Hacker News new | ask | show | jobs
by NoahZuniga 138 days ago
Well, more than just that. For the published key transparency information to be trusted it has to not just be signed by WhatsApp, but also by an independent witness. In this case Cloudflare.

So for wa to do a man in the middle attack they would also need to convince Cloudflare to sign two inconsistent tree heads.