|
|
|
|
|
by soatok
478 days ago
|
|
> Signal's way to validate that a session isn't man-in-the-middle'd is the same as XMPP: You have to validate the session's fingerprint in real life, or over another secure channel, by scanning each other's QR code, a procedure we'll refer to as "the QR thing". Tell me you didn't read the article, without telling me you didn't read the article. They're adding Key Transparency to keep themselves honest. Their specific implementation today (which is probably not final) was one of the final parts I reviewed: https://soatok.blog/signal-crypto-review-2025-part-7/ If you're going to talk about this with profound ignorance, it's probably wisest to not do so while responding to a blog post that significantly spent time on the piece that debunks your whole premise. |
|
Repeat after me: The server matters. A lot. Even if you don't want it to.