Important progress has been made regarding bringing MLS end-to-end encryption to the ActivityPub protocol, with developers already building implementations and providing feedback to a future version of the protocol spec.

  • Rioting Pacifist@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    2
    ·
    13 hours ago

    That’s not really going to be the case if you’re using a website instead of an audited app like signal/matrix.

      • Rioting Pacifist@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        11 hours ago

        Any we client including Matrix webclient is incredibly vulnerable to the server just injecting JS and reading your messages.

        Like there is no point of E2E encryption in Twitter, Musk can read your messages if you open them on any device he can execute arbitrary code on.

        • Jean-luc Peak-hard@piefed.social
          link
          fedilink
          English
          arrow-up
          4
          ·
          11 hours ago

          Any we client including Matrix webclient is incredibly vulnerable to the server just injecting JS

          That doesn’t preclude fediverse clients from enabling E2EE. A web-client isn’t a requirement.

          Like there is no point of E2E encryption in Twitter, Musk can read your messages if you open them on any device he can execute arbitrary code on.

          Agreed, nobody should trust twitter, but I would trust most mastodon clients to send encrypted messages, if/when implemented correctly. Does it guarantee that messages will never be read? No, but it does an extra layer that wasn’t there before.