privacyspreadsheet.com icon indicating copy to clipboard operation
privacyspreadsheet.com copied to clipboard

Track "Un-e2ee Message Support"

Open maltfield opened this issue 1 year ago • 0 comments

This is a request to add a new row (called Un-e2ee Messages) to the spreadsheet that tracks whether or not an app supports messages that are not end-to-end encrypted.

Problem

Some apps (eg Matrix, Telegram, XMPP) allow the user to send & receive messages that are not end-to-end encrypted. Other apps (eg WhatsApp, Wire, Signal, Threema) do not have the ability for users to send & receive messages that are not end-to-end encrypted.

Many organizations that are looking for secure messaging solutions require that all messages are end-to-end encrypted. For these orgs, it is a non-starter if an app has the ability to send or receive a message that is not end-to-end encrypted.

There is a large risk for apps that allow messages to be send or received that are not end-to-end encrypted. This is largely due to user error -- either accidental or malicious.

Consider, for example, an organization that has a team (eg KYC/AML) that handles customer PII. Within a small trusted team, they need to be able to securely send & receive super-sensitive customer details (eg social security numbers, passport photos, etc). If it's at all possible for a user to accidentally send or receive a message that is not end-to-end encrypted, it introduces an unacceptable amount of risk to the org and to their customers.

For this reason, many orgs simply require apps to not have the ability to send or receive messages that are not end-to-end encrypted. Unfortunately, privacyspreadsheet.com currently does not clearly differentiate which apps satisfy this requirement.

Solution

A new row (called Un-e2ee Message Support) will display if an app supports sending message that are not end-to-end encrypted or not.

If an app cannot send or receive a message that is not end-to-end encrypted, then a green No should appear.

If an app can send or receive a message that is not end-to-end encrypted, then a red Yes should appear.

maltfield avatar Feb 04 '24 22:02 maltfield