To the extent open source matters at all when looking at E2E encryption, it theoretically makes it easier to see whether the source code implements a secure protocol. This sounds much more useful than it actually is. For one thing, almost nobody is compiling the source code themselves, so you're ultimately going to have to evaluate the security of compiled code anyways. Also there is an incredibly vast gap between the promise and reality of the open source promise in terms of finding security problems. Accidental or deliberate weaknesses can be subtle and hard to find whether or not you have the code. The extensive history of serious cryptographic problems living in open source code for years before they were found and people regularly being able to find problems in software despite it being closed source suggests open source as a security panacea should be taken with a large grain of salt.
They are not equal to effect and motivations of either user or finder.
I would like to understand if you consider signal (for example, as a very large community of use e2ee with open source) has substantive problems due to people "not looking hard enough"
E2EE without verifiable builds is as good as a cheeto lock. Even with all the E2EE claims, Facebook could still do anything with the data and you could never hold them accountable because the binary code is obfuscated in the first place so all you would really have is half-reverse engineered stuff that also breaks WhatsApp's terms of use policy.
Please stop defending FB, everytime someone does it, they prove all of you wrong again.
Even a closed source client soon has opensource 'compatible' clients. To build those, you need to reverse engineer/understand the crypto. In the process of doing that, you will likely uncover any systemic flaw that reveals every conversation to a passive attacker.
That effectively leaves the 'send a secret message to leak the key' type backdoors that the client could have. However, if this functionality existed and was used on every chat, then it is quickly discovered by anyone debugging the unofficial client.
So the only remaining 'loophole' is that there is a backdoor in the official client, but that it is only used very rarely or on request.
That in turn means that facebook can't go do large scale data mining on the private chats. Thats a win.
FB messenger doesn't yet have e2e encryption, so there hasn't yet been any need.
[0] https://github.com/tgalal/yowsup/issues?q=is%3Aissue+is%3Aop...
You don't even have that option with closed source software.
That the FBI can is a concern to absolutists, but I don't think the masses.
This is basically true for any sizable company in the US. And this is also true with small companies. If the FBI wants to work with you, you don't really have a choice.
And if you're not in the US, you're working with whoever is the FBI in that country.
Many? It feels like it's been 10 years since I've seen one, and it's only a US thing. I'm wondering if Signal still has one (I can't find it, so maybe the canary is "dead"). Canaries are also a legal grey area.
> My point was that Facebook will decrypt(in the case that are really encrypted) your messages
That's FUD.
Open source client doesn't matter in mobile world, as you never compile the app yourself. This is only misleading to the non-tech users who don't get how the whole thing works. That's why Telegram's claim of security is total garbage because while their client is "open source", the backend is that has all the messages is not. Something they don't clearly state on their website.
So the Telegram's admins can read all the messages in plain text on the backend. So "open source" client means absolutely nothing for the security.
I'd still rather use Signal though.
Okay, so we're ignoring verifiable builds exist?
> Open source client doesn't matter in mobile world, as you never compile the app yourself.
That's a really weird take. Nobody ever checks files for corruption or modification but hashes still exist. Just because most people do not check something does not mean it's non-existent or pointless.
> So the Telegram's admins can read all the messages in plain text on the backend.
They can't. The messages are encrypted on the servers and their keys are split between multiple jurisdictions. No engineer can decrypt messages.
You really don't get why E2E encryption is necessary, do you?
E2EE has obvious flaws, mostly related to feature-set. Cloud sync is difficult with E2EE, as well as managing chats with thousands of members. Telegram is more of a social media with a great convenient messenger. It doesn't make sense for it to be like WhatsApp or Signal. Those who use Telegram know the difference very well.