Hacker News new | ask | show | jobs
by psychphysic 1161 days ago
WhatsApp web generates a key which your phone signs and then sender's encrypt messages for all those keys.

Presumably this means that the device knows how many devices it will be send to.

1 comments

If the private subkey is stored on their servers, then that means their servers are one of the "ends" in "end to end encryption", and they can read all your messages.

Like putting a screen door on a submarine.

It’s stored in a local session on your computer. You won’t be able to start a new session.

So no, not their servers.