It's more risky in terms of getting caught, but probably not hugely so if you do it in a way that has plausible deniability.
I think you pretty much have to trust the app supplier. Which in this case, I do not.
It's more risky in terms of getting caught, but probably not hugely so if you do it in a way that has plausible deniability.
I think you pretty much have to trust the app supplier. Which in this case, I do not.
This is a much much much better situation than handing someone your keys and letting them MITM you at any time with no hope of knowing.
I agree it's definitely better to do proper e2e encryption like WhatsApp / Signal do, but I don't think we should pretend they are magically fully secure against this attack.
If. Just recently there was a news about how meta bruteforcing localhost of all its users to hack their devices (https://localmess.github.io/). And now someone seriously suggests to believe that meta does not collect private keys on its servers?
Moreover, I think that now corporations don't even have an option not to steal keys from users: you either have their keys or go to jail. And if you have the keys, but users think you don't and trust all their secrets - that's even better.
And if you think government authorities can't do something, look what happened to Alexey Pertsev. A criminal uses your tool to ensure their privacy? You're going to jail. So in today's world, it's better to have keys on your server, even if you're not going to use them. Because at some point, you might be asked for them and refusing (ore not having one) will mean jail time.
Yeah unfortunately that list no longer includes countries like the UK and Australia.