• speckofrust@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 days ago

    From the article…

    I want to make one technical point absolutely clear because several people have misunderstood my argument:

    The encryption still works. OpenAl hasn’t cracked or mathematically broken iMessage encryption. An iMessage remains encrypted between endpoints. The privacy problem occurs at the endpoint.

    Once the message has been decrypted on the recipient’s Mac, that recipient can authorise third party software to access the readable conversation. The encryption worked exactly as designed. It simply can’t protect message content from software authorised to access it before or after decryption.

    That’s what I mean when I say this integration undermines the purpose of end to end encryption.

    • Encrypt-Keeper@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      But it doesn’t undermine the purpose of end to end encryption? End to end encryption means it’s encrypted on one end and is decrypted on the other end, as opposed to being decrypted somewhere in the middle.

      This problem doesn’t for anything to undermine end to end encryption at all? With E2EE you still have to trust the other end. If the person who is the other end installs a plugin that reads the texts you send them, that’s not really a technology problem it’s an OpSec problem.

      • speckofrust@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        I agree. It definitely does undermine the purpose of E2EE. I just wanted to let it be known that ChatGPT hasn’t actually broken the encryption algo.

        Still, fuck Open AI, and any friend who would ever use AI to scan our Signal chats (if such a plugin is ever created) will be immediately cut off from chat comms.

        • Encrypt-Keeper@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          It definitely does undermine the purpose of E2EE

          It doesn’t undermine it at all is what I’m saying. The problem is just entirely unrelated to E2EE