|
|
|
|
|
by FabHK
3450 days ago
|
|
Hehe, yes, but the point is this: if you had verified fingerprints with Bob and are happily chatting with him, all the messages that reached him (two tick marks in WhatsApp) are safe. Only those that have not yet been delivered (one tick mark) would, when the server sends you you a new key, be re-encrypted and re-sent. All of this, as usual, is predicated on the client behaving as promised. |
|
Boelter said: “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which users might not notice. Using the retransmission vulnerability, the WhatsApp server can then later get a transcript of the whole conversation, not just a single message.”
I frankly didn't understand what was said here.