korrents

Matthew Green

@matthew-green · 11 positions · 0 changes of mind

Cryptographer and professor at Johns Hopkins University, where he works on applied cryptography and user privacy. He writes A Few Thoughts on Cryptographic Engineering, which is where most public arguments about messaging encryption, client-side scanning and cloud backup end up being adjudicated.

Matthew Green did not write this page.

We collected these quotes from things they published elsewhere, and every quote links to where it was said. They have no account here and have not endorsed this site. Quotes are word for word; the short line under each one is our own restatement, not their wording. Their own site. Is this you? Claim it or ask us to remove it. Or tell us what is wrong here.

  1. Telegram clearly fails to meet this stronger definition for a simple reason: it does not end-to-end encrypt conversations by default.

    Is Telegram really an encrypted messaging app?blog.cryptographyengineering.com 1st of 4 in this piece

    Telegram

  2. The practical impact is that the vast majority of one-on-one Telegram conversations — and literally every single group chat — are probably visible on Telegram’s servers, which can see and record the content of all messages sent between users.

    Is Telegram really an encrypted messaging app?blog.cryptographyengineering.com 2nd of 4 in this piece

    Telegram

  3. Indeed, it no longer feels amusing to see the Telegram organization urge people away from default-encrypted messengers, while refusing to implement essential features that would widely encrypt their own users’ messages.

    Is Telegram really an encrypted messaging app?blog.cryptographyengineering.com 3rd of 4 in this piece

    Telegram

  4. To be honest though, it doesn’t matter how secure something is if people aren’t actually using it.

    Is Telegram really an encrypted messaging app?blog.cryptographyengineering.com 4th of 4 in this piece

  5. 21 months earlier
  6. A handful of Silicon Valley executives made the choice for us, in pursuit of adoption metrics and a “magical” user experience.

    Why encrypted backup is so importantblog.cryptographyengineering.com 1st of 2 in this piece

    design

  7. It terrifies me, because these data repositories are not only a risk to individual user privacy, they’re effectively a surveillance super-weapon.

    Why encrypted backup is so importantblog.cryptographyengineering.com 2nd of 2 in this piece

    data centersprivacy

  8. 16 months earlier
  9. In short: traceability can really screw with the “who sent what” side of content confidentiality.

    Thinking about “traceability”blog.cryptographyengineering.com 1st of 3 in this piece

  10. Information revealed about “who sent what” in an E2E system is not the same as metadata.

    Thinking about “traceability”blog.cryptographyengineering.com 2nd of 3 in this piece

  11. This brings us to the central challenge of all content tracing proposals so far: to make tracing possible, a tracing system needs to turn every WhatsApp user (including the originator) into a cooperative green circle — regardless of whether users actually want to cooperate with police.

    Thinking about “traceability”blog.cryptographyengineering.com 3rd of 3 in this piece

  12. 12 days earlier
  13. The problem that companies like Apple need to solve is not preventing exploits forever, but a much simpler one: they need to screw up the economics of NSO-style mass exploitation.

    A case against security nihilismblog.cryptographyengineering.com 1st of 2 in this piece

    Apple

  14. Rather: NSO’s genius is that they’ve done something that attackers were never incentivized to do in this past: democratize access to exploit technology.

    A case against security nihilismblog.cryptographyengineering.com 2nd of 2 in this piece

    governmentprivacy