korrents

What Matthew Green thinks about privacy

@matthew-green · 11 positions · 0 changes of mind

Cryptographer and professor at Johns Hopkins University, where he works on applied cryptography and user privacy. He writes A Few Thoughts on Cryptographic Engineering, which is where most public arguments about messaging encryption, client-side scanning and cloud backup end up being adjudicated.

Matthew Green did not write this page.

We collected these quotes from things they published elsewhere, and every quote links to where it was said. They have no account here and have not endorsed this site. Quotes are word for word; the short line under each one is our own restatement, not their wording. Their own site. Is this you? Claim it or ask us to remove it. Or tell us what is wrong here.

7 dated positions, 2021 to 2024, in their own words. Our reading of what Matthew Green has said — not written or endorsed by them.

  1. Telegram clearly fails to meet this stronger definition for a simple reason: it does not end-to-end encrypt conversations by default.

    Is Telegram really an encrypted messaging app?blog.cryptographyengineering.com 1st of 4 in this piece

    Telegram

  2. Indeed, it no longer feels amusing to see the Telegram organization urge people away from default-encrypted messengers, while refusing to implement essential features that would widely encrypt their own users’ messages.

    Is Telegram really an encrypted messaging app?blog.cryptographyengineering.com 3rd of 4 in this piece

    Telegram

  3. To be honest though, it doesn’t matter how secure something is if people aren’t actually using it.

    Is Telegram really an encrypted messaging app?blog.cryptographyengineering.com 4th of 4 in this piece

  4. 21 months earlier
  5. It terrifies me, because these data repositories are not only a risk to individual user privacy, they’re effectively a surveillance super-weapon.

    Why encrypted backup is so importantblog.cryptographyengineering.com 2nd of 2 in this piece

    data centers

  6. 16 months earlier
  7. In short: traceability can really screw with the “who sent what” side of content confidentiality.

    Thinking about “traceability”blog.cryptographyengineering.com 1st of 3 in this piece

  8. Information revealed about “who sent what” in an E2E system is not the same as metadata.

    Thinking about “traceability”blog.cryptographyengineering.com 2nd of 3 in this piece

  9. 12 days earlier
  10. Rather: NSO’s genius is that they’ve done something that attackers were never incentivized to do in this past: democratize access to exploit technology.

    A case against security nihilismblog.cryptographyengineering.com 2nd of 2 in this piece

    government