|
|
|
|
|
by Javantea_
3440 days ago
|
|
It now is a lot more clear what's going on here. The discoverer of this issue is basing his argument on the fact that when you verify a fingerprint, you are now confident that your end-to-end encryption won't transparently send your encrypted data to someone with a different keypair. The other side of the argument is that if WhatsApp actually did what you expect, data would be lost when a person switched phones in the middle of someone sending them a message. As a person who doesn't switch phones very often, I would prefer an end-to-end encryption to never send data to a different public key than the one I've used before. I would rather lose data than divulge it to a third party who has the ability to spoof the recipient's phone. This would only come up whenever someone switched their phone when I was sending them a message, so it's pretty rare. To me the trade off is a no brainer, and apparently to Facebook and Whisper Systems the trade off is a no brainer in the opposite direction. |
|
Only temporarily lost. WhatsApp could ask you: "do you want to resend the message(s) to the contact's new phone?". An easy solution and it could be optional, even off by default.