Post B6IWLnjq12HwvT6xEm by jaseg@chaos.social
 (DIR) More posts by jaseg@chaos.social
 (DIR) Post #B6IOjLKAVixg7NoqTg by jaseg@chaos.social
       0 likes, 0 repeats
       
       delta.chat advertises that they provide “🔒 Audited end-to-end encryption safe against network and server attacks”, but if you click through it turns out that supposed audit:(1) didn’t actually cover their e2ee but only a key establishment protocol and (2) wasn’t actually an audit. Instead, unprompted, some researchers took a look at that key establishment protocol and found 20(!!) separate flaws. This research was not intended as an audit, nor was it commissioned or paid by delta.chat.
       
 (DIR) Post #B6IOjLXdhdjknA7bTU by delta@chaos.social
       0 likes, 0 repeats
       
       @jaseg  ups, thanks for pointing a bug in our home page! You are totally right to criticize that audits are not the same as security analysis.The "audited end-to-end encryption" link should actually go to:https://delta.chat/en/help#security-auditsIt's also fixed on https://delta.chat now. Status: there are 5 published independent audits and one published security analysis from the ETH Applied Crypto Group. There is another soon to be published audit, and more audits scheduled this year.
       
 (DIR) Post #B6IOjN0kEuc3LikMTo by jaseg@chaos.social
       0 likes, 0 repeats
       
       I just noticed that looking at their marketing materials. If you ask me, as someone who has worked both in industry and in academia in the privacy & security space, this is super shady behavior.
       
 (DIR) Post #B6IWLnjq12HwvT6xEm by jaseg@chaos.social
       0 likes, 0 repeats
       
       @delta weird mistake. Why do you list that paper as an “audit” on the page you linked? It was not an audit. Also the actual audits you list there lack a direct link to the report in at least one case, and they do not support your assertion that your e2ee implementation as such was audited as they only cover small components of your system.
       
 (DIR) Post #B6IYFQytuei6W7FSjo by delta@chaos.social
       0 likes, 0 repeats
       
       @jaseg We are doing our best but mistakes like a wrong link or a misleading link happen. In the fediverse and support forum, we have otherwise linked to the security FAQ section many times. What is likely missing more than refining the FAQ entry, is a comprehensive security paper, linking and putting the audits in context, and giving 10-15 pages of going into some details, threat models etc.
       
 (DIR) Post #B6IYsopRBO8NlvbO1Q by jaseg@chaos.social
       0 likes, 0 repeats
       
       @delta this isn’t about “refining” something. calling a scientific paper an audit is an incorrect statement. calling your e2ee audited when it was not is also an incorrect statement. these marketing statements need to be removed not refined.
       
 (DIR) Post #B6IZYgy2nhW5YNauqu by delta@chaos.social
       0 likes, 0 repeats
       
       @jaseg sorry but it's not clear what wording you are refering to precisely.  pull requests can be opened  at https://github.com/deltachat/deltachat-pages/blob/main/en/help.md  and then more properly discussed by the people who care for this page.