logoalt Hacker News

Stefan-Hyesterday at 8:09 PM1 replyview on HN

The point of E2EE is that only the people/systems that need access to the data are able to do so. If the message is encrypted on the user's device and then is only decrypted in the TEE where the data is needed in order to process the request, and only lives there ephemerally, then in what way is it not end-to-end encrypted?


Replies

paxysyesterday at 8:38 PM

Because anyone with access to the TEE also has access to the data. The owners can say they won't tamper with it, but those are promises, not guarantees.

show 1 reply