Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.mobile.android > #155821 > unrolled thread
| Started by | Kim JongUn <USAandNK@WorkersParty.org> |
|---|---|
| First post | 2026-09-09 20:41 +0200 |
| Last post | 2026-09-12 14:08 +0200 |
| Articles | 13 on this page of 33 — 7 participants |
Back to article view | Back to comp.mobile.android
Zero-Knowledge Encryption vs End-to-End Encryption: What’s the Difference? Kim JongUn <USAandNK@WorkersParty.org> - 2026-09-09 20:41 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What’s the Difference? "Carlos E.R." <robin_listas@es.invalid> - 2026-09-09 21:34 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-09 22:22 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Kim JongUn <USAandNK@WorkersParty.org> - 2026-09-09 22:50 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-10 07:43 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Hermes <noreply@oc2mx.net> - 2026-09-11 17:30 +0000
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-11 20:07 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Hermes <noreply@oc2mx.net> - 2026-09-11 18:29 +0000
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-11 21:55 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Hermes <noreply@oc2mx.net> - 2026-09-11 20:32 +0000
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-12 08:22 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Librarian2025 <librarian2025@cock.li> - 2026-09-16 00:32 -0500
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-16 08:44 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Gab_Virebent <gabriel1@virebent.invalid> - 2026-09-16 09:28 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-16 15:45 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Nuno Silva <nunojsilva@invalid.invalid> - 2026-09-16 18:57 +0100
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-16 21:40 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Nuno Silva <nunojsilva@invalid.invalid> - 2026-09-17 00:46 +0100
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-17 09:38 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Nuno Silva <nunojsilva@invalid.invalid> - 2026-09-17 10:32 +0100
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-17 19:12 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Nuno Silva <nunojsilva@invalid.invalid> - 2026-09-18 11:16 +0100
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-18 15:03 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Librarian2025 <librarian2025@cock.li> - 2026-09-17 01:12 -0500
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-17 09:46 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Librarian2025 <librarian2025@cock.li> - 2026-09-17 13:54 -0500
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-17 22:11 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "Carlos E.R." <robin_listas@es.invalid> - 2026-09-11 20:31 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-11 22:16 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "Carlos E.R." <robin_listas@es.invalid> - 2026-09-11 22:44 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-12 08:42 +0200
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? Nuno Silva <nunojsilva@invalid.invalid> - 2026-09-12 10:46 +0100
Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? "R.Wieser" <address@is.invalid> - 2026-09-12 14:08 +0200
Page 2 of 2 — ← Prev page 1 [2]
| From | "R.Wieser" <address@is.invalid> |
|---|---|
| Date | 2026-09-17 19:12 +0200 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <118h73a$gls1$1@dont-email.me> |
| In reply to | #155969 |
Nuno, >> So, again : why use a symmetric key when you already have generated and >> used an a-symmetric one - just so you could safely get that symmetric key >> to some other party ? > > Because the asymmetric encryption used to exchange the symmetric key is > more expensive than the symmetric encryption, so in a longer exchange > you do asymmetric encryption at the beginning, to establish the key for > the cheaper symmetric encryption that takes place for the rest of the > conversation/exchange. And so you have drifted off from how to use symmetric encryption keys for exchange of multiple messages (ref: hermes suggested MycroCrypt program) to a so-called session-encryption key - normally with a rather short lifespan. But you have a point, I did not think of doing it that way. >>>>> Just think of what could happen when one of both parties "looses" >>>>> their symetric key ? And just assume that they do not realise >>>>> that it has happened. And I'm *still* missing an answer to this question. >> I get the feeling that you have no idea how to defend your stance that >> the usage of symmetric encryption is equal to that of a-symmetric >> encryption. > > That's not my stance. Than what /is/ your stance ? But, in a nutshell : The security of a symmetric key fully depends on how often you replace it. An a-symmetric public key doesn't have that vulnerability. Regards, Rudy Wieser
[toc] | [prev] | [next] | [standalone]
| From | Nuno Silva <nunojsilva@invalid.invalid> |
|---|---|
| Date | 2026-09-18 11:16 +0100 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <118j32m$156ki$3@dont-email.me> |
| In reply to | #155980 |
On 2026-09-17, R.Wieser wrote: > Nuno, > >>> So, again : why use a symmetric key when you already have generated and >>> used an a-symmetric one - just so you could safely get that symmetric key >>> to some other party ? >> >> Because the asymmetric encryption used to exchange the symmetric key is >> more expensive than the symmetric encryption, so in a longer exchange >> you do asymmetric encryption at the beginning, to establish the key for >> the cheaper symmetric encryption that takes place for the rest of the >> conversation/exchange. > > And so you have drifted off from how to use symmetric encryption keys for > exchange of multiple messages (ref: hermes suggested MycroCrypt program) to > a so-called session-encryption key - normally with a rather short lifespan. > > But you have a point, I did not think of doing it that way. I think at one point in the thread the usefulness of symmetric encryption was questioned, hence why I mentioned that. > >>>>>> Just think of what could happen when one of both parties "looses" >>>>>> their symetric key ? And just assume that they do not realise >>>>>> that it has happened. > > And I'm *still* missing an answer to this question. > >>> I get the feeling that you have no idea how to defend your stance that >>> the usage of symmetric encryption is equal to that of a-symmetric >>> encryption. >> >> That's not my stance. > > Than what /is/ your stance ? If I have to have a stance and make it public on anything you choose to point out in the context of threads I'm replying to, that's a game I don't want to play. > But, in a nutshell : > > The security of a symmetric key fully depends on how often you replace it. > > An a-symmetric public key doesn't have that vulnerability. Oh, but it does have similar weaknesses depending on size and the advance of computing machinery, and making them age-limited is a thing that *is* done too. > > Regards, > Rudy Wieser > > -- Nuno Silva
[toc] | [prev] | [next] | [standalone]
| From | "R.Wieser" <address@is.invalid> |
|---|---|
| Date | 2026-09-18 15:03 +0200 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <118jcrc$1a1fp$1@dont-email.me> |
| In reply to | #156007 |
Nuno, > I think at one point in the thread the usefulness of symmetric > encryption was questioned, hence why I mentioned that. Not by me. I *did* however question its application : [quote=me] > MicroCrypt is a multi-purpose symmetric encryption app for mobile and > desktop. Symmetric ? That to me means its disqualified. [/quote] >>>> I get the feeling that you have no idea how to defend your stance >>>> that the usage of symmetric encryption is equal to that of >>>> a-symmetric encryption. >>> >>> That's not my stance. >> >> Than what /is/ your stance ? > > If I have to have a stance and make it public on anything you choose > to point out in the context of threads I'm replying to, that's a game > I don't want to play. *You* say that thats not your stance , but when I than ask what that stance is you don't want to tell ? Thats odd ... >> But, in a nutshell : >> >> The security of a symmetric key fully depends on how often you replace >> it. >> >> An a-symmetric public key doesn't have that vulnerability. > > Oh, but it does have similar weaknesses depending on size and the > advance of computing machinery, and making them age-limited is a > thing that *is* done too. Weaknesses that are equal or surpass that of a symmetric encryption ? And Nuno, I've been *trying* to compare the security of the usage of the encryption *keys*. Can you stay on that subject ? And to re-re-re-repeat myself : [quote] Just think of what could happen when one of both parties "looses" their symmetric key ? And just assume that they do not realise that it has happened. [/quote] I'm *still* missing an answer to this question. :-( Or, bluntly said: I'm getting the feeling you want to ignore the, to me, obvious. You may do that ofcourse, but you're getting tiresome. You want to put your POV (stance?) forward and have me respond to it ? Than I expect the same from you. Regards, Rudy Wieser
[toc] | [prev] | [next] | [standalone]
| From | Librarian2025 <librarian2025@cock.li> |
|---|---|
| Date | 2026-09-17 01:12 -0500 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <m2h5joxv7p.fsf@cock.li> |
| In reply to | #155952 |
"R.Wieser" <address@is.invalid> writes: > Gab, > >>> Why though? There is no magical vulnerability in symmetric >>> encryption. > > You're correct, there is nothing magical about it. > >>> Asymmetric encryption solves key distribution problem, >>> nothing else. > > Just think of what could happen when one of both parties "looses" their > symetric key ? I'm pretty sure they then would exchange keys again. Same as they've done before and same as they would have to do if one of them lose secret key. The process of exchanging keys would be different, of course, but not necessarily "worse" than in case of asymmetric encryption. > And just assume that they do not realise that it has > happened. We can "just assume" a lot of things. Let's assume that one of them lost their secret key and they lost the email of the other party. So now they can't access their previous correspondence, and they don't know where to write to re-establish communication. Now what? > Regards, > Rudy Wieser
[toc] | [prev] | [next] | [standalone]
| From | "R.Wieser" <address@is.invalid> |
|---|---|
| Date | 2026-09-17 09:46 +0200 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <118g5to$3iq2$2@dont-email.me> |
| In reply to | #155964 |
Librarian2025, >> Just think of what could happen when one of both parties "looses" >> their symetric key ? > > I'm pretty sure they then would exchange keys again. Thats not what I asked. > We can "just assume" a lot of things. Ah yes, the famous whataboutism. Try to answer the question. If you can't than maybe just keep your mouth shut. Regards, Rudy Wieser
[toc] | [prev] | [next] | [standalone]
| From | Librarian2025 <librarian2025@cock.li> |
|---|---|
| Date | 2026-09-17 13:54 -0500 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <m21par3dzo.fsf@cock.li> |
| In reply to | #155968 |
"R.Wieser" <address@is.invalid> writes: > Librarian2025, > >>> Just think of what could happen when one of both parties "looses" >>> their symetric key ? >> >> I'm pretty sure they then would exchange keys again. > > Thats not what I asked. Well, that's what I answered. >> We can "just assume" a lot of things. > > Ah yes, the famous whataboutism. It was not me who started with "just assume..." > Try to answer the question. If you can't than maybe just keep your mouth > shut. I'm not obligated to only give you answers that you like.
[toc] | [prev] | [next] | [standalone]
| From | "R.Wieser" <address@is.invalid> |
|---|---|
| Date | 2026-09-17 22:11 +0200 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <118hhhr$kq7d$1@dont-email.me> |
| In reply to | #155985 |
Librarian2025, >>>> Just think of what could happen when one of both parties >>>> "looses" their symetric key ? >>> >>> I'm pretty sure they then would exchange keys again. >> >> Thats not what I asked. > > Well, that's what I answered. And with it you've shown to me you're dishonest. Goodbye. Regards, Rudy Wieser
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-09-11 20:31 +0200 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <k0udnmxfd4.ln2@Telcontar.valinor> |
| In reply to | #155861 |
On 2026-09-11 20:07, R.Wieser wrote: > Hermes, ... >> or would you prefer to allow end users to manage it themselves? > > How ? > > And mind you, you said "messaging apps", not email where you create the > message in a text-editor, than encypt it, and than add the resulting file as > an attachment. Thats much to cumbersome - especially on a smartphone. > > iow, if you offer the raw text to the messaging app you already have to > trust that the app will not MITM the conversation or also send a duplicate > to the message-apps company (or elsewhere). Can the app, on install, create automatically an encryption key that only exists on the app? Then send the public part to the server, so that any client can download the public key of anyone they want to message. All clients would do the same. The private key, only exists on the client. Just as PGP in email, but automatic. Would that work? -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | "R.Wieser" <address@is.invalid> |
|---|---|
| Date | 2026-09-11 22:16 +0200 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <1181nj7$3755n$1@dont-email.me> |
| In reply to | #155867 |
Carlos, >> iow, if you offer the raw text to the messaging app you already have to >> trust that the app will not MITM the conversation or also send a >> duplicate >> to the message-apps company (or elsewhere). > > Can the app, on install, create automatically an encryption key that only > exists on the app? Than *you already trust the app* not to do either of what I mentioned, and you quoted, in the above. > Then send the public part to the server, so that any client can download > the public key of anyone they want to message. A messaging app could use *a* public key, not necessarily that of the intended receipient. Can you view the public key use by the app for the current E2E message ? If not .... ... and even if you can that doesn't mean that that is the key thats used ... Yes, there is a LOT of trust for the app involved. :-( :-) > All clients would do the same. > > The private key, only exists on the client. > > Just as PGP in email, but automatic. Would that work? Only if you trust the messaging-app not to pull a fast one - again, see what you quoted. Regards, Rudy Wieser
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2026-09-11 22:44 +0200 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <up5enmxihq.ln2@Telcontar.valinor> |
| In reply to | #155877 |
On 2026-09-11 22:16, R.Wieser wrote: > Carlos, > >>> iow, if you offer the raw text to the messaging app you already have to >>> trust that the app will not MITM the conversation or also send a >>> duplicate >>> to the message-apps company (or elsewhere). >> >> Can the app, on install, create automatically an encryption key that only >> exists on the app? > > Than *you already trust the app* not to do either of what I mentioned, and > you quoted, in the above. Use open source. > >> Then send the public part to the server, so that any client can download >> the public key of anyone they want to message. > > A messaging app could use *a* public key, not necessarily that of the > intended receipient. Can you view the public key use by the app for the > current E2E message ? If not .... > > ... and even if you can that doesn't mean that that is the key thats used > ... > > Yes, there is a LOT of trust for the app involved. :-( :-) Again, use open source. > >> All clients would do the same. >> >> The private key, only exists on the client. >> >> Just as PGP in email, but automatic. Would that work? > > Only if you trust the messaging-app not to pull a fast one - again, see what > you quoted. > > Regards, > Rudy Wieser > > -- Cheers, Carlos. ES🇪🇸, EU🇪🇺;
[toc] | [prev] | [next] | [standalone]
| From | "R.Wieser" <address@is.invalid> |
|---|---|
| Date | 2026-09-12 08:42 +0200 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <1182sa2$3ha83$2@dont-email.me> |
| In reply to | #155879 |
Carlos, >> Than *you already trust the app* not to do either of what I mentioned, >> and >> you quoted, in the above. > > Use open source. "open source" is not a magical solve-all incantation. Most people use open source in a pre-compiled form. Its better, but still far from perfect. >> Yes, there is a LOT of trust for the app involved. :-( :-) > > Again, use open source. It doesn't change the "lots of trust for the involved" problem. Unless you grab yourself the sourcecode, read *and understand* the whole thing and than compile it on your own machine you still trust others to have done their work in this regard too ref: the offered "walled gardens", where a number bad apps have been found where the developpers where unaware - caught-out by poisonned libraries. Regards, Rudy Wieser
[toc] | [prev] | [next] | [standalone]
| From | Nuno Silva <nunojsilva@invalid.invalid> |
|---|---|
| Date | 2026-09-12 10:46 +0100 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <118371p$3jqcq$3@dont-email.me> |
| In reply to | #155887 |
On 2026-09-12, R.Wieser wrote: > Carlos, > >>> Than *you already trust the app* not to do either of what I mentioned, >>> and >>> you quoted, in the above. >> >> Use open source. > > "open source" is not a magical solve-all incantation. Most people use open > source in a pre-compiled form. Its better, but still far from perfect. > >>> Yes, there is a LOT of trust for the app involved. :-( :-) >> >> Again, use open source. > > It doesn't change the "lots of trust for the involved" problem. > > Unless you grab yourself the sourcecode, read *and understand* the whole > thing and than compile it on your own machine you still trust others to have > done their work in this regard too > > ref: the offered "walled gardens", where a number bad apps have been found > where the developpers where unaware - caught-out by poisonned > libraries. Source being available still means inspection is possible, whereas with closed source you really don't have much of an option other than blindly trust (although, yes, reverse engineering is possible). Now source being available also works better if you can reproducibly build it, even if you're not building it yourself. I think F-Droid also takes this into account, for example. (And this is also why some licenses say you must make the source available, and if you're releasing code that can't be used to build the same program, you'd be violating the license, even if there is *some* source.) You either trust the application or then you have to trust the OS to provide some sort of unhijackable interface for encrypted messaging, for example, if the system could have a messaging interface application, one or several messaging providers (SMS, E-mail, XMPP, ...) and a separate optional encryption layer. That does not sound easy to establish, but it at least would make it easier to audit and trust the encryption part, while allowing different services, even proprietary ones. It would also have the benefit of a stable, consistent interface between messaging systems (and herein lies a disadvantage, because not all media are equal, compare the SMS message length and text encoding needs with electronic mail, but OTOH we've had messaging apps supporting at least SMS and MMS). Another disadvantage, of course, is the SPOF which could then be attacked, by having e.g. manufacturers installing backdoored messaging systems... (As for the encryption system itself, I'd personally favour asymmetric encryption with OpenPGP.) -- Nuno Silva
[toc] | [prev] | [next] | [standalone]
| From | "R.Wieser" <address@is.invalid> |
|---|---|
| Date | 2026-09-12 14:08 +0200 |
| Subject | Re: Zero-Knowledge Encryption vs End-to-End Encryption: What's the Difference? |
| Message-ID | <1183fcn$3nn2i$1@dont-email.me> |
| In reply to | #155890 |
Nuno, > Source being available still means inspection is possible, > whereas with closed source you really don't have much of an > option other than blindly trust (although, yes, reverse > engineering is possible). So, in both cases inspection is /possible/ (1). It doesn't mean that run-of-the-mill "compile me that, batman" users are capable to do either. And don't forget the libraries that are often imported as binary blobs. (1) Though I've dis-assembled enough programs to be aware that looking thru sourcecode is mostly a *lot* easier. > You either trust the application or then you have to trust the OS to > provide some sort of unhijackable interface for encrypted messaging, Indeed. Do I trust the Android messaging app ? Whats the reason I should ? I cannot inspect what it does, nor what it sends/receives (does it even actually encypt the message?), nor what happens in transit. Thats not trust, that is having blind fate. Also, you *start* with trusting the OS. If you can't trust it than all your apps could be above board, but that would not mean a thing. And whatdoyouknow, I'm not running Googles Android. <whistle> > for example, if the system could have a messaging interface > application, one or several messaging providers (SMS, E-mail, > XMPP, ...) and a separate optional encryption layer. Something like that, yes. > (and herein lies a disadvantage, because not all media are equal, > compare the SMS message length and text encoding needs with > electronic mail, but OTOH we've had messaging apps supporting at > least SMS and MMS). Thats what status/error codes are for. :-) > Another disadvantage, of course, is the SPOF which could then > be attacked, by having e.g. manufacturers installing backdoored > messaging systems... Thats not "another disadvantage", that is what we started with. The *advantage* of the latter is that its modulair, allowing for mix-and-match. And as the complex stuff is in the modules, it would be a lot easier for a (hobby) programmer to write an UI or posibly a commandline-interface (batch anyone ? :-) ) for it. Regards, Rudy Wieser
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | comp.mobile.android
csiph-web