Hacker News new | ask | show | jobs
by kryogen1c 1844 days ago
> WhatsApp/signal style apps cannot be secure to this sort of attack.

isnt this not true?

e2e keys are not known to signal server like they are on whatsapp. also there are no serverside signal backups.

2 comments

> e2e keys are not known to signal server like they are on whatsapp. also there are no serverside signal backups.

E2E keys are not known to WhatsApp's servers, and there are no server-side WhatsApp backups, either.

Your contacts weren't known to the WhatsApp server, now they are. There's no reason the next automatic update for signal can't contain code to send your keys to the server, and it wouldn't be the first centralized E2EE app to do that.