|
|
|
|
|
by henearkr
1986 days ago
|
|
Not if the keys are generated by the client. Signal also offers to label contacts for which you could verify the authenticity by another way. Doing a video call with the contact can be a simple way to clear doubts, even if it is not a proper different channel. |
|
Signal does have the capability to have a verification phrase displayed, which is generated from the session key. Reading that off can make the video more difficult to MITM, because then they'd have to morph the audio to match the phrase, and if it's done after the video is setup, morph the video as well. Not impossible, but difficult.