

I’m saying those others that pretend to implement pfs, still leak all chats the user didn’t delete (and in some cases even then) when an attacker has access to the private key because that’s stored in the same database.


I’m saying those others that pretend to implement pfs, still leak all chats the user didn’t delete (and in some cases even then) when an attacker has access to the private key because that’s stored in the same database.


Yes and I’m saying that since the only way to get access to that private key on delta chat is to get access to an unlocked device at which point you have access to all the messages on that device anyway (on signal too)


I think anonymous messenger generally means talking to other people anonymously. If I want to talk to my friend from school that is private messaging, but that shouldn’t require me to identify myself to some foreign company.


Delta chat assumes the relays are evil and of course doesn’t send private keys there


Just don’t allow easily guessable identifiers


Forward secrecy protects against intercepting now and decrypting later when you get access to the users private key: this is only possible on delta chat if you get access to the client database at which point you can read all undeleted messages anyway. (On Signal even deleted messages!)


Yes that’s the point of requiring payment or a phone number


Holy shit the astroturfing in this comment section is crazy. If a 9 year old went into any other store and used a company card the store would reasonably refuse to sell 100k worth of goods. If the payment system Google implemented doesn’t even verify who is paying then that’s negligence on their part.
Okay and how would you get that private key?
By having access to an unlocked device: which means you also have access to all messages. Therefor this attack vector is not as big a deal as you are making it.