Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
For an app claiming end-to-end encryption, what evidence would earn your trust?
3 points by Brandon-Coll 53 days ago | hide | past | favorite | 6 comments


The only truly-trustable option is basically F-Droid's reproducible builds (or similar) with source code availability:

https://f-droid.org/docs/Reproducible_Builds/

Eg this app: https://verification.f-droid.org/packages/com.inspiredandroi...

and its source code: https://github.com/SimonSchubert/Kai/tree/main

You can verify yourself what it is doing, and what was built is guaranteed not to be tampered with.

AFAIK there isn't any evidence that isn't variations of "trust me bro" for the Play Store and App Store.


so if an app is not open-source, it's credibility as secure, private or encrypted becomes questionable? and if an app has code open, that's mean it is absolutely trustworthy? what is your take on this?


The reproducible build process is also a critical component, not just source code access, because what you download from the marketplace could be different to the source. All boils down to trust "but verify", these are the ingredients that let you verify the claims.


well put. I'd add third-party audits to thelist. independent security audits together create a much stronger trust model but regular and different for respective analysis


"decrypt" button


and maybe some sort of physical way to share keys via qr or something with clear transparent state visualization. the more you abstract away the cryptography math the less safe it feels with more vectors of attack so it has to be also educational like "this is how proper cryptography works and here is proof we are doing everything by the books" but in friendly ux manner thats easy for children to grasp intuitively




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: