• Arthur Besse@lemmy.mlOP
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    2
    ·
    edit-2
    4 months ago

    should the devs even bother encrypting at all given that it’s not a primary focus for them?

    Yes, imo, even doing what they’re doing now (without TOFU, trivially vulnerable to active attacks) is better than not encrypting at all - they should just have been forthright with users about it having been designed to only provide confidentiality from passive adversaries.

    But also, they should actually mitigate active adversaries by implementing TOFU. And then still, they should be more forthright about Meshtastic not being designed for privacy (re: enabling location tracking, etc, even absent GPS).