• Helix 🧬@feddit.deB
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    I guess very few people self-host their email or Matrix or XMPP.

    You don’t need to self host email, Matrix or XMPP to use E2EE. I meant self hosting the web clients.

    And it still doesn’t protect you against someone breaking the TLS connection between you and your server.

    HSTS, Certificate Pinning, …

    Every communication method suffers from this, it’s not exclusive to web-based communication.

    proprietary, windows only apps are not generally designed with security as the number 1 concern

    Yeah, Open Source software down to the OS itself is important for security. But even then, who audits their own software? It’s probably 0.01% of the 0.01% of the general population you mentioned.

    • Dreeg Ocedam@lemmy.ml
      link
      fedilink
      arrow-up
      3
      ·
      3 years ago

      You don’t need to self host email, Matrix or XMPP to use E2EE. I meant self hosting the web clients.

      Nobody does that

      HSTS, Certificate Pinning, …

      HSTS is great but doesn’t protect you against maliciously issued certificates, and Certificate pinning is deprecated on the Web.

      Yeah, Open Source software down to the OS itself is important for security. But even then, who audits their own software? It’s probably 0.01% of the 0.01% of the general population you mentioned.

      That’s why you stick to software under high scrutiny and highly visible for security sensible stuff, and avoid using software with a broken security model for sensible stuff.