|
|
|
|
|
by dingaling
3447 days ago
|
|
Out of band but not out of app. It's the WhatsApp app that generates and presents the 'security code' or key fingerprint for comparison. It's not like SSH in which separate and discrete components generate the keypair and verify fingerprint on connection. |
|
I also don't see the difference between this and SSH. If your SSH server or client is backdoored/compromised, you have no control over what happens with your plaintext, no matter what the fingerprint verification tells you. The only difference is that one is open source, so the likelihood that a backdoor is detected is probably higher, though I don't think this means a) there is no backdoor and b) a backdoor in a closed-source app cannot be detected.