Giter Club home page Giter Club logo

Comments (8)

koto avatar koto commented on May 20, 2024

From [email protected] on June 03, 2014 19:10:44

Hi!

I'm making this bug non-private, I hope you don't mind.

At the moment we are an open source project so this doesn't apply right now.

I don't have further comment for now, but we hear you :)

Labels: -Restrict-View-Commit

from end-to-end.

koto avatar koto commented on May 20, 2024

From [email protected] on June 03, 2014 19:27:59

Status: Done

from end-to-end.

koto avatar koto commented on May 20, 2024

From [email protected] on June 04, 2014 09:16:00

I don't understand why you closed this issue.

Being compelled by the government to issue hostile updates is the easiest and most likely attack vector against e2e. It's well documented that Google both complies government demands at the expense of user privacy, and that the government interferes with Google services without Google's knowledge.

National-Security-Letter cryptanalysis is just as valid as mathematical cryptanalysis. End-to-End, operating within Chrome, is supremely vulnerable to this "attack". Simply ignoring it and pretending it is rather disingenuous, considering the public media statements supporting user privacy.

from end-to-end.

koto avatar koto commented on May 20, 2024

From [email protected] on June 04, 2014 16:06:51

We didn't say that this won't apply to the Chrome extension, which, however, isn't what we released yesterday.

Rest assure that we're aware of this problem, but please focus on the source code now.

from end-to-end.

koto avatar koto commented on May 20, 2024

From [email protected] on June 05, 2014 12:36:52

Yes, we treat this concern very seriously.

I closed it because we aren't auto-updating any extensions (there's no CRX we are shipping that could be auto-updated).

from end-to-end.

koto avatar koto commented on May 20, 2024

From [email protected] on June 05, 2014 23:47:15

If you treat this concern very seriously then IMO you should shut down this project as there is no way you can defend against the attack described while developing this code under US jurisdiction.

Basically you are just building a honeypot.

from end-to-end.

koto avatar koto commented on May 20, 2024

From [email protected] on June 16, 2014 03:50:49

To avoid us loosing track of responses to closed bugs, restrict adding comments to closed issues.

Please file a new bug if needed.

Labels: Restrict-AddIssueComment-CoreTeam

from end-to-end.

koto avatar koto commented on May 20, 2024

From [email protected] on July 21, 2014 16:42:58

Labels: Type-Defect Priority-Low Component-Scripts Security

from end-to-end.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.