Web加密承诺皆为骗局
推荐指数 72.0 NO. 012 · 2026.07.06
发布2026/07/05Score74Comments83
为什么值得看
文章指出所有声称端到端加密的Web应用本质上不可信,因为浏览器无法向用户证明其运行的代码未被篡改。这对依赖网页版密码管理器、加密文件分享或在线钱包的用户是致命警示。
编辑判断
这篇文章的尖锐之处在于它攻击的不是某个实现漏洞,而是整个Web平台的结构性缺陷:即使服务器今天给你的是诚实代码,明天被 subpoena 或入侵后推送恶意JS,用户毫无察觉能力。Signal的桌面端用独立二进制部分缓解此问题,而纯Web方案如ProtonMail的网页版长期被密码学界质疑。
对AI从业者的直接启示:如果你在做AI应用的隐私计算(如浏览器端模型推理、联邦学习Web客户端),同样的信任困境存在——用户怎么确信你的JS没偷偷上传prompt?考虑提供可审计的浏览器扩展或原生应用作为信任锚点,而非仅依赖HTTPS下的网页。
社区反馈
意见分歧 75 条评论
核心争论:Web E2EE 是否因服务器可篡改代码而本质上不可信,还是信任模型在实践中足够可用
相关内容
在加密社区之外,加密仍然被视为一种骗局 技术虽具革命性,但信号被价格图表、网红骗局和低俗梗淹没,普通人只见波动性、诈骗和尴尬行话,而非可编程信任或财务自主权。 什么是加密骗局——主流诈骗套路与防范措施 加密货币诈骗以窃取资金或信息为目的,常见类型包括钓鱼、拉高出货、庞氏骗局、假钱包等,务必核查防范。 投资者警惕:警惕欺诈性数字资产和"加密"交易网站 SEC与CFTC警告投资者审查数字资产网站,识别欺诈危险信号如高额保证回报、承诺低风险或无风险等典型骗局特征。 Chatbots, Celebrities, and Victim Retargeting: Why Crypto Giveaway Scams Are Still So Successful 加密货币赠品骗局利用社交媒体和网络钓鱼,以高收益承诺骗取信任,结合聊天机器人、名人效应和受害者再 targeting 手段。 Web3 骗局:常见的加密货币骗局及防范方法 加密货币领域诈骗普遍,硬件钱包无法防范所有骗局,最佳方法是学习安全实践、完全避免接触可疑项目。
I'm confused, is the argument that it doesn't work because Google is fueled by surveillance capitalism? If so what about Apple which is only partly so? What about Firefox and in particular its de-branded ones without Google search as default? I think what makes the Web special is precisely that ther
I could not find anything about google or other browser vendors in the article. My take is that you should trust provider (developer, hoster) of said encryption app to send you actual implementation, not something that looks like the real deal, but does not encrypt anything. From a regular user's po
Like I said I'm confused, genuinely trying to figure the article out. "A cryptosystem is incoherent if its implementation is distributed by the same entity which it purports to secure against." What is the cryptosystem then on the Web? Who is the entity? It's not the server or the Website so I don't