Love how it highlights that big tech (much to capitalism's fault, TBH) can only drive innovation if the tech has a moat around it, if no one else can, or would, copy it and deploy it at a lower cost.
Which is... the argument that people use to defend capitalism? That capitalism drives innovation and makes it accessible to everyone at the lowest possible price.
I like the frugal tech idea as much as I like degrowth.
Strictly speaking, if you consider Lumo's GPU servers to be one of the "ends", then yeah, it is E2EE (you and the server being the ends).
But Proton own the GPU servers, and therefore have access to their private keys, so they can decrypt your messages as they arrive, before they're deleted, which happens after they're encrypted with your asymetric key (so only you can read it) and stored with zero-access.
I don't consider this safe. In a system where you are only interfacing with a computer (and not other users), E2EE should mean that only you have access to the unencrypted data, at any given time. Which is how Proton Drive works.
Stated can be a long way away from reality. That website statement can be changed at a whim and doesn't have any legal binding.
If you wanna rely on encryption to protect your privacy, you have to be encrypted/protected from the service provider too, that's what E2EE is all about, and what many of Proton's services provide, but Lumo not.
That's no bug, mTLS just isn't implemented on Firefox (for Android) currently.
There are 2 proposed solutions on that thread:
It was possible on old versions of FF, but not the current ones. I believe this to be related to the versions prior to the revamp that happened circa 2020. (the author refers to a version that was already "old" by 2022). So it was something supported on OG Firefox, not not on the new (current, by 5 years already) version.
Using the debug menu's secret settings to enable "Use third party CA certificates". This is available on current FF, but that's no mutual TLS. It is about allowing CA certificates that you installed yourself on your device for server TLS auth.
Tried it and it was a breeze to set it up with Caddy!
Problem was... lack of client side support, specially on mobile.
Many (most?) client apps don't support it.
Use the PWA from your browser, you said? I hope you like Google and using Chrome, because Firefox for Android doesn't support it (mTLS) 😭 (for now, see replies)
Dude publishing the most vaporware scam looking game pitch since The Day Before: publishing other people's games is the problem.