this post was submitted on 14 Sep 2021
57 points (96.7% liked)

Open Source

31173 readers
459 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 5 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] dreeg_ocedam@lemmy.ml 3 points 3 years ago (1 children)

You don’t need to self host email, Matrix or XMPP to use E2EE. I meant self hosting the web clients.

Nobody does that

HSTS, Certificate Pinning, …

HSTS is great but doesn't protect you against maliciously issued certificates, and Certificate pinning is deprecated on the Web.

Yeah, Open Source software down to the OS itself is important for security. But even then, who audits their own software? It’s probably 0.01% of the 0.01% of the general population you mentioned.

That's why you stick to software under high scrutiny and highly visible for security sensible stuff, and avoid using software with a broken security model for sensible stuff.

[–] Helix@feddit.de 0 points 3 years ago (1 children)

That’s why you stick to software under high scrutiny and highly visible for security sensible stuff

So, like Element? scnr

[–] dreeg_ocedam@lemmy.ml 2 points 3 years ago

More like Signal