Conversation

nicole mikołajczyk 🔜 cebulacamp

do you think fedi projects should widely adopt the MLS over ActivityPub specification or does not every app need encrypted messaging?

2
0
1

@mkljczk i think that the more secure while staying usable it is, the better
so go for it

0
0
1
@mkljczk the problem with it is that many people use web clients, and web clients cannot securely implement E2EE (unless everyone self-hosts) because whoever is hosting the web client could simply serve a malicious version. non-self-hosted web-based E2EE cannot actually be secure (but it does potentially serve as a legal protection in case you could be forced to hand over messages but could not be forced to serve malware)
1
0
1

@noisytoot i would never host a malicious client neocat_floof_angel

1
0
2

@mkljczk even if you wouldn’t, perhaps your hosting provider could be convinced to allow an attacker to mitm connections and host a malicious client (something like that happened to jabber.ru)

0
0
2