I assume this means that the "encryption" is about as strong as base64.
I assume this means that the "encryption" is about as strong as base64.
I mean its just for notification to my app so its not something critical
When your server facilitates a communication between two clients and just acts as the infrastructure E2EE can become relevant. If the clients want to be able to exchange information withouth the server being able to snoop in on what is being sent, then you'd want to use E2EE. With that the server won't be able to read what is being sent.
- then notification service is probably something I want to E2EE then, but Idk about performance hit cost would be
If so, then you really don't need any extra encryption.
If not, then it depends on who's using your chat, how they use it, and for what purpose. Are the users of the chat room a small group with occasional users joining or leaving, or are many users expected to join and leave at any given moment?
That being said, encrypting the notifications won't bring any real benefits. A bad actor would simply focus on trying to compromise your server.
If you do decide that full e2ee would benefit your users, then look for someone who can help you implement it.
Implementing real e2ee for a 2 party chat is hard for someone without experience.
Implementing e2ee for a group chat is hard even for someone with experience.
(Though I still think that "how can I protect against TLS being broken?" is the wrong question and you should instead ask "how can I ensure that TLS doesn't break?".)
If your threat model is such that you'd rather not have the server know what's sent to and from the client, it's not enough to just encrypt the data in flight, which is what HTTPS does. With encrypted chat, we typically want what we refer to as end-to-end encryption, where the server can't see the content of messages sent between users.
I want to prevent vector attack such MiTM if TLS is somehow hacked
There are things you can do to make it more difficult to hack your TLS connection though, for example you could use key pinning to make sure that your app will only accept a server with the certificate you expect. This would protect against an IT admin installing root certs on their users' devices, or against certificate authorities issuing fake certificates for your domain.
but for things like IoT running websocket connection for long time maybe I need that
I do wish that the Paypal statement would be a bit more nuanced though. Yes, Musk made a lot of money on the dot-com hype by way of Paypal. And he seems to have built strong friendships from that, weirdly with the same people that fired him. But his involvement in Paypal was that he let it buy the startup he was in and demanded to be CEO. He then only showed interest in throwing out the FreeBSD it was built on and replace it with NT (which was the hottest fad at the time) and to rename the company to "X". Neither happened, and he was quickly let go before the company risked bankruptcy. It's rather far fetched to go from that to "changing the Internet". Paypal won and X didn't.
Elon sells a 2-3 phase project, and then delivers phase 1. Thats the entire man.
Tesla: Was meant to revolutionise car making and green the planet. He delivered a pretty ok set of electric cars and got completely outflanked by traditional car makers. He also used it to rescue his brothers failing business.
Starlink: Its billed as an uninterruptible censorship ignoring super internet in space where government cant get it. But what he delivered is just landline fiber extended by 1 - 2 satellite hops. Its great for rural areas but the business complies with all legal censorship requirements where it operates. My back of the napkin math tells me its ultimate goals are completely unachievable, and MEO internet providers IMHO are catching up.
SpaceX: SpaceX is really good, they have brought in everyone from JPL and other places and absolutely nailed low cost orbital payload. In fact I read speculation they will take boeings contracts for Artemis prep. However what he sold is the relocation of humanity to mars which is no closer to being achieved, and as far as I can tell, he has literally no one but concept artists working on.
Hyperloop etc: Basically kickstarted the boring company which IIRC is one of his better long term prospects. He wont be creating super fast mass transit systems but he can shave months off of boring projects.
Xitter: Billed as an uncensored town square, the place has just engaged in the other teams censorship and is generally a cess pit.
Neuralink: Apparently almost as good as stuff displayed on Beyond 2000 25+ years ago.
tl;dr guy is a salesman. The fact that he can sell you a dream and then pretend like he delivered it without delivering it is a testament to his business strengths. But dont drink the koolaid.
Yeah he made the electric car popular, but it can be argued that in order to make his company economically viable he basically lied to his investors and customers about self driving cars for almost a decade, when he had nothing real in his hands. Thanks to those promises he got the money to keep the company afloat until it had the manufacturing capability to actually deliver the cars they sold; and someone may argue he would have failed if he had been honest from the beginning, and that maybe people wouldn't have invested the money they did if he hadn't set unachievable goals to begin with
And this is a pattern you can see in all of his companies; he promises the world Mars, gets a lot of funding and then instead of delivering on the "dream" target, he uses the money to deliver a valid but definitely less "romantic" product he can actually sell. One time is ok, but it's basically a modus operandi now. And this gives me a strong suspicion that the product was the real goal all along, and he knew he had to lie about the "dream" in order to get the capital at all