Hacker News new | ask | show | jobs
by tptacek 1352 days ago
You keep saying that this vulnerability can be defeated by carefully examining warnings. That's simply not true. The vulnerability is that the server, which you're not supposed to trust, can allow unauthorized people to decrypt your messages. The fact that you get a warning when unauthorized people are decrypting your messages is not a "defeat" of the vulnerability!

The bug is that you're owned, not that you didn't get an alert saying that you're owned.

1 comments

Did you skim over the part where there's a toggle to strictly prevent sending messages to unauthorized devices?
No, I did not. There are like 7 different horrible vulnerabilities in this paper, and you're talking about a different one (the one where the server can add new devices to people's accounts!) than I am (the one where the server can add random people to your channel, whether they're verified or not).