TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

An Update to End-To-End

142 pointsby aarkayover 10 years ago

7 comments

mrsteveman1over 10 years ago
Given that they&#x27;ve already decided to include support in Chrome itself for accessing USB hardware security tokens for U2F, I see no reason why they couldn&#x27;t do the same with End to End + OpenPGPCards like the Yubikey NEO, which happens to also be a U2F device.<p>It would provide a solution to some of the issues they document on their own Wiki regarding secret keys being stolen by an attacker through another Chrome extension, another application on the system, etc.<p>EDIT: YES! I missed this part[1] in the Wiki earlier:<p>&quot;Additionally, we plan to add remote private key support in the future. When support for that is ready, high-risk users could protect their secret keys (stored, e.g., in a hardware USB device) from compromise even when an adversary introduces a backdoor in the source code.&quot;<p>[1] <a href="https://github.com/google/end-to-end/wiki/Threat-model#backdoor-in-end-to-end-source-code" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;end-to-end&#x2F;wiki&#x2F;Threat-model#backd...</a>
jMylesover 10 years ago
I mean, this seems just straight amazing, right? Am I missing something?<p>Obviously Google is pivoting on a number of fronts; if this enjoys wide adoption (unlikely as that may seem at the moment), they&#x27;ll have to basically retreat from email content analytics, right?
评论 #8759683 未加载
评论 #8760353 未加载
评论 #8764714 未加载
评论 #8769835 未加载
评论 #8761244 未加载
jmnicolasover 10 years ago
&gt; <i>We’re migrating End-To-End to GitHub</i><p>A bit off-topic but it seems to me that Github is fast becoming a &quot;too big to fail&quot; actor.
评论 #8762211 未加载
driverdanover 10 years ago
Can anyone who has been using End to End provide some feedback and additional info about it? The docs (and blog posts) don&#x27;t really say much other than it encrypts text.
Fastidiousover 10 years ago
How could a regular user start using this (unless it is not ready at all for the &quot;fearless ones&quot;)?
sftover 10 years ago
I wish they would stop calling it End-to-End, it&#x27;s misleading, they don&#x27;t talk about DNS at all. One weak link in the chain means the entire chain is weak.
评论 #8760375 未加载
higherpurposeover 10 years ago
I hope they don&#x27;t work too hard to making it compatible with PGP (and probably shouldn&#x27;t at all). Just through Gmail and Yahoo alone adopting it, the end-to-end encrypted e-mail user base could increase by 100x. So it makes little sense to make it backwards compatible, especially if that creates potential security issues.
评论 #8759992 未加载