This seems like a extreme argument.
If the app is not phoning home with the cleartext, this seems okay. You need some software to retrieve/read text anyway, so this becomes an exercise about trusting trust, etc.
If the app is not phoning home with the cleartext, this seems okay. You need some software to retrieve/read text anyway, so this becomes an exercise about trusting trust, etc.
It's still better than nothing, although in the hands of Facebook it might actually be worse than nothing.
Not at all. Good security often involves some black-and-white thinking, which not everyone is accustomed to.
If Facebook controls the endpoint, then they have the power to access the plaintext, full stop. Using their product (hopefully) implies a choice to trust them not to abuse such access.
Which is what...they said?
Would you argue against all encryption because clearly the CPU maker has a similar access to all decrypted content?