This is an old revision of this page, as edited by Fixuture(talk | contribs) at 20:52, 3 August 2015(Assessment: +Computer Security: class=Start, importance=Mid; +Telecommunications: class=Start, importance=High; +Espionage: class=Start (assisted)). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.Revision as of 20:52, 3 August 2015 by Fixuture(talk | contribs)(Assessment: +Computer Security: class=Start, importance=Mid; +Telecommunications: class=Start, importance=High; +Espionage: class=Start (assisted))
This article is within the scope of WikiProject Computer security, a collaborative effort to improve the coverage of computer security on Wikipedia. If you would like to participate, please visit the project page, where you can join the discussion and see a list of open tasks.Computer securityWikipedia:WikiProject Computer securityTemplate:WikiProject Computer securityComputer security
This article is within the scope of WikiProject Telecommunications, a collaborative effort to improve the coverage of Telecommunications on Wikipedia. If you would like to participate, please visit the project page, where you can join the discussion and see a list of open tasks.TelecommunicationsWikipedia:WikiProject TelecommunicationsTemplate:WikiProject TelecommunicationsTelecommunications
End-to-end encryption is within the scope of WikiProject Espionage, which aims to improve Wikipedia's coverage of espionage, intelligence, and related topics. If you would like to participate, visit the project page, or contribute to the discussion.EspionageWikipedia:WikiProject EspionageTemplate:WikiProject EspionageEspionage
This article is literally mostly about Tetra. Is Tetra notable enough to get its own article so that this one can focus on its title and just reference Tetra as an example? Chris Arnesen14:26, 25 March 2014 (UTC)[reply]
Article should describe potential vulnerability to MITM attacks, and means for mitigation
When non-certified/uncertified (is there a difference?) E2EE is used, there is potential for Man-in-the-middle attacks, especially between parties that have not previously exchanged public keys in a more secure manner. Because the article presently does not describe this potential, a reader might wrongly conclude that E2EE is by itself a complete solution to privacy and security, which would be a very dangerous misconception. The article should at least briefly describe the MITM problem, as well as means for mitigation (e.g. web of trust). While I'm very familiar with the problem, I don't have the expertise to adequately describe the possible means of mitigation, and in particular can't explain how (or even whether) those methods are used by the cited examples of E2EE protocols, software and services (e.g., ZRTP, TETRA).
--Brouhaha (talk) 18:49, 14 March 2015 (UTC)[reply]