Damus
⁡jaseg 🔜 GPN24 profile picture
⁡jaseg 🔜 GPN24
@⁡jaseg 🔜 GPN24
delta.chat advertises that they provide “🔒 Audited end-to-end encryption safe against network and server attacks”, but if you click through it turns out that supposed audit:

(1) didn’t actually cover their e2ee but only a key establishment protocol and

(2) wasn’t actually an audit. Instead, unprompted, some researchers took a look at that key establishment protocol and found 20(!!) separate flaws. This research was not intended as an audit, nor was it commissioned or paid by delta.chat.
2
Koutsie :unverified: · 4w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0ae605fgpw08r8d2u7u65wu82n5n02gzv4wef797z5dk7g3w8smq507k5d yeah, well i still dont think Delta chat itself has fucked up GPG to an extend more than it is?
Delta Chat · 4w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0ae605fgpw08r8d2u7u65wu82n5n02gzv4wef797z5dk7g3w8smq507k5d ups, thanks for pointing a bug in our home page! You are totally right to criticize that audits are not the same as security analysis. The "audited end-to-end encryption" link should a...