This service claims User-generated content is encrypted, and this service cannot decrypt it
Current title
User-generated content is encrypted, and this service cannot decrypt it
As we don’t verify the source code (which in some cases is also impossible). Neither do we verify the strength of their encryption.
x.com for example has been criticized for only securing E2EE messages with a six digit pin, which would be trivial to brute force for a malicious server. [1]
Additionally we should think about how we handle services that only encrypt some user generated content like X or Telegram.
Fully agree. Also, we ought to edit the description.
My proposal
According to the service, user-generated content is supposed to be end-to-end encrypted. This would mean that it can’t be accessed or decrypted by unauthorized parties, including the service.
Old description
Content generated by the users is end-to-end encrypted, in a way that it can’t be accessed by anyone unauthorised, and even the service has no technical means to decrypt it.
The service claims that user-generated content is end-to-end encrypted, meaning only intended recipients can access or decrypt it. As a result, no unauthorized parties, including the service itself, can view the content.
This does not necessarily cover meta data, such as the date of creation or sender and recipient information.