Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But why not allow E2E without incognito? Have both as separate options.


What use-case does E2E without incognito address?

* Sharing naked pics on a monitored work network? No - there is at least some chance that your company owns your device, so therefore you want it to disappear from that

* Sharing politically outlawed content? No - you can be compelled to give up your device.

Wanting it "just because" is fine, but simplifying the UI is a pretty valid counter argument too.


Protecting against dragnet surveillance. Which is what the encrypted-by-default in Whatsapp achieved over night.


Combined with full disk encryption it ensures nobody can get it.

Or maybe you want to use an open WiFi hotspot without letting anyone get your data. (Https solves this, though.)

Or maybe you don't want Google to have your messages for targeting purposes.


Full disk encryption and end-to-end are not really ensuring no one can get it. I feel like I beat this point into the ground in these discussions, but all encryption is weak against rubber hose cryptography. If someone can compel you to give up your device and key, then all end-to-end does for you is make it less likely you will be caught by someone monitoring traffic.

Which brings us to point two: if that's your primary concern, then using Google may not be your best bet. If you are using Google messaging apps, it's likely because you value the additional convenience Google provides and privacy is a secondary concern.


Probably because proliferation of options is bad for UX for most user types and bad for uptake, and "incognito" is what they've named the package of privacy-related options, including E2E.


It seems to me that it's simpler to understand. If you really want to keep something a secret, it's probably not a good idea to keep a copy on your (or their) phone.

Providing separate options would make it easier to make mistakes.


Pretty much no other E2E app feels the same way, and certainly doesn't enforce that.


You have this in qTox and uTox




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: