top | item 37245221

(no title)

amilich | 2 years ago

It's very simple. One of them had access to user's private keys (Lavabit).

One never has access to user private keys (Skiff).

discuss

order

tptacek|2 years ago

I don't understand how you don't have exactly the same access they did. I feel like I've invested a fair bit of time to understanding how this stuff works, and the story you're telling doesn't make sense. What am I missing?

onereplyac2|2 years ago

What amilich said is correct. However, what he is leaving out is that both have access to unencrypted email at send and recieve time, so you are taking Skiffs word that they dont log emails - since you have to trust the server this is not e2ee.