that you don't need to worry about what runs on the server, unless you're worried about metadata leakage.

Correct, but if there is something between you and other user and can intercept key exchange then it can decrypt and encrypt anything on the fly. I think you would have to exchange keys offline to have true e2e experience.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
