• 0 Posts
  • 86 Comments
Joined 1 year ago
cake
Cake day: July 9th, 2023

help-circle


  • But in the end, yes, it is a MITM. If you need your data to be E2E encrypted, don’t use it.

    Or do use E2E encryption. You can still have a layer of encryption within the SSL tunnel that cloudflare controls. Like you’d do for an E2EE filestore: the webserver (and cloudflare) see the website woosh by, and all that you do on it, but the files themselves are encrypted opaquely to both, and decrypted only by a browser at the other end.
















  • And, let’s be fair, for most people the real loss from this level of compromised privacy/security is far less than the real gain from helping your relationship.

    Sometimes I look at products I use from dubious companies, take a step back, and think, this company is actually a blessing in my life even if there is a smaller curse attached. That said, I’m grateful for all the tremendous effort put in by many people to make the digital (and rest of) world a safer, more private, fairer and more honest place. And I try to do at least a little of my share!


  • This is the way. Depending on how much convenience you are willing to sacrifice.

    There are one or two apps on F-Droid for using the work partition, and you can force-freeze apps within that, so you can turn wechat actually off when you don’t want it. That also separates wechat from your phone contacts list, without denying it nominal contacts access permission (without which, iirc, it refuses to work).

    For extra paranoia, run your dedicated wechat phone permanently through a VPN with location services on the phone turned off. Answer it only in a soundproofed room, Faraday caged with no WiFi connections except the dedicated wechat WiFi. Speak with a funny voice, and if you must show your face, wear a balaclava.

    But that might be overdoing it a little.