|
|
|
|
|
by londons_explore
1161 days ago
|
|
I occasionally verify my security barcode with friends, and so far have never found any MITM's. Has anyone ever found barcodes that mismatch, indicating a MITM? If my understanding is correct, then for this to happen, either someone must be impersonating whatsapps server (which involves faking an HTTPS cert), or whatsapp themselves must be running en evil server. Both of those are quite a high bar, even for a state sponsored attack. |
|
Key transparency makes standard MITM much more detectable, and so it will significantly dissuade agencies and private actors from investing in those capabilities. It obviously doesn't solve all problems (governments will still be able to hack, and hypothetically even to mandate client changes that break the disable transparency) it removes a piece of low-hanging fruit and signals to governments that it isn't worth trying to exploit protocol weaknesses.
[0] https://www.lawfareblog.com/principles-more-informed-excepti...