Hacker News new | ask | show | jobs
by _xoxa 3671 days ago
Take a look at Signal be Open Whisper Systems - biggest problem with signal is that in order for you to verify the other parties identity in a fully trustworthy manner, you'd need to verify your keys in person.
2 comments

The main issue with WhatsApp is the lack of warning when someone's keys change and the fact that you have no guarantee that the noise protocol is implemented end to end as it's impossible to check the source (decompiling/reverse engineering aside)
WhatsApp has implemented the same encryption scheme, but it's not as trustworthy as Signal on account of it being closed source. Assuming the code were trustworthy, proper verification of keys requires a physical meeting.