pull down to refresh
I never thought about it before but that XKCD comic is pretty stupid. it pokes fun at an extremely specific and unlikely scenario where good encryption is useless. Yes sure, but the other 99% of the time it's very good to have.
reply
The unfortunate (or fortunate?) reality is that the big fish will do whatever it takes to not spend their life in prison while everyone else will be under constant surveillance without E2EE but with all implications of that.
I think the answer in the link is about intercepting encrypted messages but not about the key exchange. If you're able to intercept the key exchange (man-in-the-middle attack), the scheme is fucked. You need to be absolutely sure you're using the correct public key. That's why the phone call is mentioned: use a second channel for multi-factor authentication (MFA).
You're fucked but this attack doesn't work on scale so hopefully you're not among the biggest big fishes.