• Pennomi@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    6 days ago

    The hell? There’s no reason to use plain HTTP instead of HTTPS.

    And symmetric encryption is wildly irresponsible as well.

    • webghost0101@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      3
      ·
      6 days ago

      Not for s second do I believe this was a accidental oversight.

      I am sure they had very good reasons, all alligned with their actual interests with no thought spared to even consider consequences for small fish users.

      • kinsnik@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 days ago

        i just can’t think of any. like the article says, i fully expected the app to send data to china. but even if you are maliciously spying on users, why would you send the stolen data on unsecured channels? so that everyone in the path takes advantage of the data your wanted to steal?

    • cadekat@pawb.social
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      2
      ·
      6 days ago

      Depends on how much traffic you’re talking about. Encrypting/decrypting isn’t free.

      • Pennomi@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        6 days ago

        It’s trivial compared to the compute they dedicate to AI models. Like, not even a rounding error.

        • cadekat@pawb.social
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          2
          ·
          6 days ago

          A penny saved is still a penny saved. I’m not saying it would amount to much, but it is non-zero.