Hacker News new | ask | show | jobs
by nly 1995 days ago
Encryption is useless is the remote party can silently rekey and be re-authenticated as legitimate silently.

WhatsApp could almost certainly perform active MITM

2 comments

There is no need to rekey or do anything similar. Chats are available locally on the device, WhatsApp may simply implement a side channel to access those (they could already have one to satisfy agencies btw)
There's a configuration option you can enable which shows a message whenever the remote party changes their key (usually meaning they bought a new phone, in my limited experience), so it's not that silent. Yes, it's unfortunate that on WhatsApp this option defaults to disabled (to not confuse the newbies?), while on Signal (which uses the same protocol) this options defaults to enabled.